From a91b62f99ff34c5351d1b4fd1e0ed0ecf74e3341 Mon Sep 17 00:00:00 2001
From: curben-bot <3048979-curben-bot@users.noreply.gitlab.com>
Date: Sun, 28 Mar 2021 00:12:51 +0000
Subject: [PATCH] Filter updated: Sun, 28 Mar 2021 00:12:50 UTC

---
 urlhaus-filter-ag-online.txt         |  1218 ++-
 urlhaus-filter-ag.txt                |   529 +-
 urlhaus-filter-agh-online.txt        |  1171 ++-
 urlhaus-filter-agh.txt               |   490 +-
 urlhaus-filter-bind-online.conf      |    70 +-
 urlhaus-filter-bind.conf             |    27 +-
 urlhaus-filter-dnsmasq-online.conf   |    70 +-
 urlhaus-filter-dnsmasq.conf          |    27 +-
 urlhaus-filter-domains-online.txt    |  1171 ++-
 urlhaus-filter-domains.txt           |   490 +-
 urlhaus-filter-hosts-online.txt      |    70 +-
 urlhaus-filter-hosts.txt             |    27 +-
 urlhaus-filter-online.tpl            |    70 +-
 urlhaus-filter-online.txt            |  1218 ++-
 urlhaus-filter-snort2-online.rules   | 11448 ++++++++++++-------------
 urlhaus-filter-snort3-online.rules   | 11448 ++++++++++++-------------
 urlhaus-filter-suricata-online.rules | 11448 ++++++++++++-------------
 urlhaus-filter-unbound-online.conf   |    70 +-
 urlhaus-filter-unbound.conf          |    27 +-
 urlhaus-filter-vivaldi-online.txt    |  1218 ++-
 urlhaus-filter-vivaldi.txt           |   529 +-
 urlhaus-filter.tpl                   |    27 +-
 urlhaus-filter.txt                   |   529 +-
 23 files changed, 22713 insertions(+), 20679 deletions(-)

diff --git a/urlhaus-filter-ag-online.txt b/urlhaus-filter-ag-online.txt
index 4a738a05..07aad164 100644
--- a/urlhaus-filter-ag-online.txt
+++ b/urlhaus-filter-ag-online.txt
@@ -1,5 +1,5 @@
 ! Title: Online Malicious URL Blocklist (AdGuard)
-! Updated: Sat, 27 Mar 2021 12:12:22 UTC
+! Updated: Sun, 28 Mar 2021 00:12:34 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -7,19 +7,20 @@
 ||0-24bpautomentes.hu$all
 ||0cl.sldov.ru$all
 ||1.11.234.99$all
+||1.186.151.219$all
 ||1.222.140.251$all
-||1.222.166.69$all
 ||1.222.196.60$all
 ||1.245.4.163$all
 ||1.246.222.107$all
 ||1.246.222.109$all
 ||1.246.222.113$all
 ||1.246.222.127$all
-||1.246.222.134$all
+||1.246.222.14$all
 ||1.246.222.153$all
 ||1.246.222.16$all
 ||1.246.222.165$all
 ||1.246.222.228$all
+||1.246.222.232$all
 ||1.246.222.234$all
 ||1.246.222.237$all
 ||1.246.222.245$all
@@ -33,6 +34,7 @@
 ||1.246.222.69$all
 ||1.246.222.8$all
 ||1.246.222.80$all
+||1.246.222.94$all
 ||1.246.222.98$all
 ||1.246.223.10$all
 ||1.246.223.103$all
@@ -48,9 +50,9 @@
 ||1.246.223.32$all
 ||1.246.223.35$all
 ||1.246.223.4$all
-||1.246.223.48$all
 ||1.246.223.49$all
 ||1.246.223.54$all
+||1.246.223.58$all
 ||1.246.223.59$all
 ||1.246.223.6$all
 ||1.246.223.61$all
@@ -70,7 +72,6 @@
 ||100.8.77.4$all
 ||1008691.com$all
 ||101.108.130.108$all
-||101.109.246.33$all
 ||101.16.183.179$all
 ||101.16.98.170$all
 ||101.229.85.127$all
@@ -83,35 +84,40 @@
 ||101.30.38.204$all
 ||101.64.119.250$all
 ||101.64.161.70$all
+||101.66.81.70$all
 ||101.75.157.99$all
 ||102.130.115.14$all
 ||102.141.240.139$all
 ||103.107.113.22$all
 ||103.124.104.118$all
 ||103.125.218.107$all
+||103.126.35.40$all
 ||103.139.89.205$all
 ||103.141.138.12$all
 ||103.145.13.24$all
 ||103.146.174.208$all
+||103.153.92.76$all
 ||103.156.221.66$all
 ||103.159.155.214$all
 ||103.16.145.25$all
 ||103.207.1.146$all
+||103.214.191.141$all
 ||103.217.215.21$all
 ||103.224.200.40$all
 ||103.238.228.3$all
 ||103.238.228.4$all
 ||103.240.249.121$all
+||103.245.49.180$all
 ||103.4.117.26$all
 ||103.66.78.171$all
 ||103.79.112.254$all
-||103.82.145.111$all
 ||103.82.98.170$all
 ||103.84.240.130$all
 ||103.84.240.228$all
 ||103.84.241.123$all
 ||103.84.241.94$all
 ||103.91.245.12$all
+||103.91.245.14$all
 ||103.91.245.16$all
 ||103.91.245.17$all
 ||103.91.245.19$all
@@ -123,6 +129,9 @@
 ||103.91.245.36$all
 ||103.91.245.41$all
 ||103.91.245.46$all
+||103.91.245.49$all
+||103.91.245.54$all
+||103.91.245.58$all
 ||103.92.25.90$all
 ||103.92.25.95$all
 ||104.184.75.123$all
@@ -155,7 +164,6 @@
 ||109.124.90.229$all
 ||109.233.196.232$all
 ||109.235.7.228$all
-||109.248.58.238$all
 ||109.86.85.253$all
 ||109.95.200.102$all
 ||109.95.200.230$all
@@ -181,14 +189,12 @@
 ||110.255.101.184$all
 ||110.255.167.147$all
 ||110.35.145.127$all
-||110.35.208.21$all
+||110.35.209.175$all
 ||110.35.221.77$all
-||110.35.223.92$all
-||110.35.225.24$all
-||110.35.233.147$all
 ||110.35.235.57$all
 ||110.35.4.2$all
 ||110fss.net$all
+||111.118.111.207$all
 ||111.118.88.61$all
 ||111.119.245.114$all
 ||111.125.67.125$all
@@ -228,17 +234,15 @@
 ||111.38.26.243$all
 ||111.38.8.81$all
 ||111.61.52.53$all
-||112.105.117.227$all
-||112.111.100.236$all
 ||112.111.108.184$all
 ||112.111.31.175$all
 ||112.122.62.224$all
-||112.123.200.47$all
+||112.122.63.70$all
 ||112.132.134.106$all
 ||112.132.147.102$all
 ||112.159.108.96$all
+||112.167.165.139$all
 ||112.170.124.75$all
-||112.170.219.168$all
 ||112.170.233.9$all
 ||112.186.210.211$all
 ||112.186.96.252$all
@@ -250,10 +254,8 @@
 ||112.225.52.145$all
 ||112.225.82.4$all
 ||112.226.118.229$all
-||112.226.176.167$all
 ||112.226.195.104$all
 ||112.226.202.111$all
-||112.226.205.96$all
 ||112.226.67.193$all
 ||112.226.92.34$all
 ||112.228.180.95$all
@@ -263,7 +265,6 @@
 ||112.229.188.28$all
 ||112.229.199.19$all
 ||112.230.251.85$all
-||112.234.121.107$all
 ||112.234.134.244$all
 ||112.234.16.252$all
 ||112.234.194.178$all
@@ -293,18 +294,21 @@
 ||112.242.106.228$all
 ||112.242.18.128$all
 ||112.242.2.247$all
+||112.242.97.131$all
 ||112.243.115.183$all
 ||112.245.12.89$all
+||112.245.178.153$all
 ||112.245.5.141$all
 ||112.245.8.24$all
 ||112.246.162.50$all
 ||112.246.180.49$all
 ||112.247.100.14$all
-||112.247.14.135$all
+||112.247.16.222$all
 ||112.247.161.45$all
 ||112.247.191.118$all
 ||112.247.214.146$all
 ||112.247.240.226$all
+||112.247.25.42$all
 ||112.247.81.173$all
 ||112.247.82.122$all
 ||112.248.148.90$all
@@ -329,6 +333,8 @@
 ||112.252.239.103$all
 ||112.252.245.249$all
 ||112.252.46.212$all
+||112.254.128.160$all
+||112.254.188.228$all
 ||112.254.208.123$all
 ||112.254.32.5$all
 ||112.255.127.212$all
@@ -344,7 +350,6 @@
 ||112.27.124.113$all
 ||112.27.124.117$all
 ||112.27.124.119$all
-||112.27.124.120$all
 ||112.27.124.122$all
 ||112.27.124.124$all
 ||112.27.124.127$all
@@ -356,7 +361,6 @@
 ||112.27.124.136$all
 ||112.27.124.138$all
 ||112.27.124.139$all
-||112.27.124.140$all
 ||112.27.124.142$all
 ||112.27.124.143$all
 ||112.27.124.146$all
@@ -372,6 +376,7 @@
 ||112.27.124.168$all
 ||112.27.124.171$all
 ||112.27.124.172$all
+||112.27.124.174$all
 ||112.27.124.175$all
 ||112.27.124.176$all
 ||112.27.124.178$all
@@ -390,16 +395,19 @@
 ||112.27.88.116$all
 ||112.27.91.212$all
 ||112.27.91.247$all
+||112.30.1.133$all
 ||112.30.1.149$all
 ||112.30.1.150$all
 ||112.30.1.158$all
-||112.30.1.159$all
+||112.30.1.164$all
 ||112.30.1.168$all
 ||112.30.1.177$all
 ||112.30.1.178$all
 ||112.30.1.181$all
+||112.30.1.182$all
 ||112.30.1.188$all
 ||112.30.1.190$all
+||112.30.1.194$all
 ||112.30.1.197$all
 ||112.30.1.211$all
 ||112.30.1.219$all
@@ -414,15 +422,15 @@
 ||112.30.1.90$all
 ||112.30.1.91$all
 ||112.30.100.228$all
-||112.30.110.27$all
 ||112.30.110.30$all
 ||112.30.110.31$all
+||112.30.110.36$all
 ||112.30.110.37$all
 ||112.30.110.38$all
 ||112.30.110.41$all
 ||112.30.110.42$all
 ||112.30.110.43$all
-||112.30.110.45$all
+||112.30.110.51$all
 ||112.30.110.52$all
 ||112.30.110.57$all
 ||112.30.110.58$all
@@ -438,6 +446,7 @@
 ||112.30.4.136$all
 ||112.30.4.37$all
 ||112.30.4.52$all
+||112.30.4.53$all
 ||112.30.4.57$all
 ||112.30.4.61$all
 ||112.30.4.70$all
@@ -447,6 +456,7 @@
 ||112.31.176.16$all
 ||112.31.211.135$all
 ||112.31.82.160$all
+||112.31.87.98$all
 ||112.53.224.79$all
 ||112.65.53.175$all
 ||112.72.153.37$all
@@ -455,6 +465,8 @@
 ||112.72.162.53$all
 ||112.72.176.112$all
 ||112.72.176.84$all
+||112.72.226.202$all
+||112.72.231.35$all
 ||112.78.45.158$all
 ||112.80.118.16$all
 ||112.80.127.91$all
@@ -473,31 +485,24 @@
 ||112.9.140.247$all
 ||112.91.219.195$all
 ||112.93.29.211$all
-||112.95.80.165$all
 ||113.0.74.25$all
 ||113.11.95.254$all
 ||113.110.204.254$all
-||113.110.243.79$all
-||113.116.150.147$all
-||113.116.176.26$all
-||113.116.44.33$all
-||113.116.89.82$all
 ||113.118.13.194$all
-||113.118.133.113$all
-||113.118.250.227$all
-||113.118.6.104$all
+||113.118.159.178$all
+||113.119.37.141$all
 ||113.122.238.68$all
 ||113.122.59.84$all
 ||113.161.58.249$all
 ||113.172.250.35$all
 ||113.189.243.248$all
+||113.193.29.42$all
 ||113.194.133.9$all
 ||113.194.135.154$all
 ||113.195.163.26$all
 ||113.195.166.46$all
 ||113.195.168.190$all
 ||113.201.219.47$all
-||113.225.171.27$all
 ||113.226.42.250$all
 ||113.227.128.9$all
 ||113.227.169.170$all
@@ -505,28 +510,22 @@
 ||113.227.35.229$all
 ||113.231.211.131$all
 ||113.231.93.142$all
-||113.232.211.182$all
+||113.232.156.157$all
 ||113.234.224.130$all
 ||113.235.116.209$all
 ||113.253.144.141$all
 ||113.254.169.251$all
 ||113.59.128.133$all
-||113.59.133.16$all
-||113.59.144.42$all
 ||113.59.154.21$all
 ||113.59.191.47$all
 ||113.61.204.205$all
 ||113.86.204.13$all
 ||113.87.203.239$all
-||113.87.227.222$all
-||113.88.100.120$all
-||113.88.104.194$all
-||113.88.111.36$all
-||113.88.209.47$all
 ||113.88.232.36$all
 ||113.88.38.232$all
+||113.88.39.21$all
+||113.90.27.218$all
 ||113.92.93.208$all
-||114.199.204.37$all
 ||114.199.253.235$all
 ||114.224.203.128$all
 ||114.226.100.56$all
@@ -537,7 +536,6 @@
 ||114.229.52.14$all
 ||114.234.189.154$all
 ||114.235.115.236$all
-||114.30.54.64$all
 ||114.79.161.94$all
 ||114.79.172.42$all
 ||115.165.216.112$all
@@ -545,45 +543,49 @@
 ||115.193.83.0$all
 ||115.201.38.185$all
 ||115.201.98.176$all
+||115.205.197.221$all
 ||115.208.97.42$all
 ||115.209.234.226$all
 ||115.223.159.80$all
 ||115.229.250.130$all
-||115.23.88.135$all
 ||115.42.47.36$all
 ||115.48.163.47$all
 ||115.48.179.43$all
 ||115.48.188.17$all
-||115.48.200.115$all
-||115.48.49.84$all
+||115.48.201.26$all
+||115.48.41.101$all
 ||115.49.124.80$all
 ||115.49.158.175$all
+||115.49.24.63$all
 ||115.49.36.220$all
-||115.49.43.52$all
-||115.49.80.117$all
-||115.49.96.88$all
-||115.50.15.24$all
+||115.49.79.131$all
+||115.50.1.41$all
+||115.50.168.160$all
+||115.50.171.192$all
+||115.50.175.205$all
 ||115.50.19.136$all
 ||115.50.20.73$all
 ||115.50.206.128$all
-||115.50.226.30$all
-||115.50.228.168$all
+||115.50.211.74$all
 ||115.50.238.227$all
 ||115.50.239.77$all
-||115.50.240.72$all
+||115.50.242.7$all
+||115.50.247.46$all
 ||115.50.61.82$all
+||115.50.79.78$all
 ||115.50.91.30$all
 ||115.50.96.254$all
-||115.51.104.85$all
-||115.51.106.209$all
+||115.51.7.254$all
 ||115.52.17.196$all
+||115.52.172.72$all
 ||115.53.200.130$all
 ||115.53.224.134$all
 ||115.53.234.210$all
-||115.53.238.224$all
+||115.53.58.228$all
+||115.54.113.49$all
 ||115.54.123.147$all
-||115.54.70.108$all
-||115.55.105.154$all
+||115.54.158.251$all
+||115.55.127.0$all
 ||115.55.144.42$all
 ||115.55.145.147$all
 ||115.55.157.96$all
@@ -591,64 +593,67 @@
 ||115.55.158.250$all
 ||115.55.161.38$all
 ||115.55.179.168$all
+||115.55.198.105$all
 ||115.55.206.35$all
 ||115.55.206.78$all
 ||115.55.26.94$all
 ||115.55.42.200$all
+||115.55.52.17$all
 ||115.56.111.63$all
 ||115.56.114.17$all
-||115.56.132.61$all
+||115.56.131.150$all
 ||115.56.133.96$all
 ||115.56.134.79$all
+||115.56.135.255$all
 ||115.56.137.48$all
 ||115.56.139.122$all
-||115.56.143.241$all
+||115.56.142.45$all
 ||115.56.145.102$all
 ||115.56.148.22$all
+||115.56.150.149$all
 ||115.56.151.65$all
 ||115.56.151.68$all
 ||115.56.154.147$all
-||115.56.175.2$all
+||115.56.155.50$all
 ||115.56.189.162$all
+||115.56.31.11$all
 ||115.56.31.54$all
 ||115.56.98.205$all
 ||115.56.99.235$all
 ||115.58.132.199$all
 ||115.58.134.143$all
-||115.58.161.17$all
+||115.58.86.217$all
 ||115.58.90.143$all
+||115.58.91.65$all
 ||115.59.198.69$all
-||115.59.209.196$all
 ||115.59.212.193$all
 ||115.59.214.107$all
 ||115.59.228.237$all
-||115.59.235.229$all
 ||115.59.253.202$all
 ||115.59.57.171$all
 ||115.59.82.123$all
-||115.61.102.110$all
+||115.61.103.197$all
+||115.61.112.159$all
 ||115.61.118.201$all
 ||115.61.118.90$all
-||115.61.139.74$all
-||115.62.152.207$all
+||115.61.158.98$all
 ||115.62.155.83$all
+||115.62.171.143$all
 ||115.62.26.39$all
+||115.63.131.173$all
 ||115.63.139.175$all
 ||115.63.141.147$all
 ||115.63.180.149$all
 ||115.63.189.77$all
 ||115.63.21.130$all
-||115.63.37.6$all
 ||115.63.53.188$all
 ||115.73.3.11$all
 ||115.75.217.79$all
 ||115.78.133.146$all
 ||115.92.174.231$all
-||115.96.61.246$all
-||115.97.136.10$all
+||115.97.139.32$all
 ||116.124.219.2$all
 ||116.149.243.14$all
-||116.2.100.221$all
 ||116.206.164.46$all
 ||116.207.71.237$all
 ||116.211.100.26$all
@@ -656,22 +661,27 @@
 ||116.212.142.215$all
 ||116.30.4.2$all
 ||116.30.95.156$all
-||116.72.51.230$all
-||116.73.222.118$all
-||116.75.199.105$all
-||116.75.212.119$all
+||116.72.28.239$all
+||116.73.52.125$all
+||116.74.101.150$all
+||116.74.17.122$all
+||116.75.193.33$all
+||116.75.198.85$all
+||116.75.212.81$all
 ||116.76.114.71$all
+||116.9.43.220$all
 ||117.11.234.35$all
 ||117.12.48.157$all
 ||117.156.69.22$all
-||117.192.224.103$all
-||117.192.225.161$all
-||117.192.225.195$all
-||117.192.227.137$all
-||117.194.160.78$all
-||117.194.163.210$all
-||117.194.166.103$all
-||117.194.166.20$all
+||117.194.148.198$all
+||117.194.160.203$all
+||117.194.164.123$all
+||117.194.167.131$all
+||117.196.48.148$all
+||117.196.48.181$all
+||117.196.50.154$all
+||117.196.50.239$all
+||117.196.50.76$all
 ||117.20.204.138$all
 ||117.20.204.5$all
 ||117.20.210.52$all
@@ -679,43 +689,17 @@
 ||117.20.243.40$all
 ||117.200.76.54$all
 ||117.200.76.60$all
-||117.202.67.238$all
-||117.202.67.246$all
-||117.202.67.4$all
-||117.202.70.96$all
-||117.202.71.179$all
-||117.207.5.156$all
-||117.208.134.226$all
-||117.208.134.64$all
-||117.213.11.104$all
-||117.213.14.17$all
-||117.213.14.30$all
-||117.213.14.62$all
-||117.213.15.179$all
-||117.213.43.219$all
-||117.213.44.116$all
-||117.213.46.160$all
-||117.213.47.183$all
-||117.213.8.163$all
-||117.215.248.14$all
-||117.215.251.253$all
-||117.222.160.108$all
-||117.222.162.50$all
-||117.222.164.19$all
-||117.222.164.21$all
-||117.222.169.141$all
-||117.222.172.16$all
-||117.222.174.16$all
+||117.202.67.92$all
+||117.208.132.10$all
+||117.208.132.45$all
+||117.213.44.102$all
+||117.222.161.42$all
+||117.222.164.100$all
+||117.222.164.189$all
+||117.222.173.218$all
+||117.222.175.120$all
 ||117.241.64.105$all
-||117.241.67.141$all
-||117.242.208.153$all
-||117.242.208.95$all
-||117.247.200.129$all
-||117.247.202.150$all
-||117.247.203.156$all
-||117.247.204.118$all
-||117.247.204.66$all
-||117.251.60.194$all
+||117.248.62.29$all
 ||117.26.235.164$all
 ||117.27.10.73$all
 ||117.60.204.190$all
@@ -727,7 +711,8 @@
 ||117.91.240.50$all
 ||117.93.115.242$all
 ||117.93.79.40$all
-||118.172.80.79$all
+||118.114.84.237$all
+||118.172.176.41$all
 ||118.176.104.35$all
 ||118.176.157.64$all
 ||118.176.7.132$all
@@ -749,10 +734,8 @@
 ||118.250.51.192$all
 ||118.42.125.246$all
 ||118.43.180.33$all
-||118.68.245.69$all
 ||118.70.83.140$all
 ||118.75.120.136$all
-||118.75.200.198$all
 ||118.75.240.136$all
 ||118.75.240.239$all
 ||118.75.50.253$all
@@ -763,23 +746,21 @@
 ||118.79.218.157$all
 ||118.79.50.203$all
 ||118.79.58.82$all
+||118.79.96.11$all
 ||118.83.79.43$all
-||118.91.24.27$all
+||118.91.41.135$all
 ||118.99.179.164$all
 ||118.99.183.235$all
 ||118.99.239.217$all
 ||119.100.40.250$all
 ||119.108.251.176$all
-||119.109.34.245$all
 ||119.112.22.58$all
-||119.112.27.20$all
 ||119.115.247.23$all
+||119.118.150.84$all
+||119.119.176.198$all
 ||119.119.52.202$all
-||119.123.125.139$all
-||119.123.216.42$all
-||119.123.218.76$all
-||119.123.221.158$all
-||119.123.237.218$all
+||119.123.173.95$all
+||119.123.175.210$all
 ||119.14.143.145$all
 ||119.147.213.57$all
 ||119.162.109.111$all
@@ -837,7 +818,6 @@
 ||119.189.227.244$all
 ||119.190.211.99$all
 ||119.190.234.181$all
-||119.190.240.238$all
 ||119.191.150.85$all
 ||119.191.187.206$all
 ||119.191.215.221$all
@@ -849,13 +829,12 @@
 ||119.251.12.85$all
 ||119.251.14.251$all
 ||119.56.131.155$all
+||119.56.140.73$all
 ||119.56.143.46$all
 ||119.56.143.71$all
-||119.56.144.75$all
 ||119.56.148.115$all
 ||119.56.155.57$all
 ||119.56.172.28$all
-||119.56.195.90$all
 ||119.96.37.55$all
 ||119.96.70.116$all
 ||119.99.188.187$all
@@ -870,6 +849,7 @@
 ||12.207.39.227$all
 ||120.12.153.54$all
 ||120.12.212.5$all
+||120.12.231.61$all
 ||120.142.222.22$all
 ||120.150.213.110$all
 ||120.151.248.134$all
@@ -892,6 +872,7 @@
 ||120.193.91.201$all
 ||120.193.91.202$all
 ||120.193.91.204$all
+||120.193.91.205$all
 ||120.193.91.207$all
 ||120.193.91.208$all
 ||120.193.91.212$all
@@ -913,31 +894,28 @@
 ||120.5.15.95$all
 ||120.50.66.60$all
 ||120.50.93.115$all
+||120.57.214.228$all
 ||120.57.98.208$all
 ||120.6.141.142$all
+||120.6.241.130$all
 ||120.6.8.11$all
 ||120.69.131.51$all
 ||120.7.75.99$all
 ||120.7.90.104$all
 ||120.83.189.232$all
 ||120.85.165.112$all
-||120.85.169.113$all
-||120.85.170.109$all
-||120.85.173.234$all
 ||120.85.185.141$all
-||120.85.236.95$all
+||120.85.196.211$all
+||120.85.208.107$all
 ||120.85.238.10$all
-||120.85.238.244$all
 ||120.9.32.51$all
 ||121.100.114.164$all
 ||121.100.96.8$all
 ||121.121.44.222$all
 ||121.123.53.25$all
 ||121.127.155.220$all
-||121.136.249.5$all
 ||121.141.11.56$all
 ||121.15.142.137$all
-||121.151.78.190$all
 ||121.159.22.144$all
 ||121.17.103.176$all
 ||121.170.234.142$all
@@ -955,32 +933,25 @@
 ||121.25.101.86$all
 ||121.254.43.215$all
 ||121.254.76.17$all
-||121.61.101.93$all
 ||121.61.102.1$all
 ||121.61.107.189$all
 ||121.61.97.195$all
 ||121.61.98.151$all
 ||121.88.99.236$all
 ||122.100.150.204$all
-||122.137.52.122$all
 ||122.160.147.53$all
 ||122.176.44.34$all
 ||122.188.86.225$all
-||122.190.19.204$all
-||122.192.190.203$all
 ||122.199.66.28$all
 ||122.199.72.23$all
 ||122.199.79.27$all
 ||122.202.37.85$all
 ||122.202.41.23$all
 ||122.252.199.3$all
-||122.252.250.22$all
 ||122.254.183.207$all
 ||122.254.29.37$all
 ||122.254.33.214$all
 ||123.0.240.58$all
-||123.10.131.225$all
-||123.10.41.32$all
 ||123.10.83.136$all
 ||123.11.11.207$all
 ||123.11.4.168$all
@@ -993,16 +964,19 @@
 ||123.110.19.248$all
 ||123.110.200.98$all
 ||123.110.238.188$all
-||123.12.7.82$all
+||123.12.189.247$all
+||123.12.225.70$all
+||123.12.235.159$all
+||123.12.243.85$all
 ||123.128.128.205$all
 ||123.128.133.91$all
 ||123.128.177.161$all
 ||123.129.84.36$all
 ||123.129.88.123$all
-||123.13.44.60$all
 ||123.130.202.8$all
 ||123.130.208.52$all
 ||123.130.23.110$all
+||123.130.27.19$all
 ||123.130.37.182$all
 ||123.130.61.210$all
 ||123.130.77.225$all
@@ -1014,16 +988,19 @@
 ||123.133.98.135$all
 ||123.134.14.130$all
 ||123.134.50.186$all
-||123.135.157.193$all
 ||123.135.39.36$all
 ||123.135.71.150$all
-||123.14.172.149$all
-||123.14.86.82$all
+||123.14.127.238$all
+||123.14.173.199$all
+||123.14.249.33$all
+||123.14.34.240$all
+||123.14.37.32$all
+||123.14.50.214$all
 ||123.14.93.154$all
 ||123.144.211.86$all
 ||123.152.42.4$all
-||123.152.43.21$all
 ||123.153.80.178$all
+||123.154.116.116$all
 ||123.154.236.114$all
 ||123.154.94.1$all
 ||123.155.118.36$all
@@ -1060,22 +1037,23 @@
 ||123.28.217.23$all
 ||123.4.11.40$all
 ||123.4.166.2$all
-||123.4.176.22$all
 ||123.4.177.93$all
-||123.4.193.171$all
+||123.4.194.152$all
 ||123.4.209.154$all
 ||123.4.241.118$all
+||123.4.45.31$all
 ||123.4.76.117$all
 ||123.4.83.66$all
 ||123.4.85.149$all
-||123.5.123.60$all
 ||123.5.143.203$all
 ||123.5.146.238$all
 ||123.5.190.167$all
 ||123.5.5.242$all
 ||123.5.8.211$all
 ||123.8.56.94$all
+||123.8.71.27$all
 ||123.9.194.169$all
+||123.9.240.115$all
 ||123.9.245.207$all
 ||124.105.105.222$all
 ||124.129.162.169$all
@@ -1087,7 +1065,9 @@
 ||124.131.130.95$all
 ||124.131.131.71$all
 ||124.131.136.75$all
+||124.131.137.147$all
 ||124.131.151.135$all
+||124.131.24.185$all
 ||124.131.26.243$all
 ||124.131.26.78$all
 ||124.131.41.48$all
@@ -1111,7 +1091,6 @@
 ||124.199.56.198$all
 ||124.226.24.117$all
 ||124.230.174.233$all
-||124.234.6.130$all
 ||124.254.254.61$all
 ||124.5.92.20$all
 ||124.6.0.4$all
@@ -1119,8 +1098,8 @@
 ||124.7.254.85$all
 ||124.80.46.73$all
 ||124.91.237.147$all
+||124.92.135.37$all
 ||124.93.94.207$all
-||124.95.17.41$all
 ||125.105.219.169$all
 ||125.126.69.95$all
 ||125.128.28.161$all
@@ -1131,65 +1110,64 @@
 ||125.36.148.42$all
 ||125.40.1.127$all
 ||125.40.113.66$all
-||125.40.160.116$all
-||125.40.17.14$all
-||125.40.237.130$all
 ||125.40.25.140$all
 ||125.40.65.120$all
 ||125.40.73.6$all
 ||125.40.74.153$all
 ||125.40.75.22$all
+||125.41.141.41$all
+||125.41.164.60$all
+||125.41.185.186$all
+||125.41.196.114$all
 ||125.41.208.139$all
-||125.41.244.43$all
 ||125.41.6.192$all
 ||125.41.7.204$all
 ||125.41.74.22$all
 ||125.41.96.238$all
 ||125.41.96.33$all
+||125.41.97.231$all
 ||125.41.97.81$all
 ||125.42.107.136$all
 ||125.42.124.114$all
-||125.42.98.24$all
-||125.42.98.35$all
 ||125.43.112.123$all
 ||125.43.112.182$all
 ||125.43.133.130$all
 ||125.43.167.192$all
-||125.43.2.169$all
-||125.43.21.157$all
 ||125.43.215.244$all
-||125.43.26.36$all
 ||125.43.33.20$all
-||125.43.37.138$all
 ||125.43.53.50$all
 ||125.43.53.9$all
+||125.43.6.186$all
 ||125.43.60.218$all
-||125.43.73.19$all
-||125.43.92.62$all
+||125.43.63.47$all
 ||125.44.10.125$all
 ||125.44.107.182$all
 ||125.44.175.118$all
 ||125.44.198.62$all
+||125.44.208.152$all
 ||125.44.212.131$all
-||125.44.243.220$all
-||125.44.31.79$all
+||125.44.227.51$all
+||125.44.70.64$all
 ||125.44.8.227$all
 ||125.45.153.91$all
+||125.45.43.63$all
 ||125.45.55.146$all
-||125.46.138.117$all
+||125.46.166.112$all
 ||125.46.166.125$all
 ||125.46.205.88$all
 ||125.46.206.160$all
 ||125.46.217.52$all
 ||125.46.241.237$all
+||125.47.125.16$all
 ||125.47.241.188$all
 ||125.47.245.200$all
+||125.47.248.131$all
 ||125.47.250.98$all
-||125.47.252.106$all
-||125.47.254.154$all
 ||125.47.254.44$all
 ||125.47.28.18$all
+||125.47.38.142$all
 ||125.47.45.218$all
+||125.47.47.212$all
 ||125.47.57.80$all
 ||125.47.91.51$all
 ||125.79.192.197$all
@@ -1202,12 +1180,13 @@
 ||139.159.226.180$all
 ||139.170.173.198$all
 ||139.170.174.162$all
+||139.213.97.191$all
 ||139.216.102.151$all
 ||139.227.46.137$all
 ||14.102.17.222$all
 ||14.102.97.204$all
+||14.109.126.96$all
 ||14.136.80.242$all
-||14.138.109.129$all
 ||14.138.109.26$all
 ||14.138.8.215$all
 ||14.138.8.51$all
@@ -1225,27 +1204,25 @@
 ||14.55.29.2$all
 ||14.98.184.178$all
 ||140.237.30.113$all
+||140.237.30.172$all
 ||140.237.5.43$all
+||140.240.151.177$all
 ||142.11.216.5$all
 ||142.177.56.127$all
 ||146.71.79.230$all
 ||148.69.108.177$all
 ||149.20.176.179$all
-||149.255.15.112$all
 ||149.255.15.134$all
+||149.255.15.172$all
 ||149.255.15.180$all
 ||149.255.15.182$all
 ||149.255.15.184$all
-||149.255.15.191$all
 ||149.255.15.213$all
-||149.255.15.235$all
-||149.255.15.27$all
 ||149.255.15.43$all
 ||149.255.15.87$all
 ||149.255.15.99$all
 ||149.3.124.194$all
-||149.3.36.210$all
-||149.3.85.55$all
+||149.3.73.210$all
 ||150.116.207.99$all
 ||151.177.163.87$all
 ||151.33.230.191$all
@@ -1258,7 +1235,6 @@
 ||153.34.135.92$all
 ||153.34.23.76$all
 ||153.34.29.28$all
-||153.35.111.46$all
 ||153.35.27.49$all
 ||153.36.126.35$all
 ||158.101.165.14$all
@@ -1269,27 +1245,28 @@
 ||162.191.205.175$all
 ||162.194.28.60$all
 ||162.209.98.174$all
-||163.125.125.6$all
-||163.125.157.64$all
+||162.212.203.250$all
 ||163.125.18.93$all
 ||163.125.193.148$all
-||163.125.195.248$all
-||163.125.200.199$all
+||163.125.200.118$all
+||163.125.200.242$all
 ||163.125.202.193$all
-||163.125.202.195$all
-||163.125.202.21$all
+||163.125.202.255$all
+||163.125.202.87$all
 ||163.125.203.198$all
+||163.125.203.236$all
 ||163.125.204.156$all
-||163.125.204.244$all
 ||163.125.204.34$all
-||163.125.207.61$all
-||163.125.243.131$all
+||163.125.206.16$all
 ||163.125.255.165$all
 ||163.204.208.169$all
+||163.204.211.136$all
 ||163.204.211.228$all
 ||163.204.211.58$all
 ||163.53.206.228$all
 ||165.90.16.5$all
+||168.194.146.145$all
+||168.205.223.254$all
 ||168.90.204.207$all
 ||170.81.238.178$all
 ||171.113.36.216$all
@@ -1303,11 +1280,13 @@
 ||171.120.125.147$all
 ||171.121.6.162$all
 ||171.123.134.239$all
+||171.125.122.91$all
 ||171.125.242.71$all
 ||171.125.30.233$all
 ||171.125.30.93$all
 ||171.125.64.223$all
 ||171.125.65.22$all
+||171.125.65.89$all
 ||171.125.75.68$all
 ||171.126.70.133$all
 ||171.223.72.123$all
@@ -1321,7 +1300,6 @@
 ||171.36.249.91$all
 ||171.38.145.146$all
 ||171.38.148.69$all
-||171.38.217.222$all
 ||171.38.219.189$all
 ||171.38.223.110$all
 ||171.38.223.213$all
@@ -1353,12 +1331,13 @@
 ||175.145.200.216$all
 ||175.146.17.227$all
 ||175.150.168.92$all
-||175.153.144.2$all
 ||175.162.137.166$all
 ||175.162.195.27$all
 ||175.162.69.13$all
+||175.164.61.215$all
 ||175.165.90.198$all
 ||175.168.139.182$all
+||175.169.13.182$all
 ||175.17.90.14$all
 ||175.174.93.57$all
 ||175.199.33.139$all
@@ -1375,10 +1354,8 @@
 ||176.111.174.67$all
 ||176.113.161.104$all
 ||176.113.161.113$all
-||176.113.161.120$all
 ||176.113.161.128$all
-||176.113.161.138$all
-||176.113.161.59$all
+||176.113.161.60$all
 ||176.113.161.65$all
 ||176.113.161.66$all
 ||176.113.161.76$all
@@ -1392,37 +1369,36 @@
 ||176.123.7.127$all
 ||176.123.9.243$all
 ||176.124.7.225$all
+||176.221.251.238$all
 ||176.240.40.142$all
 ||176.240.84.106$all
 ||177.11.92.78$all
 ||177.131.226.235$all
 ||177.229.64.218$all
-||177.44.61.243$all
-||177.86.235.143$all
+||177.54.82.154$all
 ||178.124.182.187$all
-||178.141.125.98$all
+||178.134.185.112$all
 ||178.141.25.82$all
+||178.141.44.152$all
 ||178.141.45.2$all
 ||178.141.57.166$all
 ||178.150.174.65$all
 ||178.151.143.2$all
 ||178.165.122.141$all
 ||178.175.0.140$all
-||178.175.0.42$all
-||178.175.0.47$all
 ||178.175.1.139$all
-||178.175.1.143$all
 ||178.175.1.153$all
+||178.175.1.176$all
 ||178.175.1.182$all
-||178.175.1.224$all
 ||178.175.1.244$all
-||178.175.1.247$all
 ||178.175.1.249$all
 ||178.175.1.250$all
 ||178.175.1.252$all
+||178.175.1.44$all
 ||178.175.1.80$all
-||178.175.1.99$all
-||178.175.10.102$all
+||178.175.10.104$all
+||178.175.10.121$all
+||178.175.10.178$all
 ||178.175.10.34$all
 ||178.175.10.42$all
 ||178.175.10.71$all
@@ -1430,118 +1406,117 @@
 ||178.175.100.110$all
 ||178.175.100.129$all
 ||178.175.100.180$all
-||178.175.100.187$all
-||178.175.100.190$all
+||178.175.100.191$all
 ||178.175.100.218$all
 ||178.175.100.34$all
 ||178.175.100.4$all
-||178.175.100.87$all
+||178.175.100.52$all
 ||178.175.101.110$all
-||178.175.101.243$all
+||178.175.101.173$all
+||178.175.101.191$all
 ||178.175.102.134$all
-||178.175.102.152$all
-||178.175.102.190$all
+||178.175.102.14$all
 ||178.175.102.221$all
-||178.175.102.228$all
 ||178.175.102.245$all
 ||178.175.102.35$all
 ||178.175.102.53$all
 ||178.175.103.172$all
-||178.175.103.195$all
+||178.175.103.24$all
+||178.175.103.246$all
 ||178.175.103.27$all
 ||178.175.104.106$all
 ||178.175.104.110$all
 ||178.175.104.120$all
 ||178.175.104.140$all
+||178.175.104.151$all
 ||178.175.104.155$all
 ||178.175.104.16$all
-||178.175.104.169$all
-||178.175.104.183$all
-||178.175.104.196$all
+||178.175.104.199$all
 ||178.175.104.206$all
+||178.175.104.239$all
 ||178.175.104.49$all
+||178.175.105.122$all
 ||178.175.105.125$all
 ||178.175.105.146$all
 ||178.175.105.197$all
 ||178.175.105.217$all
-||178.175.105.220$all
+||178.175.105.240$all
 ||178.175.105.245$all
+||178.175.105.248$all
 ||178.175.106.104$all
 ||178.175.106.106$all
 ||178.175.106.118$all
+||178.175.106.149$all
 ||178.175.106.18$all
 ||178.175.106.193$all
+||178.175.106.36$all
 ||178.175.106.37$all
 ||178.175.106.77$all
+||178.175.106.83$all
 ||178.175.107.0$all
 ||178.175.107.133$all
 ||178.175.107.149$all
 ||178.175.107.240$all
 ||178.175.107.245$all
 ||178.175.107.83$all
+||178.175.108.65$all
 ||178.175.108.87$all
 ||178.175.108.94$all
 ||178.175.109.132$all
 ||178.175.109.140$all
+||178.175.109.227$all
 ||178.175.109.37$all
 ||178.175.109.77$all
-||178.175.11.109$all
+||178.175.11.155$all
 ||178.175.11.165$all
 ||178.175.11.176$all
-||178.175.11.184$all
 ||178.175.11.204$all
+||178.175.11.241$all
 ||178.175.11.57$all
 ||178.175.11.6$all
 ||178.175.110.155$all
 ||178.175.110.169$all
+||178.175.110.194$all
 ||178.175.110.197$all
 ||178.175.110.198$all
 ||178.175.110.221$all
-||178.175.110.250$all
 ||178.175.111.105$all
 ||178.175.111.159$all
 ||178.175.111.187$all
 ||178.175.111.190$all
-||178.175.111.203$all
+||178.175.111.195$all
 ||178.175.111.206$all
-||178.175.111.36$all
 ||178.175.111.98$all
 ||178.175.112.139$all
 ||178.175.112.147$all
 ||178.175.112.159$all
 ||178.175.112.4$all
 ||178.175.112.46$all
-||178.175.112.59$all
-||178.175.112.66$all
 ||178.175.112.85$all
-||178.175.113.174$all
 ||178.175.114.200$all
 ||178.175.114.254$all
-||178.175.114.29$all
-||178.175.114.51$all
 ||178.175.114.55$all
 ||178.175.114.63$all
 ||178.175.114.90$all
 ||178.175.114.99$all
-||178.175.115.138$all
+||178.175.115.147$all
+||178.175.115.175$all
 ||178.175.115.206$all
 ||178.175.115.208$all
+||178.175.115.88$all
+||178.175.116.101$all
+||178.175.116.170$all
 ||178.175.116.188$all
-||178.175.116.200$all
 ||178.175.116.227$all
 ||178.175.116.48$all
 ||178.175.116.64$all
-||178.175.117.209$all
-||178.175.117.215$all
+||178.175.117.12$all
 ||178.175.117.39$all
-||178.175.117.51$all
 ||178.175.118.112$all
 ||178.175.118.113$all
-||178.175.118.165$all
 ||178.175.118.192$all
 ||178.175.118.198$all
 ||178.175.118.47$all
-||178.175.118.60$all
 ||178.175.119.215$all
 ||178.175.119.237$all
 ||178.175.119.26$all
@@ -1553,53 +1528,45 @@
 ||178.175.12.40$all
 ||178.175.12.53$all
 ||178.175.12.70$all
+||178.175.12.93$all
 ||178.175.12.97$all
-||178.175.120.133$all
-||178.175.120.162$all
 ||178.175.120.184$all
-||178.175.120.196$all
 ||178.175.120.203$all
 ||178.175.120.231$all
 ||178.175.120.4$all
+||178.175.120.5$all
+||178.175.121.104$all
 ||178.175.121.116$all
-||178.175.121.122$all
 ||178.175.121.123$all
 ||178.175.121.155$all
-||178.175.121.190$all
+||178.175.121.19$all
+||178.175.121.192$all
+||178.175.121.193$all
 ||178.175.121.229$all
-||178.175.121.63$all
-||178.175.121.83$all
-||178.175.122.123$all
-||178.175.122.130$all
-||178.175.122.168$all
+||178.175.122.199$all
 ||178.175.122.201$all
+||178.175.122.208$all
 ||178.175.122.217$all
 ||178.175.122.245$all
 ||178.175.122.26$all
 ||178.175.122.28$all
 ||178.175.123.191$all
-||178.175.123.196$all
 ||178.175.123.2$all
+||178.175.123.26$all
 ||178.175.123.30$all
-||178.175.123.40$all
 ||178.175.123.56$all
 ||178.175.123.7$all
 ||178.175.123.90$all
 ||178.175.124.109$all
 ||178.175.124.122$all
-||178.175.124.131$all
 ||178.175.124.197$all
 ||178.175.124.4$all
 ||178.175.124.79$all
 ||178.175.124.89$all
-||178.175.124.9$all
 ||178.175.125.14$all
 ||178.175.125.153$all
-||178.175.125.174$all
-||178.175.125.227$all
-||178.175.125.39$all
+||178.175.125.56$all
 ||178.175.126.167$all
-||178.175.126.171$all
 ||178.175.126.220$all
 ||178.175.126.222$all
 ||178.175.126.237$all
@@ -1608,27 +1575,26 @@
 ||178.175.126.83$all
 ||178.175.126.93$all
 ||178.175.127.10$all
-||178.175.127.119$all
 ||178.175.127.122$all
 ||178.175.127.15$all
 ||178.175.127.159$all
 ||178.175.127.166$all
+||178.175.127.168$all
 ||178.175.127.176$all
+||178.175.127.219$all
 ||178.175.127.230$all
 ||178.175.127.231$all
 ||178.175.127.236$all
-||178.175.127.237$all
+||178.175.127.43$all
 ||178.175.127.63$all
 ||178.175.127.64$all
 ||178.175.127.75$all
-||178.175.13.1$all
-||178.175.13.157$all
+||178.175.127.97$all
 ||178.175.13.19$all
 ||178.175.13.220$all
 ||178.175.13.237$all
-||178.175.13.250$all
+||178.175.14.131$all
 ||178.175.14.178$all
-||178.175.14.185$all
 ||178.175.14.230$all
 ||178.175.14.60$all
 ||178.175.14.69$all
@@ -1636,11 +1602,9 @@
 ||178.175.15.199$all
 ||178.175.15.215$all
 ||178.175.15.217$all
-||178.175.15.253$all
 ||178.175.15.35$all
 ||178.175.15.45$all
 ||178.175.15.5$all
-||178.175.15.85$all
 ||178.175.16.1$all
 ||178.175.16.108$all
 ||178.175.16.114$all
@@ -1648,11 +1612,11 @@
 ||178.175.16.179$all
 ||178.175.16.221$all
 ||178.175.16.49$all
-||178.175.16.59$all
 ||178.175.16.73$all
 ||178.175.16.97$all
+||178.175.17.118$all
 ||178.175.17.245$all
-||178.175.18.93$all
+||178.175.17.66$all
 ||178.175.19.163$all
 ||178.175.19.174$all
 ||178.175.19.229$all
@@ -1660,6 +1624,7 @@
 ||178.175.2.108$all
 ||178.175.2.110$all
 ||178.175.2.123$all
+||178.175.2.186$all
 ||178.175.2.188$all
 ||178.175.2.237$all
 ||178.175.2.41$all
@@ -1668,22 +1633,21 @@
 ||178.175.2.54$all
 ||178.175.20.117$all
 ||178.175.20.170$all
-||178.175.20.225$all
 ||178.175.20.237$all
 ||178.175.20.24$all
 ||178.175.20.70$all
+||178.175.20.97$all
 ||178.175.21.149$all
-||178.175.21.170$all
 ||178.175.21.184$all
 ||178.175.21.233$all
 ||178.175.21.238$all
+||178.175.21.28$all
 ||178.175.21.76$all
 ||178.175.21.8$all
 ||178.175.22.110$all
 ||178.175.22.147$all
 ||178.175.22.237$all
 ||178.175.22.247$all
-||178.175.23.102$all
 ||178.175.23.156$all
 ||178.175.23.228$all
 ||178.175.23.250$all
@@ -1693,24 +1657,22 @@
 ||178.175.24.171$all
 ||178.175.24.172$all
 ||178.175.24.177$all
-||178.175.24.216$all
+||178.175.24.198$all
 ||178.175.24.218$all
 ||178.175.24.238$all
 ||178.175.24.243$all
 ||178.175.24.77$all
 ||178.175.25.113$all
 ||178.175.25.117$all
-||178.175.25.169$all
+||178.175.25.148$all
 ||178.175.25.177$all
 ||178.175.25.28$all
 ||178.175.25.46$all
 ||178.175.25.56$all
-||178.175.25.64$all
 ||178.175.25.75$all
 ||178.175.25.77$all
 ||178.175.26.112$all
 ||178.175.26.116$all
-||178.175.26.164$all
 ||178.175.26.165$all
 ||178.175.26.209$all
 ||178.175.26.215$all
@@ -1719,7 +1681,7 @@
 ||178.175.26.246$all
 ||178.175.26.34$all
 ||178.175.27.106$all
-||178.175.27.122$all
+||178.175.27.137$all
 ||178.175.27.138$all
 ||178.175.27.14$all
 ||178.175.27.167$all
@@ -1727,43 +1689,50 @@
 ||178.175.27.177$all
 ||178.175.27.179$all
 ||178.175.27.199$all
-||178.175.27.202$all
 ||178.175.27.215$all
 ||178.175.27.225$all
 ||178.175.27.233$all
 ||178.175.27.239$all
+||178.175.27.244$all
 ||178.175.27.32$all
 ||178.175.27.37$all
 ||178.175.27.46$all
 ||178.175.27.48$all
-||178.175.27.68$all
 ||178.175.27.69$all
 ||178.175.28.102$all
 ||178.175.28.199$all
+||178.175.28.200$all
+||178.175.28.51$all
+||178.175.28.69$all
 ||178.175.29.16$all
 ||178.175.29.173$all
 ||178.175.29.174$all
 ||178.175.29.2$all
 ||178.175.29.201$all
 ||178.175.29.207$all
+||178.175.29.208$all
 ||178.175.29.220$all
+||178.175.29.7$all
 ||178.175.3.116$all
-||178.175.3.130$all
 ||178.175.3.166$all
 ||178.175.3.172$all
 ||178.175.3.190$all
 ||178.175.3.196$all
 ||178.175.3.214$all
+||178.175.3.66$all
+||178.175.3.87$all
 ||178.175.30.0$all
 ||178.175.30.135$all
 ||178.175.30.213$all
-||178.175.30.252$all
 ||178.175.30.70$all
 ||178.175.30.93$all
 ||178.175.30.96$all
 ||178.175.31.171$all
 ||178.175.31.251$all
+||178.175.31.252$all
 ||178.175.31.6$all
+||178.175.31.99$all
+||178.175.32.14$all
 ||178.175.32.197$all
 ||178.175.32.198$all
 ||178.175.32.2$all
@@ -1771,36 +1740,38 @@
 ||178.175.32.211$all
 ||178.175.32.229$all
 ||178.175.32.243$all
+||178.175.32.244$all
 ||178.175.32.89$all
-||178.175.32.95$all
 ||178.175.33.112$all
 ||178.175.33.141$all
 ||178.175.33.162$all
 ||178.175.33.173$all
 ||178.175.33.181$all
-||178.175.33.2$all
+||178.175.33.196$all
 ||178.175.33.208$all
+||178.175.33.21$all
 ||178.175.33.215$all
 ||178.175.33.228$all
 ||178.175.33.234$all
+||178.175.33.245$all
 ||178.175.33.26$all
-||178.175.33.28$all
-||178.175.33.63$all
 ||178.175.34.1$all
 ||178.175.34.2$all
 ||178.175.34.200$all
-||178.175.34.243$all
-||178.175.35.144$all
+||178.175.34.53$all
 ||178.175.35.21$all
 ||178.175.35.38$all
 ||178.175.35.83$all
+||178.175.35.91$all
 ||178.175.36.0$all
 ||178.175.36.127$all
 ||178.175.36.129$all
+||178.175.36.184$all
 ||178.175.36.218$all
 ||178.175.36.231$all
 ||178.175.36.245$all
 ||178.175.36.33$all
+||178.175.36.5$all
 ||178.175.37.107$all
 ||178.175.37.135$all
 ||178.175.37.153$all
@@ -1809,25 +1780,26 @@
 ||178.175.37.38$all
 ||178.175.37.56$all
 ||178.175.37.6$all
+||178.175.37.71$all
 ||178.175.37.81$all
 ||178.175.37.83$all
 ||178.175.38.1$all
 ||178.175.38.132$all
-||178.175.38.141$all
 ||178.175.38.165$all
-||178.175.38.191$all
-||178.175.38.28$all
 ||178.175.38.98$all
+||178.175.39.110$all
+||178.175.39.129$all
 ||178.175.39.158$all
 ||178.175.39.245$all
 ||178.175.39.57$all
+||178.175.39.63$all
 ||178.175.4.144$all
+||178.175.4.192$all
 ||178.175.4.219$all
-||178.175.4.222$all
 ||178.175.4.231$all
+||178.175.4.233$all
 ||178.175.4.95$all
 ||178.175.40.155$all
-||178.175.40.166$all
 ||178.175.40.226$all
 ||178.175.40.228$all
 ||178.175.40.41$all
@@ -1837,12 +1809,14 @@
 ||178.175.41.203$all
 ||178.175.41.34$all
 ||178.175.42.171$all
+||178.175.42.228$all
+||178.175.42.240$all
+||178.175.42.25$all
 ||178.175.43.1$all
 ||178.175.43.106$all
 ||178.175.43.121$all
 ||178.175.43.138$all
 ||178.175.43.147$all
-||178.175.43.217$all
 ||178.175.43.30$all
 ||178.175.43.33$all
 ||178.175.43.69$all
@@ -1850,7 +1824,6 @@
 ||178.175.44.134$all
 ||178.175.44.143$all
 ||178.175.44.155$all
-||178.175.44.186$all
 ||178.175.44.197$all
 ||178.175.44.217$all
 ||178.175.44.22$all
@@ -1859,11 +1832,9 @@
 ||178.175.44.89$all
 ||178.175.44.90$all
 ||178.175.44.95$all
-||178.175.44.96$all
-||178.175.45.191$all
 ||178.175.45.205$all
+||178.175.45.25$all
 ||178.175.45.6$all
-||178.175.45.87$all
 ||178.175.46.119$all
 ||178.175.46.187$all
 ||178.175.46.224$all
@@ -1871,28 +1842,34 @@
 ||178.175.47.11$all
 ||178.175.47.141$all
 ||178.175.47.151$all
+||178.175.47.16$all
 ||178.175.47.168$all
 ||178.175.47.245$all
 ||178.175.48.110$all
 ||178.175.48.168$all
 ||178.175.49.139$all
+||178.175.49.214$all
 ||178.175.49.247$all
+||178.175.49.252$all
 ||178.175.49.3$all
 ||178.175.5.17$all
 ||178.175.5.51$all
+||178.175.5.79$all
 ||178.175.50.131$all
+||178.175.50.168$all
 ||178.175.50.177$all
 ||178.175.50.22$all
 ||178.175.50.236$all
 ||178.175.50.237$all
-||178.175.50.27$all
+||178.175.50.32$all
 ||178.175.51.137$all
 ||178.175.51.160$all
 ||178.175.51.202$all
 ||178.175.51.66$all
+||178.175.52.146$all
 ||178.175.52.161$all
+||178.175.52.21$all
 ||178.175.52.212$all
-||178.175.52.71$all
 ||178.175.52.94$all
 ||178.175.53.135$all
 ||178.175.53.151$all
@@ -1903,16 +1880,16 @@
 ||178.175.53.56$all
 ||178.175.53.58$all
 ||178.175.53.79$all
+||178.175.54.15$all
 ||178.175.54.158$all
 ||178.175.54.163$all
+||178.175.54.167$all
 ||178.175.54.205$all
-||178.175.54.214$all
 ||178.175.54.225$all
 ||178.175.54.64$all
 ||178.175.55.103$all
 ||178.175.55.14$all
 ||178.175.55.163$all
-||178.175.55.181$all
 ||178.175.55.25$all
 ||178.175.55.29$all
 ||178.175.55.38$all
@@ -1922,122 +1899,114 @@
 ||178.175.56.103$all
 ||178.175.56.11$all
 ||178.175.56.120$all
-||178.175.56.18$all
-||178.175.56.196$all
 ||178.175.56.24$all
 ||178.175.56.252$all
 ||178.175.56.33$all
 ||178.175.56.37$all
 ||178.175.56.50$all
+||178.175.56.52$all
 ||178.175.56.54$all
 ||178.175.56.72$all
 ||178.175.56.75$all
 ||178.175.57.10$all
 ||178.175.57.141$all
 ||178.175.57.179$all
+||178.175.57.99$all
 ||178.175.58.28$all
-||178.175.58.29$all
 ||178.175.58.74$all
 ||178.175.58.79$all
 ||178.175.59.161$all
+||178.175.59.241$all
 ||178.175.59.33$all
-||178.175.59.47$all
 ||178.175.59.54$all
 ||178.175.6.134$all
 ||178.175.6.157$all
 ||178.175.6.189$all
+||178.175.6.89$all
 ||178.175.60.209$all
 ||178.175.60.212$all
-||178.175.60.251$all
+||178.175.60.76$all
 ||178.175.61.156$all
 ||178.175.61.163$all
 ||178.175.61.17$all
 ||178.175.61.171$all
+||178.175.61.178$all
 ||178.175.61.219$all
 ||178.175.61.237$all
+||178.175.61.95$all
 ||178.175.62.111$all
 ||178.175.62.115$all
+||178.175.62.141$all
 ||178.175.62.166$all
 ||178.175.62.168$all
-||178.175.62.208$all
 ||178.175.62.42$all
 ||178.175.62.43$all
 ||178.175.62.70$all
 ||178.175.62.8$all
 ||178.175.62.84$all
-||178.175.63.167$all
+||178.175.63.192$all
 ||178.175.63.21$all
-||178.175.63.73$all
+||178.175.63.230$all
+||178.175.63.78$all
 ||178.175.63.96$all
 ||178.175.64.12$all
+||178.175.64.155$all
 ||178.175.64.156$all
 ||178.175.64.158$all
 ||178.175.64.187$all
+||178.175.64.190$all
 ||178.175.64.22$all
-||178.175.64.30$all
-||178.175.64.50$all
-||178.175.65.115$all
+||178.175.64.231$all
+||178.175.65.19$all
 ||178.175.65.202$all
 ||178.175.65.236$all
-||178.175.66.105$all
-||178.175.66.123$all
 ||178.175.66.186$all
 ||178.175.66.192$all
 ||178.175.66.199$all
 ||178.175.66.211$all
 ||178.175.66.228$all
-||178.175.66.43$all
 ||178.175.66.54$all
 ||178.175.66.93$all
 ||178.175.67.0$all
 ||178.175.67.36$all
 ||178.175.67.51$all
-||178.175.67.8$all
+||178.175.67.55$all
 ||178.175.67.81$all
 ||178.175.67.83$all
 ||178.175.67.89$all
-||178.175.68.109$all
+||178.175.68.116$all
 ||178.175.68.44$all
 ||178.175.68.66$all
 ||178.175.68.85$all
 ||178.175.69.111$all
-||178.175.69.112$all
 ||178.175.69.119$all
 ||178.175.69.128$all
 ||178.175.69.18$all
-||178.175.69.4$all
-||178.175.69.96$all
 ||178.175.7.6$all
 ||178.175.7.60$all
 ||178.175.7.71$all
+||178.175.70.10$all
 ||178.175.70.109$all
-||178.175.70.12$all
-||178.175.70.147$all
-||178.175.70.18$all
 ||178.175.70.196$all
 ||178.175.70.218$all
 ||178.175.70.246$all
-||178.175.70.38$all
 ||178.175.70.5$all
 ||178.175.70.50$all
-||178.175.70.64$all
 ||178.175.70.71$all
 ||178.175.70.83$all
-||178.175.71.202$all
+||178.175.70.93$all
+||178.175.71.160$all
 ||178.175.71.45$all
-||178.175.71.55$all
 ||178.175.71.84$all
 ||178.175.72.108$all
-||178.175.72.13$all
 ||178.175.72.222$all
 ||178.175.72.30$all
 ||178.175.72.37$all
-||178.175.73.127$all
-||178.175.73.77$all
+||178.175.72.47$all
 ||178.175.73.96$all
 ||178.175.74.182$all
+||178.175.74.205$all
 ||178.175.74.48$all
-||178.175.75.130$all
 ||178.175.75.181$all
 ||178.175.75.19$all
 ||178.175.75.84$all
@@ -2049,97 +2018,101 @@
 ||178.175.76.217$all
 ||178.175.76.83$all
 ||178.175.76.9$all
+||178.175.77.248$all
+||178.175.77.34$all
 ||178.175.77.46$all
 ||178.175.77.47$all
-||178.175.77.71$all
-||178.175.78.118$all
 ||178.175.78.198$all
 ||178.175.78.243$all
-||178.175.78.46$all
+||178.175.78.57$all
 ||178.175.78.97$all
 ||178.175.79.17$all
 ||178.175.79.244$all
 ||178.175.79.247$all
 ||178.175.79.69$all
 ||178.175.8.100$all
+||178.175.8.227$all
+||178.175.8.64$all
 ||178.175.80.100$all
-||178.175.80.114$all
 ||178.175.80.129$all
-||178.175.80.17$all
+||178.175.80.197$all
 ||178.175.80.20$all
-||178.175.80.35$all
 ||178.175.80.41$all
 ||178.175.80.61$all
+||178.175.80.68$all
 ||178.175.80.79$all
 ||178.175.80.86$all
-||178.175.81.17$all
+||178.175.80.89$all
+||178.175.81.19$all
 ||178.175.81.192$all
 ||178.175.81.226$all
 ||178.175.81.232$all
 ||178.175.81.244$all
 ||178.175.81.253$all
-||178.175.81.50$all
-||178.175.82.137$all
-||178.175.82.32$all
+||178.175.82.23$all
+||178.175.82.73$all
+||178.175.83.144$all
 ||178.175.83.2$all
+||178.175.83.20$all
 ||178.175.83.247$all
 ||178.175.84.102$all
-||178.175.84.109$all
 ||178.175.84.159$all
+||178.175.84.17$all
 ||178.175.84.215$all
+||178.175.84.28$all
 ||178.175.84.42$all
 ||178.175.85.153$all
 ||178.175.85.183$all
 ||178.175.85.23$all
-||178.175.85.55$all
+||178.175.85.230$all
 ||178.175.85.57$all
 ||178.175.86.119$all
+||178.175.86.122$all
 ||178.175.86.36$all
 ||178.175.86.59$all
 ||178.175.87.126$all
 ||178.175.87.139$all
 ||178.175.87.144$all
 ||178.175.87.253$all
-||178.175.87.68$all
-||178.175.88.127$all
-||178.175.88.140$all
+||178.175.88.160$all
 ||178.175.88.166$all
 ||178.175.88.181$all
 ||178.175.88.182$all
+||178.175.88.24$all
+||178.175.88.248$all
 ||178.175.88.69$all
 ||178.175.89.157$all
 ||178.175.89.169$all
-||178.175.89.24$all
+||178.175.89.30$all
 ||178.175.9.125$all
 ||178.175.9.139$all
 ||178.175.9.175$all
 ||178.175.9.179$all
-||178.175.9.183$all
 ||178.175.9.198$all
 ||178.175.9.210$all
 ||178.175.9.215$all
 ||178.175.9.225$all
+||178.175.9.64$all
 ||178.175.9.84$all
 ||178.175.9.95$all
 ||178.175.90.122$all
 ||178.175.90.167$all
 ||178.175.90.172$all
+||178.175.90.185$all
 ||178.175.90.21$all
-||178.175.90.212$all
-||178.175.90.244$all
 ||178.175.90.4$all
 ||178.175.90.74$all
+||178.175.90.81$all
+||178.175.90.90$all
 ||178.175.91.108$all
 ||178.175.91.13$all
 ||178.175.91.15$all
 ||178.175.91.244$all
 ||178.175.91.253$all
-||178.175.91.40$all
 ||178.175.91.96$all
-||178.175.92.128$all
 ||178.175.92.132$all
-||178.175.92.141$all
 ||178.175.92.186$all
+||178.175.92.200$all
 ||178.175.92.215$all
 ||178.175.92.231$all
 ||178.175.92.253$all
@@ -2148,37 +2121,32 @@
 ||178.175.93.143$all
 ||178.175.93.150$all
 ||178.175.93.159$all
-||178.175.93.34$all
-||178.175.93.45$all
+||178.175.93.199$all
+||178.175.93.44$all
 ||178.175.93.62$all
-||178.175.93.93$all
 ||178.175.94.195$all
 ||178.175.94.200$all
+||178.175.94.27$all
 ||178.175.94.40$all
 ||178.175.94.55$all
+||178.175.95.116$all
 ||178.175.95.141$all
+||178.175.95.163$all
 ||178.175.95.17$all
 ||178.175.95.227$all
-||178.175.95.237$all
 ||178.175.95.4$all
 ||178.175.95.56$all
-||178.175.96.169$all
-||178.175.96.192$all
-||178.175.97.1$all
+||178.175.96.81$all
 ||178.175.97.128$all
 ||178.175.97.135$all
-||178.175.97.143$all
-||178.175.97.78$all
+||178.175.98.216$all
 ||178.175.98.228$all
 ||178.175.98.254$all
 ||178.175.98.29$all
-||178.175.98.36$all
+||178.175.98.44$all
 ||178.175.98.68$all
 ||178.175.99.123$all
 ||178.175.99.130$all
-||178.175.99.22$all
-||178.175.99.45$all
-||178.175.99.88$all
 ||178.175.99.91$all
 ||178.19.183.14$all
 ||178.205.101.33$all
@@ -2193,6 +2161,7 @@
 ||178.95.136.35$all
 ||179.159.58.134$all
 ||179.4.187.39$all
+||179.42.107.139$all
 ||179.43.157.173$all
 ||179.60.84.7$all
 ||179.99.210.161$all
@@ -2205,7 +2174,6 @@
 ||180.125.44.194$all
 ||180.157.66.204$all
 ||180.175.236.209$all
-||180.175.93.52$all
 ||180.176.105.41$all
 ||180.176.110.243$all
 ||180.176.165.230$all
@@ -2216,6 +2184,7 @@
 ||180.177.242.73$all
 ||180.218.5.171$all
 ||180.248.80.38$all
+||180.253.99.109$all
 ||180.66.111.36$all
 ||180.66.53.93$all
 ||180.94.170.166$all
@@ -2226,123 +2195,131 @@
 ||181.193.107.10$all
 ||181.199.170.222$all
 ||181.199.170.230$all
-||181.199.170.240$all
 ||181.210.45.42$all
 ||181.215.47.82$all
 ||181.224.242.131$all
 ||181.49.236.4$all
 ||181.49.59.162$all
+||182.112.28.118$all
+||182.112.34.220$all
 ||182.112.43.249$all
 ||182.112.52.131$all
+||182.113.238.197$all
+||182.113.29.28$all
+||182.114.105.40$all
 ||182.114.111.64$all
-||182.114.24.20$all
-||182.114.49.104$all
 ||182.114.64.27$all
+||182.114.76.42$all
 ||182.114.79.103$all
 ||182.114.83.88$all
 ||182.114.92.90$all
 ||182.114.93.96$all
-||182.116.101.82$all
-||182.116.103.234$all
 ||182.116.104.106$all
-||182.116.108.180$all
+||182.116.105.208$all
 ||182.116.108.244$all
+||182.116.116.70$all
 ||182.116.118.250$all
+||182.116.119.66$all
+||182.116.36.175$all
 ||182.116.60.73$all
 ||182.116.61.252$all
 ||182.116.80.107$all
 ||182.116.94.196$all
 ||182.116.99.150$all
+||182.117.13.57$all
 ||182.117.15.172$all
 ||182.117.25.120$all
 ||182.117.26.235$all
 ||182.117.29.220$all
 ||182.117.39.51$all
 ||182.117.43.27$all
+||182.117.49.127$all
 ||182.118.146.181$all
+||182.118.166.128$all
 ||182.119.100.135$all
 ||182.119.109.173$all
 ||182.119.118.218$all
 ||182.119.14.252$all
+||182.119.15.78$all
 ||182.119.166.208$all
-||182.119.176.209$all
+||182.119.166.76$all
+||182.119.179.193$all
+||182.119.197.123$all
+||182.119.202.180$all
+||182.119.21.68$all
 ||182.119.211.69$all
 ||182.119.214.120$all
 ||182.119.221.141$all
-||182.119.225.30$all
+||182.119.226.84$all
 ||182.119.255.115$all
 ||182.119.7.54$all
+||182.119.89.107$all
 ||182.120.16.22$all
 ||182.120.16.46$all
-||182.120.33.117$all
 ||182.120.37.251$all
 ||182.120.43.0$all
-||182.121.11.43$all
 ||182.121.129.163$all
-||182.121.130.67$all
-||182.121.133.46$all
 ||182.121.134.70$all
-||182.121.158.141$all
+||182.121.15.223$all
+||182.121.157.35$all
 ||182.121.205.201$all
 ||182.121.205.237$all
 ||182.121.207.195$all
-||182.121.40.234$all
-||182.121.50.111$all
+||182.121.254.147$all
+||182.121.55.106$all
 ||182.121.66.189$all
 ||182.121.9.117$all
 ||182.121.94.13$all
-||182.122.181.105$all
 ||182.122.202.18$all
 ||182.123.203.21$all
 ||182.123.211.239$all
+||182.123.241.195$all
 ||182.124.123.107$all
 ||182.124.177.48$all
 ||182.124.19.87$all
+||182.124.201.207$all
 ||182.124.88.122$all
 ||182.126.113.127$all
-||182.126.120.66$all
+||182.126.123.19$all
 ||182.126.126.203$all
 ||182.126.127.254$all
-||182.126.181.121$all
-||182.126.52.233$all
 ||182.126.67.24$all
-||182.126.80.108$all
 ||182.126.83.79$all
 ||182.126.88.138$all
+||182.127.0.16$all
 ||182.127.103.79$all
 ||182.127.104.235$all
-||182.127.110.147$all
+||182.127.106.43$all
 ||182.127.152.3$all
 ||182.127.155.157$all
-||182.127.209.26$all
 ||182.127.221.243$all
+||182.127.93.38$all
 ||182.160.98.250$all
 ||182.172.36.164$all
 ||182.233.0.252$all
 ||182.235.252.31$all
 ||182.53.197.62$all
-||182.58.219.8$all
+||182.56.193.251$all
+||182.59.235.150$all
 ||183.105.104.83$all
 ||183.105.225.154$all
 ||183.109.169.45$all
 ||183.11.238.228$all
 ||183.136.252.233$all
-||183.150.138.131$all
 ||183.150.244.122$all
 ||183.16.208.30$all
 ||183.185.112.19$all
+||183.185.162.225$all
 ||183.187.163.176$all
 ||183.188.151.225$all
 ||183.188.180.116$all
 ||183.188.188.186$all
 ||183.188.228.38$all
+||183.188.93.116$all
 ||183.83.105.21$all
-||183.83.125.235$all
 ||183.83.127.89$all
 ||183.83.26.115$all
-||183.83.99.87$all
 ||183.92.195.140$all
-||183.95.147.102$all
 ||183.97.22.14$all
 ||184.164.185.41$all
 ||184.175.115.10$all
@@ -2384,14 +2361,11 @@
 ||186.225.120.173$all
 ||186.232.44.86$all
 ||186.28.60.184$all
-||186.33.112.218$all
-||186.33.112.228$all
-||186.33.112.66$all
-||186.33.113.241$all
 ||186.33.113.77$all
 ||186.4.125.48$all
 ||186.73.188.132$all
 ||187.12.10.98$all
+||187.188.124.229$all
 ||187.212.200.162$all
 ||187.233.208.103$all
 ||187.33.71.68$all
@@ -2399,12 +2373,12 @@
 ||188.10.231.246$all
 ||188.113.102.18$all
 ||188.113.81.17$all
+||188.119.45.194$all
 ||188.13.179.87$all
 ||188.138.200.32$all
 ||188.152.41.141$all
 ||188.169.178.50$all
-||188.169.199.59$all
-||188.169.36.163$all
+||188.169.179.151$all
 ||188.169.45.140$all
 ||188.242.167.159$all
 ||188.242.242.144$all
@@ -2438,6 +2412,7 @@
 ||190.216.140.123$all
 ||190.35.225.36$all
 ||190.65.206.162$all
+||190.73.12.149$all
 ||190.92.4.231$all
 ||190.98.37.135$all
 ||190.98.37.200$all
@@ -2445,7 +2420,6 @@
 ||191.255.248.220$all
 ||192.210.175.130$all
 ||192.210.241.200$all
-||192.227.185.106$all
 ||192.227.209.27$all
 ||192.227.220.55$all
 ||192.227.228.67$all
@@ -2454,6 +2428,7 @@
 ||192.99.240.77$all
 ||193.142.146.25$all
 ||193.228.135.144$all
+||193.38.55.9$all
 ||193.91.131.237$all
 ||194.147.142.230$all
 ||194.15.36.167$all
@@ -2470,7 +2445,6 @@
 ||197.50.27.115$all
 ||198.23.133.218$all
 ||198.23.207.121$all
-||198.23.213.57$all
 ||198.23.251.105$all
 ||198.251.72.110$all
 ||198.46.201.76$all
@@ -2482,7 +2456,9 @@
 ||2.45.111.158$all
 ||2.45.4.24$all
 ||2.55.125.182$all
+||2.58.69.44$all
 ||2.83.152.16$all
+||20.185.42.197$all
 ||20.dbstrony.pl$all
 ||200.105.167.98$all
 ||200.111.189.70$all
@@ -2495,17 +2471,16 @@
 ||201.187.102.73$all
 ||201.200.254.86$all
 ||201.203.221.20$all
+||201.203.27.37$all
 ||201.215.84.97$all
 ||201.218.97.142$all
 ||202.107.233.41$all
+||202.150.176.100$all
 ||202.164.153.80$all
 ||202.166.217.54$all
 ||202.169.234.22$all
 ||202.169.234.37$all
-||202.169.234.47$all
 ||202.169.234.52$all
-||202.169.234.55$all
-||202.169.234.9$all
 ||202.29.95.12$all
 ||202.4.124.58$all
 ||202.51.176.114$all
@@ -2513,12 +2488,10 @@
 ||202.74.236.9$all
 ||203.109.201.243$all
 ||203.130.69.205$all
-||203.170.115.82$all
 ||203.189.156.107$all
 ||203.204.232.18$all
 ||203.229.21.56$all
 ||203.236.190.28$all
-||203.238.86.202$all
 ||203.70.166.107$all
 ||203.77.80.159$all
 ||203.80.119.166$all
@@ -2528,7 +2501,6 @@
 ||203.93.6.28$all
 ||204.195.116.171$all
 ||205.185.115.74$all
-||205.185.123.217$all
 ||206.248.137.132$all
 ||206.47.41.166$all
 ||207.5.32.6$all
@@ -2540,6 +2512,7 @@
 ||210.124.149.19$all
 ||210.216.152.122$all
 ||210.216.153.142$all
+||210.57.234.131$all
 ||210.57.234.93$all
 ||210.57.237.70$all
 ||210.57.245.109$all
@@ -2561,6 +2534,7 @@
 ||211.247.113.49$all
 ||211.247.5.96$all
 ||211.36.174.137$all
+||211.47.102.51$all
 ||211.51.174.149$all
 ||212.122.86.105$all
 ||212.143.227.22$all
@@ -2575,11 +2549,11 @@
 ||213.149.190.193$all
 ||213.163.104.12$all
 ||213.163.104.138$all
-||213.163.104.160$all
+||213.163.104.7$all
 ||213.163.104.99$all
+||213.163.113.100$all
 ||213.163.113.135$all
 ||213.163.113.225$all
-||213.163.113.23$all
 ||213.163.113.237$all
 ||213.163.113.51$all
 ||213.163.114.155$all
@@ -2591,7 +2565,9 @@
 ||213.163.115.33$all
 ||213.163.115.71$all
 ||213.163.116.132$all
+||213.163.116.181$all
 ||213.163.116.192$all
+||213.163.116.197$all
 ||213.163.116.203$all
 ||213.163.116.33$all
 ||213.163.116.85$all
@@ -2600,21 +2576,21 @@
 ||213.163.117.97$all
 ||213.163.118.129$all
 ||213.163.118.144$all
+||213.163.118.236$all
 ||213.163.118.238$all
-||213.163.118.65$all
 ||213.163.119.24$all
 ||213.163.119.240$all
-||213.163.126.104$all
 ||213.163.126.20$all
 ||213.163.126.243$all
+||213.163.126.249$all
 ||213.163.126.60$all
 ||213.163.126.7$all
 ||213.163.126.84$all
 ||213.163.127.204$all
 ||213.163.127.217$all
+||213.163.127.242$all
 ||213.163.127.46$all
 ||213.189.178.163$all
-||213.226.140.23$all
 ||213.240.218.15$all
 ||213.249.156.189$all
 ||213.27.8.6$all
@@ -2642,6 +2618,7 @@
 ||218.35.81.81$all
 ||218.48.135.50$all
 ||218.56.93.129$all
+||218.57.109.48$all
 ||218.57.53.55$all
 ||218.59.116.203$all
 ||218.72.198.15$all
@@ -2649,33 +2626,37 @@
 ||218.93.102.63$all
 ||218.93.102.75$all
 ||219.154.103.40$all
-||219.154.114.132$all
 ||219.154.114.45$all
 ||219.154.115.250$all
+||219.154.116.168$all
 ||219.154.126.205$all
+||219.154.142.35$all
+||219.154.143.132$all
 ||219.154.147.58$all
 ||219.154.148.116$all
 ||219.154.173.163$all
+||219.154.178.138$all
+||219.154.41.36$all
 ||219.155.102.14$all
+||219.155.11.252$all
 ||219.155.113.58$all
 ||219.155.14.17$all
-||219.155.170.22$all
+||219.155.209.253$all
 ||219.155.24.246$all
 ||219.155.243.184$all
 ||219.155.26.204$all
-||219.155.26.37$all
 ||219.155.29.165$all
 ||219.155.31.15$all
 ||219.155.31.67$all
-||219.155.42.216$all
+||219.155.86.156$all
 ||219.155.98.64$all
 ||219.156.131.116$all
-||219.156.167.103$all
 ||219.156.17.217$all
+||219.156.176.153$all
 ||219.156.23.29$all
 ||219.156.60.224$all
+||219.156.65.47$all
 ||219.156.88.219$all
-||219.156.9.32$all
 ||219.157.11.39$all
 ||219.157.146.200$all
 ||219.157.147.87$all
@@ -2683,8 +2664,8 @@
 ||219.157.178.201$all
 ||219.157.178.210$all
 ||219.157.183.29$all
+||219.157.214.235$all
 ||219.157.223.241$all
-||219.157.223.245$all
 ||219.157.42.228$all
 ||219.157.67.171$all
 ||219.241.6.180$all
@@ -2692,6 +2673,7 @@
 ||219.68.1.84$all
 ||219.68.163.7$all
 ||219.68.171.144$all
+||219.68.245.63$all
 ||219.68.251.32$all
 ||219.68.5.140$all
 ||219.69.71.186$all
@@ -2703,21 +2685,21 @@
 ||220.133.30.200$all
 ||220.200.22.163$all
 ||220.71.239.115$all
+||220.90.159.188$all
 ||221.1.162.82$all
 ||221.124.78.15$all
-||221.14.11.33$all
 ||221.14.122.127$all
 ||221.14.165.237$all
+||221.14.185.105$all
 ||221.14.47.162$all
-||221.14.58.5$all
+||221.14.47.189$all
+||221.14.57.175$all
 ||221.15.108.55$all
+||221.15.112.103$all
 ||221.15.125.190$all
-||221.15.127.124$all
-||221.15.147.220$all
-||221.15.21.133$all
-||221.15.212.123$all
+||221.15.155.186$all
+||221.15.190.2$all
 ||221.15.234.159$all
-||221.15.236.211$all
 ||221.15.237.107$all
 ||221.15.250.213$all
 ||221.15.253.236$all
@@ -2731,8 +2713,10 @@
 ||221.196.12.96$all
 ||221.198.167.192$all
 ||221.2.190.22$all
+||221.202.232.230$all
 ||221.214.130.147$all
 ||221.214.224.184$all
+||221.214.251.109$all
 ||221.215.116.167$all
 ||221.215.172.207$all
 ||221.215.184.31$all
@@ -2757,52 +2741,50 @@
 ||222.135.219.29$all
 ||222.135.26.161$all
 ||222.135.67.115$all
-||222.136.49.252$all
 ||222.136.53.227$all
+||222.136.77.190$all
 ||222.137.101.251$all
 ||222.137.101.33$all
 ||222.137.121.127$all
 ||222.137.137.5$all
 ||222.137.138.252$all
 ||222.137.148.192$all
-||222.137.160.202$all
+||222.137.161.88$all
 ||222.137.172.250$all
 ||222.137.198.247$all
+||222.137.220.215$all
+||222.137.237.203$all
 ||222.137.239.124$all
 ||222.137.49.36$all
-||222.137.5.150$all
-||222.137.57.234$all
+||222.137.53.193$all
 ||222.137.72.146$all
-||222.137.85.26$all
 ||222.137.96.9$all
+||222.138.118.192$all
 ||222.138.143.84$all
 ||222.138.151.100$all
 ||222.138.189.138$all
 ||222.138.201.241$all
-||222.138.23.254$all
+||222.138.213.235$all
+||222.138.226.142$all
 ||222.138.96.79$all
-||222.139.16.229$all
-||222.140.129.239$all
+||222.139.106.55$all
 ||222.140.162.140$all
 ||222.140.163.112$all
 ||222.140.17.245$all
+||222.140.179.142$all
+||222.140.208.18$all
 ||222.140.209.222$all
-||222.140.254.11$all
 ||222.140.39.66$all
+||222.141.101.39$all
 ||222.141.120.26$all
 ||222.141.13.77$all
-||222.141.44.36$all
-||222.141.73.249$all
+||222.141.40.69$all
+||222.141.46.119$all
 ||222.141.9.0$all
-||222.142.162.164$all
 ||222.142.192.66$all
 ||222.142.209.231$all
-||222.142.209.7$all
-||222.142.245.207$all
 ||222.179.215.189$all
 ||222.185.116.233$all
-||222.186.20.19$all
-||222.187.184.136$all
 ||222.187.9.178$all
 ||222.211.72.66$all
 ||222.214.54.208$all
@@ -2811,7 +2793,7 @@
 ||222.238.230.7$all
 ||222.239.83.232$all
 ||222.248.64.253$all
-||222.83.150.240$all
+||222.81.156.229$all
 ||222.92.9.126$all
 ||222.99.171.192$all
 ||223.166.117.210$all
@@ -2856,7 +2838,7 @@
 ||27.141.218.17$all
 ||27.147.29.52$all
 ||27.147.40.128$all
-||27.153.207.1$all
+||27.153.142.115$all
 ||27.184.244.14$all
 ||27.184.54.199$all
 ||27.187.248.22$all
@@ -2864,7 +2846,6 @@
 ||27.193.196.190$all
 ||27.193.217.210$all
 ||27.194.149.142$all
-||27.194.158.229$all
 ||27.194.192.66$all
 ||27.194.210.20$all
 ||27.197.17.88$all
@@ -2890,13 +2871,11 @@
 ||27.203.165.138$all
 ||27.203.175.203$all
 ||27.203.185.42$all
-||27.203.185.48$all
 ||27.203.213.79$all
 ||27.203.246.96$all
 ||27.203.255.42$all
 ||27.203.28.115$all
 ||27.203.4.188$all
-||27.203.54.217$all
 ||27.203.68.144$all
 ||27.203.87.75$all
 ||27.203.94.134$all
@@ -2920,11 +2899,10 @@
 ||27.208.164.18$all
 ||27.208.166.13$all
 ||27.208.201.212$all
-||27.208.214.139$all
 ||27.208.247.130$all
 ||27.208.25.59$all
 ||27.208.34.2$all
-||27.208.46.167$all
+||27.208.70.115$all
 ||27.208.92.64$all
 ||27.209.160.222$all
 ||27.209.231.15$all
@@ -2940,6 +2918,7 @@
 ||27.213.109.105$all
 ||27.213.109.58$all
 ||27.213.145.221$all
+||27.213.166.50$all
 ||27.213.167.175$all
 ||27.213.175.208$all
 ||27.213.220.5$all
@@ -2952,6 +2931,7 @@
 ||27.215.212.209$all
 ||27.215.212.80$all
 ||27.215.253.149$all
+||27.215.27.143$all
 ||27.215.34.242$all
 ||27.215.38.119$all
 ||27.215.38.166$all
@@ -2966,7 +2946,6 @@
 ||27.216.227.95$all
 ||27.216.234.98$all
 ||27.216.46.85$all
-||27.216.58.120$all
 ||27.216.95.56$all
 ||27.217.120.226$all
 ||27.217.133.53$all
@@ -3001,23 +2980,30 @@
 ||27.35.154.13$all
 ||27.35.212.124$all
 ||27.35.58.5$all
-||27.41.143.46$all
+||27.41.159.28$all
+||27.41.37.155$all
+||27.41.9.105$all
 ||27.41.9.44$all
+||27.41.97.36$all
+||27.43.108.78$all
+||27.43.111.161$all
+||27.43.117.66$all
+||27.46.23.10$all
 ||27.46.44.130$all
-||27.46.44.161$all
+||27.46.44.153$all
+||27.46.45.86$all
 ||27.46.46.100$all
 ||27.46.46.252$all
-||27.5.23.215$all
-||27.5.34.254$all
-||27.5.46.18$all
-||27.6.195.65$all
-||27.6.240.125$all
-||27.6.242.65$all
+||27.5.23.69$all
+||27.5.47.16$all
+||27.6.240.171$all
+||27.6.38.96$all
 ||31.0.98.131$all
 ||31.11.51.57$all
 ||31.13.23.180$all
 ||31.154.234.3$all
 ||31.163.191.11$all
+||31.168.124.130$all
 ||31.168.179.83$all
 ||31.168.184.59$all
 ||31.168.191.243$all
@@ -3038,11 +3024,13 @@
 ||31.30.119.23$all
 ||32.208.157.193$all
 ||32.218.180.9$all
+||32792.prolocksmithwinterpark.com$all
 ||35.184.169.169$all
 ||36.108.231.218$all
 ||36.250.203.246$all
 ||36.251.157.225$all
 ||36.251.18.18$all
+||36.251.18.63$all
 ||36.251.19.88$all
 ||36.251.51.244$all
 ||36.255.90.219$all
@@ -3050,10 +3038,13 @@
 ||36.33.160.167$all
 ||36.34.150.236$all
 ||36.36.243.67$all
+||36.43.11.16$all
 ||36.66.105.159$all
 ||36.66.111.203$all
 ||36.66.133.125$all
 ||36.66.139.36$all
+||36.67.152.161$all
+||36.81.23.38$all
 ||36.89.18.133$all
 ||36.96.187.93$all
 ||360.lcy2zzx.pw$all
@@ -3108,9 +3099,11 @@
 ||39.77.150.203$all
 ||39.77.197.81$all
 ||39.77.209.209$all
+||39.77.48.213$all
 ||39.77.94.189$all
 ||39.77.95.50$all
 ||39.79.146.67$all
+||39.79.163.188$all
 ||39.79.166.31$all
 ||39.79.218.46$all
 ||39.79.62.43$all
@@ -3122,6 +3115,7 @@
 ||39.80.205.255$all
 ||39.80.24.54$all
 ||39.80.36.151$all
+||39.80.37.182$all
 ||39.81.251.0$all
 ||39.81.27.15$all
 ||39.81.29.231$all
@@ -3141,17 +3135,14 @@
 ||39.86.216.144$all
 ||39.86.234.187$all
 ||39.86.248.91$all
-||39.86.60.98$all
 ||39.86.66.24$all
 ||39.86.73.100$all
-||39.86.78.228$all
 ||39.87.63.58$all
 ||39.87.90.210$all
 ||39.87.93.109$all
 ||39.88.141.172$all
 ||39.88.155.96$all
 ||39.88.233.131$all
-||39.88.41.73$all
 ||39.88.67.238$all
 ||39.88.72.9$all
 ||39.89.146.198$all
@@ -3166,66 +3157,84 @@
 ||41.219.185.171$all
 ||41.230.31.58$all
 ||41.72.203.82$all
+||41.86.18.133$all
 ||41.86.18.148$all
-||41.86.18.200$all
+||41.86.18.157$all
+||41.86.18.164$all
+||41.86.18.165$all
 ||41.86.18.71$all
-||41.86.21.23$all
-||41.86.5.233$all
-||41.86.5.236$all
+||41.86.19.206$all
+||41.86.19.80$all
+||41.86.21.38$all
+||41.86.21.44$all
+||41.86.21.62$all
+||41.86.5.142$all
+||41.86.5.198$all
+||41.86.5.206$all
 ||42.176.112.72$all
 ||42.177.164.171$all
 ||42.179.162.208$all
 ||42.179.163.177$all
 ||42.202.101.147$all
+||42.224.122.183$all
 ||42.224.122.39$all
-||42.224.169.111$all
 ||42.224.171.104$all
 ||42.224.172.125$all
-||42.224.18.165$all
+||42.224.188.223$all
+||42.224.189.79$all
 ||42.224.19.55$all
 ||42.224.220.37$all
 ||42.224.233.247$all
 ||42.224.234.23$all
 ||42.224.245.91$all
 ||42.224.249.160$all
+||42.224.249.188$all
+||42.224.3.187$all
 ||42.224.36.220$all
-||42.224.56.81$all
+||42.224.52.81$all
+||42.224.68.72$all
 ||42.224.69.11$all
 ||42.224.70.213$all
 ||42.225.120.122$all
 ||42.225.205.191$all
 ||42.225.241.5$all
-||42.226.89.25$all
 ||42.227.194.95$all
 ||42.227.196.123$all
 ||42.227.66.88$all
-||42.228.39.232$all
+||42.228.196.68$all
 ||42.228.40.56$all
 ||42.228.60.114$all
 ||42.228.67.135$all
 ||42.228.68.118$all
 ||42.228.70.126$all
 ||42.228.70.231$all
-||42.228.84.206$all
-||42.230.153.183$all
-||42.230.219.175$all
+||42.230.218.252$all
 ||42.230.25.164$all
+||42.230.46.55$all
 ||42.230.48.162$all
-||42.231.95.195$all
+||42.231.95.247$all
 ||42.232.102.163$all
-||42.232.23.76$all
+||42.232.46.169$all
+||42.233.159.21$all
 ||42.233.78.236$all
-||42.233.90.183$all
+||42.234.247.41$all
 ||42.234.85.184$all
 ||42.235.23.163$all
-||42.235.3.187$all
-||42.235.82.129$all
-||42.235.86.211$all
+||42.235.67.162$all
+||42.235.82.112$all
+||42.235.87.100$all
 ||42.235.90.32$all
 ||42.235.95.254$all
 ||42.236.148.201$all
+||42.237.142.157$all
+||42.237.24.151$all
 ||42.237.252.159$all
+||42.237.60.73$all
+||42.238.228.0$all
+||42.239.155.147$all
+||42.239.202.121$all
 ||42.239.21.27$all
+||42.239.218.137$all
 ||42.239.98.70$all
 ||42.242.200.90$all
 ||42.56.15.227$all
@@ -3234,6 +3243,7 @@
 ||42.87.29.162$all
 ||43.230.156.44$all
 ||43.241.106.183$all
+||43.252.8.94$all
 ||45.133.1.137$all
 ||45.133.1.139$all
 ||45.133.1.242$all
@@ -3248,10 +3258,13 @@
 ||45.144.225.65$all
 ||45.148.10.47$all
 ||45.148.10.94$all
+||45.165.215.19$all
 ||45.176.108.116$all
+||45.176.108.164$all
 ||45.176.108.22$all
 ||45.176.108.248$all
 ||45.176.110.99$all
+||45.176.111.119$all
 ||45.176.111.154$all
 ||45.176.111.16$all
 ||45.176.111.202$all
@@ -3267,10 +3280,10 @@
 ||45.81.235.31$all
 ||45.9.148.37$all
 ||46.151.155.218$all
+||46.161.185.15$all
 ||46.172.75.231$all
 ||46.175.184.121$all
 ||46.182.173.246$all
-||46.182.173.247$all
 ||46.20.63.218$all
 ||46.21.153.231$all
 ||46.214.27.4$all
@@ -3292,7 +3305,6 @@
 ||49.142.87.36$all
 ||49.143.32.36$all
 ||49.143.43.93$all
-||49.156.35.166$all
 ||49.158.201.200$all
 ||49.159.20.121$all
 ||49.159.21.3$all
@@ -3303,13 +3315,14 @@
 ||49.68.221.252$all
 ||49.68.249.121$all
 ||49.70.15.16$all
+||49.70.95.181$all
 ||5.146.202.18$all
 ||5.181.135.114$all
 ||5.2.70.50$all
+||5.42.37.74$all
 ||5.53.146.179$all
 ||5.8.10.62$all
 ||50.115.174.102$all
-||50.115.174.106$all
 ||50.121.91.255$all
 ||50.252.47.29$all
 ||51.171.146.13$all
@@ -3317,6 +3330,7 @@
 ||54.36.114.136$all
 ||54.36.180.122$all
 ||58.114.246.26$all
+||58.115.108.164$all
 ||58.115.162.92$all
 ||58.115.174.4$all
 ||58.125.191.4$all
@@ -3331,7 +3345,6 @@
 ||58.218.67.253$all
 ||58.22.212.107$all
 ||58.226.129.29$all
-||58.229.194.122$all
 ||58.23.245.24$all
 ||58.230.89.42$all
 ||58.238.42.192$all
@@ -3340,92 +3353,57 @@
 ||58.241.78.55$all
 ||58.243.126.133$all
 ||58.248.112.254$all
-||58.248.140.46$all
+||58.248.117.238$all
+||58.248.142.5$all
 ||58.248.143.240$all
-||58.248.144.122$all
-||58.248.144.88$all
-||58.248.147.235$all
-||58.248.151.128$all
+||58.248.144.229$all
+||58.248.147.196$all
+||58.248.151.33$all
 ||58.248.153.224$all
-||58.248.76.23$all
+||58.248.74.240$all
 ||58.248.77.38$all
-||58.248.82.34$all
 ||58.249.12.80$all
 ||58.249.14.53$all
 ||58.249.16.173$all
 ||58.249.19.127$all
-||58.249.23.58$all
-||58.249.73.182$all
-||58.249.74.197$all
+||58.249.72.88$all
+||58.249.74.243$all
 ||58.249.74.245$all
-||58.249.75.107$all
-||58.249.75.158$all
+||58.249.75.213$all
 ||58.249.77.88$all
-||58.249.79.62$all
+||58.249.80.25$all
 ||58.249.82.35$all
-||58.249.86.11$all
-||58.249.87.54$all
-||58.249.88.218$all
+||58.249.87.171$all
+||58.249.89.158$all
 ||58.252.176.71$all
-||58.253.13.50$all
+||58.255.133.161$all
+||58.255.140.150$all
 ||58.48.154.143$all
 ||58.50.221.148$all
 ||58.72.165.153$all
 ||58.72.165.39$all
 ||58.76.151.189$all
+||58.76.151.51$all
 ||58.97.206.33$all
 ||59.0.211.161$all
 ||59.102.168.189$all
+||59.127.11.50$all
 ||59.151.202.3$all
 ||59.151.214.4$all
+||59.151.246.125$all
 ||59.29.133.229$all
-||59.32.97.190$all
-||59.42.62.0$all
 ||59.45.235.176$all
 ||59.58.104.244$all
 ||59.58.117.226$all
 ||59.7.124.148$all
 ||59.8.35.22$all
-||59.92.176.186$all
-||59.92.18.43$all
-||59.92.181.100$all
-||59.92.182.21$all
-||59.92.182.84$all
-||59.92.218.209$all
-||59.92.218.254$all
-||59.93.17.66$all
-||59.93.18.37$all
-||59.93.22.45$all
-||59.94.180.222$all
-||59.94.181.124$all
-||59.94.183.163$all
-||59.95.174.230$all
-||59.95.175.37$all
-||59.96.38.154$all
-||59.96.38.182$all
-||59.97.168.127$all
-||59.97.169.111$all
-||59.97.169.173$all
-||59.97.171.61$all
-||59.97.172.0$all
-||59.97.173.49$all
-||59.97.174.151$all
-||59.97.175.163$all
-||59.99.136.22$all
-||59.99.136.63$all
-||59.99.138.83$all
-||59.99.139.190$all
-||59.99.141.237$all
-||59.99.40.173$all
-||59.99.40.27$all
-||59.99.41.192$all
-||59.99.44.136$all
-||59.99.44.201$all
-||59.99.44.5$all
-||59.99.47.220$all
-||59.99.47.96$all
-||59.99.93.136$all
-||59.99.94.181$all
+||59.92.180.232$all
+||59.92.217.35$all
+||59.94.180.230$all
+||59.96.37.181$all
+||59.96.37.192$all
+||59.96.39.222$all
+||59.97.193.255$all
 ||60.13.61.12$all
 ||60.14.48.221$all
 ||60.16.247.78$all
@@ -3443,6 +3421,7 @@
 ||60.211.19.63$all
 ||60.211.6.112$all
 ||60.212.100.83$all
+||60.212.111.39$all
 ||60.212.162.152$all
 ||60.212.202.218$all
 ||60.212.206.246$all
@@ -3453,6 +3432,8 @@
 ||60.213.162.59$all
 ||60.213.58.188$all
 ||60.213.83.55$all
+||60.214.217.96$all
+||60.214.32.17$all
 ||60.214.73.6$all
 ||60.214.93.166$all
 ||60.215.165.64$all
@@ -3466,15 +3447,15 @@
 ||60.25.115.48$all
 ||60.25.76.224$all
 ||60.253.15.104$all
-||60.253.39.88$all
+||60.253.4.72$all
 ||60.253.42.72$all
 ||60.253.51.127$all
-||60.253.8.81$all
 ||60.26.17.221$all
 ||60.7.10.121$all
 ||60.7.8.43$all
 ||60.7.99.254$all
 ||61.102.243.124$all
+||61.130.195.121$all
 ||61.162.169.210$all
 ||61.162.55.42$all
 ||61.163.142.96$all
@@ -3482,52 +3463,49 @@
 ||61.179.171.60$all
 ||61.179.91.194$all
 ||61.179.91.230$all
-||61.18.112.48$all
 ||61.192.73.253$all
 ||61.213.118.28$all
 ||61.247.224.66$all
 ||61.253.94.230$all
-||61.3.124.126$all
-||61.3.124.8$all
-||61.3.127.102$all
-||61.3.149.89$all
+||61.3.124.125$all
+||61.3.151.60$all
 ||61.47.220.169$all
 ||61.52.103.144$all
+||61.52.103.217$all
+||61.52.109.9$all
 ||61.52.11.87$all
 ||61.52.159.231$all
+||61.52.167.66$all
 ||61.52.195.226$all
+||61.52.210.53$all
+||61.52.211.61$all
 ||61.52.212.191$all
 ||61.52.214.11$all
+||61.52.234.193$all
 ||61.52.237.212$all
 ||61.52.242.56$all
+||61.52.30.172$all
+||61.52.4.214$all
+||61.52.42.174$all
 ||61.52.48.40$all
 ||61.52.76.72$all
 ||61.52.9.166$all
 ||61.52.9.62$all
+||61.52.98.22$all
 ||61.52.99.161$all
-||61.53.100.87$all
 ||61.53.102.137$all
 ||61.53.117.115$all
 ||61.53.119.161$all
 ||61.53.122.161$all
 ||61.53.123.162$all
 ||61.53.192.49$all
-||61.53.2.35$all
 ||61.53.201.162$all
-||61.53.54.255$all
-||61.53.72.250$all
-||61.53.81.18$all
-||61.53.99.179$all
 ||61.54.103.56$all
 ||61.54.168.35$all
 ||61.54.232.45$all
 ||61.54.40.202$all
-||61.54.58.190$all
 ||61.54.58.20$all
-||61.54.63.23$all
 ||61.54.64.104$all
-||61.54.76.122$all
-||61.54.77.175$all
 ||61.56.180.67$all
 ||61.56.181.7$all
 ||61.57.96.116$all
@@ -3572,17 +3550,18 @@
 ||67.3.169.223$all
 ||67.8.138.101$all
 ||67.81.98.111$all
-||67.82.242.243$all
 ||67.83.49.234$all
 ||67.84.138.165$all
 ||68.151.244.128$all
 ||68.174.182.226$all
 ||68.175.107.153$all
+||68.183.25.71$all
 ||68.188.144.143$all
 ||68.204.88.29$all
 ||68.205.106.84$all
 ||68.205.119.241$all
 ||68.78.33.33$all
+||68468438438.xyz$all
 ||69.115.37.205$all
 ||69.120.237.255$all
 ||69.123.245.151$all
@@ -3606,7 +3585,6 @@
 ||71.127.148.69$all
 ||71.146.190.91$all
 ||71.167.164.113$all
-||71.19.150.93$all
 ||71.204.63.239$all
 ||71.29.48.164$all
 ||71.34.191.213$all
@@ -3624,16 +3602,17 @@
 ||72.214.69.226$all
 ||72.229.230.118$all
 ||72.229.35.40$all
+||72.31.40.122$all
 ||73.204.216.103$all
 ||74.101.1.159$all
 ||74.108.224.112$all
+||74.116.216.141$all
 ||74.194.117.165$all
 ||74.195.115.176$all
 ||74.199.84.77$all
 ||74.64.139.223$all
 ||74.75.165.81$all
 ||75.127.141.52$all
-||75.176.213.114$all
 ||75.83.102.27$all
 ||75.99.213.61$all
 ||76.108.199.153$all
@@ -3648,6 +3627,7 @@
 ||77.71.52.220$all
 ||77.79.191.32$all
 ||77.89.203.238$all
+||77.94.89.20$all
 ||78.186.155.18$all
 ||78.187.141.144$all
 ||78.187.240.125$all
@@ -3700,7 +3680,6 @@
 ||82.80.154.214$all
 ||82.80.187.109$all
 ||82.81.100.54$all
-||82.81.106.65$all
 ||82.81.108.172$all
 ||82.81.131.158$all
 ||82.81.19.42$all
@@ -3723,9 +3702,9 @@
 ||84.210.219.208$all
 ||84.210.219.213$all
 ||84.212.219.127$all
-||84.224.162.170$all
 ||84.228.50.118$all
 ||84.228.95.204$all
+||84.238.24.35$all
 ||84.247.83.74$all
 ||84.254.39.129$all
 ||84.33.111.227$all
@@ -3745,6 +3724,7 @@
 ||85.97.195.129$all
 ||86.35.43.220$all
 ||87.61.89.40$all
+||87du.vip$all
 ||88.119.171.253$all
 ||88.2.208.71$all
 ||88.2.219.179$all
@@ -3758,7 +3738,6 @@
 ||88.250.254.90$all
 ||89.122.183.130$all
 ||89.29.213.33$all
-||89.34.26.165$all
 ||89.35.62.96$all
 ||89.40.85.166$all
 ||89.40.87.5$all
@@ -3780,7 +3759,6 @@
 ||92.114.191.82$all
 ||92.241.78.114$all
 ||92.27.246.202$all
-||92.54.237.143$all
 ||92.54.237.237$all
 ||92.83.62.139$all
 ||92.85.18.138$all
@@ -3803,6 +3781,7 @@
 ||95.153.241.63$all
 ||95.154.20.231$all
 ||95.158.19.130$all
+||95.170.113.227$all
 ||95.170.113.52$all
 ||95.170.201.34$all
 ||95.181.155.112$all
@@ -3812,7 +3791,6 @@
 ||95.9.120.40$all
 ||96.239.73.246$all
 ||96.47.147.169$all
-||97.103.64.196$all
 ||97.68.140.254$all
 ||97.96.199.75$all
 ||98.0.210.218$all
@@ -3826,7 +3804,6 @@
 ||98.30.24.54$all
 ||99.150.245.203$all
 ||99.33.195.164$all
-||99centsdigitals.com$all
 ||abcd.bg$all
 ||abclicks.in$all
 ||abissnet.net$all
@@ -3834,6 +3811,7 @@
 ||absoftechworld.com$all
 ||absupplies.co.uk$all
 ||abyssos.eu$all
+||academyshademani.com$all
 ||acbick.com$all
 ||accounts.thesmarttechhub.com$all
 ||aceeprc.com.aceeprc.com$all
@@ -3862,7 +3840,9 @@
 ||aiqtest.com$all
 ||ajpharmaholding.com$all
 ||ajstudiollc.com$all
+||akauk09.top$all
 ||akivj07.top$all
+||akpgi08.top$all
 ||al-wahd.com$all
 ||alasdemariposas.org$all
 ||alemelektronik.com$all
@@ -3898,6 +3878,7 @@
 ||api.cstdevs.com$all
 ||api.quocbao.biz$all
 ||api.sampy.io$all
+||aplicativoparasindicato.com.br$all
 ||apoolcondo.com$all
 ||app.adsensearticle.com$all
 ||app.explicitsurveys.co.uk$all
@@ -3905,7 +3886,6 @@
 ||apps.saintsoporte.com$all
 ||aqv.news$all
 ||areyoulivingwell.com$all
-||arsapetrolab.com$all
 ||artedibujoyarquitectura.com$all
 ||ask-regard.call-save.biz$all
 ||atfile.com$all
@@ -3916,14 +3896,13 @@
 ||atteuqpotentialunlimited.com$all
 ||augustair.com$all
 ||aulist.com$all
-||australiafashions.com$all
 ||automaticrefreshments.com$all
 ||avadhanagames.com$all
-||avissrilanka.com$all
 ||ayamallah.com$all
 ||azmeasurement.com$all
 ||azraktours.com$all
 ||b2b.toptanakaryakit.com.tr$all
+||b4ad7b79-534a-4e83-953e-c36da8cf27d9.s3.amazonaws.com/ww/setup.exe$all
 ||backgrounds.pk$all
 ||badeggdesign.com$all
 ||balealgodon.mx$all
@@ -3954,7 +3933,6 @@
 ||birdi.elin.co.za$all
 ||birminghamlink.org$all
 ||bitbucket.org/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe$all
-||bitbucket.org/densjons/bro/downloads/rew.exe$all
 ||bitbucket.org/dvdfv/anjj/downloads/jami.exe$all
 ||bitbucket.org/jpavelski/chpock/downloads/4.exe$all
 ||bitbucket.org/jpavelski/chpock/downloads/6.exe$all
@@ -4037,12 +4015,12 @@
 ||blog.oyinblogs.com$all
 ||blog.takbelit.com$all
 ||bmlifestyle.co.uk$all
-||bnrbook.com$all
 ||bnrnews.id$all
 ||bodenstein.co.za$all
 ||booksearch.com$all
 ||bounces.mi-fs.com$all
 ||bpo.correct.go.th$all
+||bradleyinstitute.co.za$all
 ||brandtrust.com.pk$all
 ||brendanquine.com$all
 ||brideofmessiah.com$all
@@ -4053,8 +4031,6 @@
 ||browardinsurancemiami.solucioneslink.com$all
 ||bt2.elin.co.za$all
 ||btdapi.robotake.com$all
-||bucrinsuranlceonlines.com$all
-||buenavista.co$all
 ||buigiaphat.com.vn$all
 ||bullseyemedia.in$all
 ||busandvanrentalmalaysia.com$all
@@ -4081,8 +4057,13 @@
 ||cdaonline.com.ar$all
 ||cdn.discordapp.com/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq$all
 ||cdn.discordapp.com/attachments/816070119281131570/816070273254162442/all.txt$all
+||cdn.discordapp.com/attachments/821809080812437507/824392185902006272/mmp1_1.exe$all
 ||cdn.discordapp.com/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso$all
+||cdn.discordapp.com/attachments/823810712891555890/824413943526195210/runpetest.exe$all
+||cdn.discordapp.com/attachments/824689793140129857/824690065988386816/sendhookfile.exe$all
+||cdn.discordapp.com/attachments/824689793140129857/824691026852970496/photo.exe$all
 ||cec.asso.ac-amiens.fr$all
+||cecra.cl$all
 ||cellas.sk$all
 ||cendekiabinaaksara.com$all
 ||cespol-bote.com.mx$all
@@ -4090,8 +4071,6 @@
 ||ch.rmu.ac.th$all
 ||changematterscounselling.com$all
 ||chardhamdodham.com$all
-||cheacrilnsurances.com$all
-||chealablilitycarinsurances.com$all
 ||chezalice.co.za$all
 ||childselect.com$all
 ||chinhdropfile.myvnc.com$all
@@ -4116,11 +4095,9 @@
 ||constructoralyon.com$all
 ||consulateins.solucioneslink.com$all
 ||contributeindustry.com$all
-||controladoradeplagasmm.com$all
 ||controleautomacao.com.br$all
 ||copelandscapes.com$all
 ||coulsongraphics.com$all
-||coutler.newreadermedia.net$all
 ||covid19.cyberschool.or.id$all
 ||cr-sq.com$all
 ||craftnesia.id$all
@@ -4173,14 +4150,16 @@
 ||destinymc.co.za$all
 ||detorre.es$all
 ||dev-interestingtech.pantheonsite.io$all
-||dev.sayse-tienda.com$all
 ||dev.sebpo.net$all
+||dezcom.com$all
 ||dfcf.91756.cn$all
-||dfsfcsfcdsfsdvcfsvcscv.com$all
 ||diamantenegro.mi-fs.com$all
 ||dienmayminhhung.com$all
 ||digilib.dianhusada.ac.id$all
+||digitalassets.ams3.digitaloceanspaces.com/hold/schost.exe$all
+||digitalassets.ams3.digitaloceanspaces.com/modern/five.exe$all
 ||djking.f3322.net$all
+||dl-link.link$all
 ||dl.1003b.56a.com$all
 ||dl.198424.com$all
 ||dl.installcdn-aws.com$all
@@ -4193,9 +4172,7 @@
 ||docs.google.com/uc?id=11jnyjpzkjiie_rzc4xwa2feok3x__yvc$all
 ||docs.google.com/uc?id=151uxflny3vqh_lmghrkgjhhsqxi163sh$all
 ||docs.google.com/uc?id=15iwonkjkhyvri_okkc_llq56aasvnvb9$all
-||docs.google.com/uc?id=16gqndqbduwuhy3qzxdn2nd9nufm_9ctq$all
 ||docs.google.com/uc?id=1ak46tqftzejmq-og_ky2oupgpmkgujtm$all
-||docs.google.com/uc?id=1b6stzilakqykxaw1ct2w9hzccizwotff$all
 ||docs.google.com/uc?id=1brsmnj6g0lxa44ixkypvg5tcxkvi5gjt$all
 ||docs.google.com/uc?id=1by_s4vv8gdmmz8wl-lbpjbjy5adcrjk1$all
 ||docs.google.com/uc?id=1dpsxfbptpyl-zegto9t29vvcku2rjm9u$all
@@ -4204,15 +4181,11 @@
 ||docs.google.com/uc?id=1erajjbz6gdxhsvvorlykzxyeoq-xu7wn$all
 ||docs.google.com/uc?id=1ev7gkzwjgtv2vlbbisg1ragd7nf0-xog$all
 ||docs.google.com/uc?id=1ey8zl85vszh-gdmubkoudacqs6zv2dup$all
-||docs.google.com/uc?id=1f5trx90ulgsd-m1zvdupuf_kfugoo9ye$all
 ||docs.google.com/uc?id=1gq_jf503du9oip5bwzcoi6_kgolr3kx2$all
-||docs.google.com/uc?id=1hlaoow8ug5gjejeeihwetcxyfjodcdut$all
 ||docs.google.com/uc?id=1imrv00kqbfz4ljzwq5qdau1to0zlmaqy$all
 ||docs.google.com/uc?id=1j6pvg1rznjh9pkldcyjiogo8ysiyl8_y$all
 ||docs.google.com/uc?id=1jlcqojhfhgifmirrsv0o5t-2rl-hblai$all
-||docs.google.com/uc?id=1jvvuxwek4wrjqs94bjm8_klnnngj7b5r$all
 ||docs.google.com/uc?id=1k6sh5h-nptesem_jsnuxmhzntnvdlgxz$all
-||docs.google.com/uc?id=1lc8lpsmu5ndjweyusqrxblm0g84sdcc7$all
 ||docs.google.com/uc?id=1lk6n-xrtv0dvdqljl26pzebxzp8tladk$all
 ||docs.google.com/uc?id=1lkcqgpimry4yp8grinnhsotnawquozcz$all
 ||docs.google.com/uc?id=1m34mp1cggxz-cz3a5ipjrgfog_qx8myx$all
@@ -4220,29 +4193,19 @@
 ||docs.google.com/uc?id=1m8w1y1-mxxa2pktrzkwfetwjxrlw1alo$all
 ||docs.google.com/uc?id=1m9jxzqcbnb8j8uph1qfcas8b9pngcogj$all
 ||docs.google.com/uc?id=1mdnlxs6vy5qk-u4dxz9movem4j3a3o-8$all
-||docs.google.com/uc?id=1o6omlk34dxy3cbai8rvkvrnp5g-ovsj-$all
 ||docs.google.com/uc?id=1od6gtslxvylgyeujmrbvm9yhupmq_1lv$all
 ||docs.google.com/uc?id=1ozpasp-mr-e-ui4lshy4qy4a2pl8pxsi$all
-||docs.google.com/uc?id=1pnmkgw-rlm9mjstqdxfcq0en07_x93ue$all
 ||docs.google.com/uc?id=1q0edpjr7vgo_ytns7dgjcav6317juz9y$all
 ||docs.google.com/uc?id=1q5gqeinogsri3i-ynlgvu88ajqnn9siq$all
 ||docs.google.com/uc?id=1quyiobd7-d-vcddlhxiqbqrwxyg7ongo$all
-||docs.google.com/uc?id=1qyzpbxbnmnbp5opdk5rmeplmbga9c_q9$all
 ||docs.google.com/uc?id=1rrtyvouwizor2icbcoywdid4w9rwngxi$all
 ||docs.google.com/uc?id=1sao6yxf-a0t6wdgdr36srwlju57vigx_$all
-||docs.google.com/uc?id=1sbg8kdmxp5futgje5jcfvh-ieq28holg$all
-||docs.google.com/uc?id=1seb4h5c8z5jaf2_ulvhdv7mzqzmntp0k$all
-||docs.google.com/uc?id=1skuwjvkgsmicbr1o48gnalcksfytwtdp$all
 ||docs.google.com/uc?id=1st5mtgqyofsskuhlomfihfmz_qx-i32o$all
+||docs.google.com/uc?id=1u5q84w84g_x98ti4uflzhrgvzzfyj_qi$all
 ||docs.google.com/uc?id=1umz5zjobot9__v2jxdutyborb2az90hz$all
 ||docs.google.com/uc?id=1we-h5qtxj9czhkhzvzg0qqpxufgu_v__$all
-||docs.google.com/uc?id=1wmi0gpfe9ebcgai4w6iw6pninxo6ke-m$all
 ||docs.google.com/uc?id=1wurpipyf0s__fqtn1ov619nx7v1-tcy3$all
 ||docs.google.com/uc?id=1wwkqbfluu4qusqz26ewulr48zh9vzq-w$all
-||docs.google.com/uc?id=1xbvceq1wmfjad59zyxwtykzy3xwy9iqb$all
-||docs.google.com/uc?id=1xqcnagjbut3pdajnpsx0nonhla3nqes-$all
-||docs.google.com/uc?id=1xsj8d2ysnoluawhk3g4tadaoyp8ktmab$all
-||docs.google.com/uc?id=1xtflvdimom8odrygcmip7j4aesrjtgsm$all
 ||docs.google.com/uc?id=1yyuejm8cerrq2tctsibww4uetepcmh4i$all
 ||dodsonimaging.com$all
 ||dokan.blueberrytec.com$all
@@ -4257,7 +4220,6 @@
 ||dovberger.com$all
 ||down.flash-plays.com$all
 ||down.pcclear.com$all
-||down.udashi.com$all
 ||down.webbora.com$all
 ||down1.arpun.com$all
 ||download.caihong.com$all
@@ -4305,6 +4267,7 @@
 ||dsenterprize.co.za$all
 ||dsspainting.com$all
 ||du-wizards.com$all
+||duckrambo.com$all
 ||duque.guantanameratravel.com$all
 ||dutapp.wisolve.co.za$all
 ||duvalcharter.dekitout.com$all
@@ -4316,7 +4279,6 @@
 ||ebruyatkin.com$all
 ||econews.treegle.org$all
 ||efficientegroup.com$all
-||elliot.newreadermedia.net$all
 ||en.baoend.com$all
 ||enc-tech.com$all
 ||endurotanzania.co.tz$all
@@ -4341,7 +4303,6 @@
 ||exxonabnie.ir/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//$all
 ||exxonabnie.ir/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///$all
 ||exxonabnie.ir/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////$all
-||f1sol.com$all
 ||familydentist.site$all
 ||farmaciasdrogaminas.com.br$all
 ||fate3.xyz$all
@@ -4355,6 +4316,7 @@
 ||files.martellexpress.us$all
 ||final.makkahkmcc.com$all
 ||fineartgallerym.com$all
+||fixauto.illumetechnology.com$all
 ||fkd.derpcity.ru$all
 ||flintspin.com$all
 ||flyingbuddhadesign.com$all
@@ -4364,7 +4326,6 @@
 ||footweardirect.elin.co.za$all
 ||forum.mdb.nu$all
 ||fotoobjetivo.com$all
-||foundationrepairhoustontx.net$all
 ||foxeps.com.br$all
 ||freecnetdownload.com$all
 ||freedombookshop.tickme.lk$all
@@ -4386,7 +4347,6 @@
 ||ghislain.dartois.pagesperso-orange.fr$all
 ||giadungg7.com$all
 ||giddos.ga$all
-||gilliem.com$all
 ||girotexuniformes.com$all
 ||gist.githubusercontent.com/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe$all
 ||giteletropical.com$all
@@ -4403,6 +4363,7 @@
 ||goldcupmortgage.com$all
 ||golden-memories-funerals.yourpageserver.com$all
 ||goldmen.in$all
+||gracejukes.com$all
 ||grupoinmare.com$all
 ||gruposelt.000webhostapp.com$all
 ||gs.monerorx.com$all
@@ -4413,6 +4374,7 @@
 ||harshraval.in$all
 ||hd11315.com$all
 ||hdkamera2003.hu$all
+||hdrest.fastlinktz.com$all
 ||hds.sz4h.com$all
 ||healthy20.net$all
 ||heavymaq.cl$all
@@ -4433,7 +4395,6 @@
 ||homefindersolutions.com$all
 ||hongluosi.com$all
 ||hookedupboatclub.com$all
-||hostelkielce.com$all
 ||hostzaa.com$all
 ||houstonshutters.site$all
 ||hqdecig.com/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/$all
@@ -4456,7 +4417,6 @@
 ||iesanjosemonitos.edu.co$all
 ||ikexpert.com$all
 ||ilrafrica.com$all
-||images.jermiau.com$all
 ||imbueautoworx.co.za$all
 ||incodimsa.com$all
 ||incrediblepixels.com$all
@@ -4476,8 +4436,10 @@
 ||intuitiveideas.com.my$all
 ||inversiones.arrayanfinanciero.cl$all
 ||invest.xpcorporative.com.br$all
+||investinae.com$all
 ||ipmes.ma$all
 ||iremart.es$all
+||iris101.co.uk$all
 ||isaac.mikhailmotoringschool.com$all
 ||iscamenabe.com$all
 ||ismf.com.ng$all
@@ -4488,7 +4450,6 @@
 ||it123.ru$all
 ||itc-demo.softgig.co.ke$all
 ||itconsultus.com.co$all
-||jamesjorgensen.newreadermedia.net$all
 ||jamiekaylive.com$all
 ||jamshed.pk$all
 ||jansen-heesch.nl$all
@@ -4497,7 +4458,6 @@
 ||jcedu.org/ebook/cs17.exe$all
 ||jebs.net.au$all
 ||jeffdahlke.com$all
-||jewsjuice.com$all
 ||jhayesconsulting.com$all
 ||jiaoyuzixun.cn$all
 ||jing-da.com.tw$all
@@ -4515,16 +4475,13 @@
 ||jpwoodfordco.com$all
 ||jumpmanualjacobhiller.com$all
 ||jupiter.toxsl.in$all
-||jurgensen.newreadermedia.net$all
 ||justinscott.com.au$all
 ||justlficante.mediafire.com/file/jl01o54yy09qrzg/fac215.tgz/file$all
-||kaizenjanitorial.com$all
 ||kalawatihomes.com$all
 ||kalpataru-elitus-mulund.thakkers.in$all
 ||karer.by$all
 ||karmakoincodes.weebly.com/uploads/3/2/8/8/3288864/karma_koin_codes.exe$all
 ||katanvetov.co.il$all
-||kbdom.com$all
 ||kensingtondriving.com$all
 ||kevinjewelry.com.co$all
 ||keywatch.yourpageserver.com$all
@@ -4532,7 +4489,6 @@
 ||kjcpromo.com$all
 ||kleinendeli.co.za$all
 ||korrectconceptservices.com$all
-||kotakwarna.co.id/dg/etrac/nf4emwz/$all
 ||ksh.hu/docs/adatgyujtesek/elektra/csv_to_xml.exe$all
 ||ktb.sch.id$all
 ||kuaizip.com/down/affiliate/kuaizip_setup_10029.exe$all
@@ -4566,7 +4522,6 @@
 ||lindnerelektroanlagen.de$all
 ||linkintec.cn$all
 ||linuxforensicsbook.com.s3.amazonaws.com/linuxforensicscode.zip$all
-||litroxlitro.com$all
 ||livetrack.in$all
 ||lloydsindian.co.uk$all
 ||lm.stagingarea.co.za$all
@@ -4580,11 +4535,8 @@
 ||logotypfabriken.se$all
 ||lotix.de$all
 ||lotusanddragonfly.com$all
-||lp.carrduci.com$all
 ||lp.definerisco.com$all
 ||lp.difusodesign.com$all
-||lp.juancamilogarciareyes.com$all
-||lp.tecnimasdecolombia.com.co$all
 ||ltc.typoten.com$all
 ||luckybrownie.com$all
 ||luminouspneuma.com$all
@@ -4614,6 +4566,7 @@
 ||materialescantu.com$all
 ||matruchhaya.co.in$all
 ||mattysplayground.com$all
+||maxiquim.cl$all
 ||maxtox.com.pk$all
 ||mbgrm.com$all
 ||mbsolutions.ge$all
@@ -4623,6 +4576,7 @@
 ||mediamaster.co.za$all
 ||medianews.ge$all
 ||medistaffconsulting.com$all
+||meditreat.itwebservice.in$all
 ||meeweb.com$all
 ||megamart.afnan-amc.com$all
 ||merbay.ru$all
@@ -4700,7 +4654,6 @@
 ||nikanpolimer.ir$all
 ||nilehouse.co.ug$all
 ||nilinkeji.com$all
-||nisacooks.com$all
 ||njtiledesigncenter.com$all
 ||nobius.org$all
 ||nocalnoodle.elin.co.za$all
@@ -4716,7 +4669,6 @@
 ||nyeh2o.com.au$all
 ||oakleyandfriends.co.uk$all
 ||obseques-conseils.com$all
-||ocean.tecnasulstore.com.br$all
 ||ohe.ie$all
 ||ohsewgorgeous.co.uk$all
 ||oknoplastik.sk$all
@@ -4759,6 +4711,7 @@
 ||onedrive.live.com/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4$all
 ||onedrive.live.com/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma$all
 ||onedrive.live.com/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48$all
+||onedrive.live.com/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq$all
 ||onedrive.live.com/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg$all
 ||onedrive.live.com/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw$all
 ||onedrive.live.com/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq$all
@@ -4796,6 +4749,7 @@
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4$all
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0$all
+||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0$all
@@ -4872,8 +4826,6 @@
 ||onedrive.live.com/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy$all
 ||onedrive.live.com/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw$all
 ||onedrive.live.com/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw$all
-||onedrive.live.com/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8$all
-||onedrive.live.com/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c$all
 ||onedrive.live.com/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y$all
 ||onedrive.live.com/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg$all
 ||onedrive.live.com/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns$all
@@ -4884,6 +4836,7 @@
 ||onedrive.live.com/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4$all
 ||onedrive.live.com/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm$all
 ||onedrive.live.com/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu$all
+||onedrive.live.com/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8$all
 ||onedrive.live.com/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8$all
 ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc$all
 ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y$all
@@ -4905,6 +4858,7 @@
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa$all
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu$all
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c$all
+||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy$all
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q$all
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm$all
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4$all
@@ -4944,7 +4898,6 @@
 ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq$all
 ||onedrive.live.com/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g$all
 ||onedrive.live.com/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum$all
-||onedrive.live.com/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa$all
 ||onedrive.live.com/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi$all
 ||onedrive.live.com/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy$all
 ||onedrive.live.com/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o$all
@@ -4967,6 +4920,7 @@
 ||onedrive.live.com/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg$all
 ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai$all
 ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc$all
+||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai$all
 ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc$all
 ||onedrive.live.com/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw$all
 ||onedrive.live.com/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8$all
@@ -5025,10 +4979,6 @@
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w$all
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta$all
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em$all
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!210&authkey=agpl0pgvft8faaa$all
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c$all
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa$all
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c$all
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto$all
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum$all
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto$all
@@ -5132,6 +5082,7 @@
 ||onedrive.live.com/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk$all
 ||onedrive.live.com/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw$all
 ||onedrive.live.com/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc$all
+||onedrive.live.com/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc$all
 ||onedrive.live.com/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e$all
 ||onedrive.live.com/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks$all
 ||onedrive.live.com/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks$all
@@ -5216,13 +5167,6 @@
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy$all
 ||onedrive.live.com/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774!124&authkey=afq42wqejwvcv8o$all
 ||onedrive.live.com/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774%21124&authkey=afq42wqejwvcv8o$all
-||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na$all
-||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8$all
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o$all
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0$all
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o$all
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0$all
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw$all
 ||onedrive.live.com/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe$all
 ||onedrive.live.com/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq$all
 ||onedrive.live.com/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4$all
@@ -5349,7 +5293,6 @@
 ||payments.atifsiddiqui.me$all
 ||pcsoori.com$all
 ||pd.oceaniarp.net$all
-||perpus.onlineman7-jombang.sch.id$all
 ||perpustekim.untirta.ac.id$all
 ||petercollie.com$all
 ||ph4s.ru$all
@@ -5372,6 +5315,7 @@
 ||poulman.panagiotopoulos-tours.gr$all
 ||ppdb.smk-ciptaskill.sch.id$all
 ||pptvideotemplates.com$all
+||prestasicash.com.ar$all
 ||prestigehomeautomation.net$all
 ||prishaartcreations.com$all
 ||procrossover.ru/wp-content/uploads/2020/10/skoda22.jpg$all
@@ -5387,7 +5331,6 @@
 ||prosyarmakassar.com$all
 ||provence.elin.co.za$all
 ||prueba.danielluza.com$all
-||ptpmeccatronica.eu$all
 ||pujashoppe.in$all
 ||punchdialogues.com$all
 ||punjabdevelopersassociation.com.pk$all
@@ -5455,7 +5398,6 @@
 ||rsgym.net$all
 ||rubazar.pro$all
 ||rubycityvietnam.com$all
-||ruch.newreadermedia.net$all
 ||ruisgood.ru$all
 ||ruwadalkuwait.com$all
 ||rydchile.cl$all
@@ -5490,6 +5432,7 @@
 ||serendibsourcing.com$all
 ||servicemhkd.myvnc.com$all
 ||servicemhkd80.myvnc.com$all
+||serviciovirtual.com.ar$all
 ||seyranikenger.com.tr$all
 ||sgessy.com.br$all
 ||shaheentbfoundation.com$all
@@ -5504,7 +5447,6 @@
 ||shopsofe.com$all
 ||shrushtiinfotech.com$all
 ||sibernetix.fr$all
-||siddharthpanditpautra.com$all
 ||sige.brisainformatica.com.br$all
 ||signatureads.co.in$all
 ||siili.net$all
@@ -5556,7 +5498,8 @@
 ||statsres.com$all
 ||statssound.com$all
 ||statsspot.com$all
-||stattilion.bar$all
+||statsvilla.com$all
+||stemschool.net$all
 ||stiepancasetia.ac.id$all
 ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt$all
 ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt$all
@@ -5578,13 +5521,13 @@
 ||supermercadostia.com$all
 ||support-4-free.com$all
 ||support.clz.kr$all
+||supportit.online$all
 ||sw.yourpageserver.com$all
 ||sweaty.dk$all
 ||sweet-diet.com$all
 ||swentsai.com$all
 ||swiftlogisticseg.com$all
 ||swwbia.com$all
-||syedpro.dezinetimes.com$all
 ||syracusecoffee.com$all
 ||sys.pbmadu.co.id$all
 ||sytraders.co$all
@@ -5598,6 +5541,7 @@
 ||tapalkoedacoffee.com$all
 ||tarravalleyfoods.com.au$all
 ||taurus.ug$all
+||tavo.cl$all
 ||taxicabsrilanka.com$all
 ||taxpos.com$all
 ||tc.snpsresidential.com$all
@@ -5619,6 +5563,7 @@
 ||test.letraele.es$all
 ||test.typoten.com$all
 ||test.wanepghana.org$all
+||test1.asistencia247.com$all
 ||test1.milenial.id$all
 ||test1.tenplusone.my$all
 ||test2.basis-web.com$all
@@ -5687,7 +5632,7 @@
 ||unisoftcc.com$all
 ||unyazitelecom.com$all
 ||upcbpta.com$all
-||urbane.dezinetimes.com$all
+||urbantrapfest.cl$all
 ||useformoney.000webhostapp.com$all
 ||users.skynet.be/crisanar/defis/jek_crackme1.7.zip$all
 ||usmadetshirts.com$all
@@ -5697,7 +5642,6 @@
 ||vcah.co.uk$all
 ||vegadelcasero.cl$all
 ||vendas.lidiacarmeli.com.br$all
-||verify.aicosoft.com$all
 ||vfocus.net$all
 ||vidmattic.com$all
 ||vienen.gblix.srv.br$all
@@ -5717,6 +5661,7 @@
 ||vokasi.ub.ac.id$all
 ||vologroup.com.br$all
 ||voteyouramerica.dekitout.com$all
+||vpinversiones.cl$all
 ||vstsample.com$all
 ||vtube.fadlymotivator.com$all
 ||vvsskmodinationalschool.com$all
@@ -5779,6 +5724,5 @@
 ||yskadvisors.com$all
 ||yummyyogaudaipur.com$all
 ||yzkzixun.com$all
-||zakra.tecnasulstore.com.br$all
 ||zytrox.tk$all
 ||zz.690tx.com$all
diff --git a/urlhaus-filter-ag.txt b/urlhaus-filter-ag.txt
index 60755ec6..4c46f2ab 100644
--- a/urlhaus-filter-ag.txt
+++ b/urlhaus-filter-ag.txt
@@ -1,5 +1,5 @@
 ! Title: Malicious URL Blocklist (AdGuard)
-! Updated: Sat, 27 Mar 2021 12:12:22 UTC
+! Updated: Sun, 28 Mar 2021 00:12:34 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1867,6 +1867,7 @@
 ||101.108.142.60$all
 ||101.108.142.75$all
 ||101.108.142.82$all
+||101.108.142.9$all
 ||101.108.143.105$all
 ||101.108.143.110$all
 ||101.108.143.137$all
@@ -2393,6 +2394,7 @@
 ||101.66.80.23$all
 ||101.66.80.72$all
 ||101.66.81.166$all
+||101.66.81.70$all
 ||101.67.176.237$all
 ||101.67.180.154$all
 ||101.67.198.121$all
@@ -2972,6 +2974,7 @@
 ||103.126.100.31$all
 ||103.126.100.9$all
 ||103.126.217.58$all
+||103.126.35.40$all
 ||103.127.104.16$all
 ||103.127.104.165$all
 ||103.127.104.184$all
@@ -4275,6 +4278,7 @@
 ||103.245.48.197$all
 ||103.245.49.135$all
 ||103.245.49.147$all
+||103.245.49.180$all
 ||103.245.49.183$all
 ||103.245.49.204$all
 ||103.245.49.24$all
@@ -8722,6 +8726,7 @@
 ||107.173.160.139$all
 ||107.173.160.14$all
 ||107.173.171.123$all
+||107.173.171.143$all
 ||107.173.171.168$all
 ||107.173.175.135$all
 ||107.173.176.100$all
@@ -12359,6 +12364,7 @@
 ||112.122.63.240$all
 ||112.122.63.54$all
 ||112.122.63.6$all
+||112.122.63.70$all
 ||112.122.63.9$all
 ||112.122.90.208$all
 ||112.122.99.186$all
@@ -14454,6 +14460,7 @@
 ||112.235.188.86$all
 ||112.235.194.43$all
 ||112.235.210.15$all
+||112.235.210.251$all
 ||112.235.217.106$all
 ||112.235.217.213$all
 ||112.235.219.224$all
@@ -16833,6 +16840,7 @@
 ||112.242.96.25$all
 ||112.242.96.4$all
 ||112.242.96.56$all
+||112.242.97.131$all
 ||112.242.97.165$all
 ||112.242.97.195$all
 ||112.242.98.194$all
@@ -16887,6 +16895,7 @@
 ||112.245.177.136$all
 ||112.245.177.145$all
 ||112.245.177.215$all
+||112.245.178.153$all
 ||112.245.179.96$all
 ||112.245.182.56$all
 ||112.245.182.9$all
@@ -17215,6 +17224,7 @@
 ||112.247.156.74$all
 ||112.247.158.19$all
 ||112.247.16.190$all
+||112.247.16.222$all
 ||112.247.161.45$all
 ||112.247.161.83$all
 ||112.247.163.177$all
@@ -17282,6 +17292,7 @@
 ||112.247.248.76$all
 ||112.247.249.198$all
 ||112.247.249.82$all
+||112.247.25.42$all
 ||112.247.250.193$all
 ||112.247.250.96$all
 ||112.247.251.11$all
@@ -18714,6 +18725,7 @@
 ||112.254.125.2$all
 ||112.254.127.63$all
 ||112.254.128.119$all
+||112.254.128.160$all
 ||112.254.128.224$all
 ||112.254.129.79$all
 ||112.254.129.95$all
@@ -18817,6 +18829,7 @@
 ||112.254.188.12$all
 ||112.254.188.137$all
 ||112.254.188.19$all
+||112.254.188.228$all
 ||112.254.188.35$all
 ||112.254.189.137$all
 ||112.254.189.16$all
@@ -21507,6 +21520,7 @@
 ||113.116.177.248$all
 ||113.116.177.29$all
 ||113.116.177.81$all
+||113.116.177.90$all
 ||113.116.178.100$all
 ||113.116.178.133$all
 ||113.116.178.138$all
@@ -22346,6 +22360,7 @@
 ||113.116.89.25$all
 ||113.116.89.29$all
 ||113.116.89.40$all
+||113.116.89.41$all
 ||113.116.89.45$all
 ||113.116.89.55$all
 ||113.116.89.82$all
@@ -22700,6 +22715,7 @@
 ||113.118.159.142$all
 ||113.118.159.144$all
 ||113.118.159.153$all
+||113.118.159.178$all
 ||113.118.159.215$all
 ||113.118.159.22$all
 ||113.118.159.232$all
@@ -23153,6 +23169,7 @@
 ||113.118.87.84$all
 ||113.118.87.88$all
 ||113.119.36.91$all
+||113.119.37.141$all
 ||113.119.85.16$all
 ||113.122.238.68$all
 ||113.122.32.245$all
@@ -26887,6 +26904,7 @@
 ||113.88.39.104$all
 ||113.88.39.194$all
 ||113.88.39.2$all
+||113.88.39.21$all
 ||113.88.39.35$all
 ||113.88.39.37$all
 ||113.88.39.55$all
@@ -27595,6 +27613,7 @@
 ||113.90.26.54$all
 ||113.90.26.6$all
 ||113.90.27.178$all
+||113.90.27.218$all
 ||113.90.92.191$all
 ||113.90.93.98$all
 ||113.90.94.120$all
@@ -27722,6 +27741,7 @@
 ||113.92.196.102$all
 ||113.92.196.116$all
 ||113.92.196.145$all
+||113.92.196.173$all
 ||113.92.196.192$all
 ||113.92.196.227$all
 ||113.92.196.235$all
@@ -30188,6 +30208,7 @@
 ||115.205.14.76$all
 ||115.205.15.79$all
 ||115.205.171.34$all
+||115.205.197.221$all
 ||115.205.235.30$all
 ||115.205.66.30$all
 ||115.205.70.49$all
@@ -32677,6 +32698,7 @@
 ||115.48.201.222$all
 ||115.48.201.244$all
 ||115.48.201.255$all
+||115.48.201.26$all
 ||115.48.201.31$all
 ||115.48.201.37$all
 ||115.48.201.40$all
@@ -33514,6 +33536,7 @@
 ||115.48.40.227$all
 ||115.48.40.3$all
 ||115.48.40.63$all
+||115.48.41.101$all
 ||115.48.41.141$all
 ||115.48.41.156$all
 ||115.48.41.184$all
@@ -34454,6 +34477,7 @@
 ||115.49.24.52$all
 ||115.49.24.58$all
 ||115.49.24.60$all
+||115.49.24.63$all
 ||115.49.240.125$all
 ||115.49.240.14$all
 ||115.49.240.147$all
@@ -36544,6 +36568,7 @@
 ||115.50.168.145$all
 ||115.50.168.153$all
 ||115.50.168.159$all
+||115.50.168.160$all
 ||115.50.168.168$all
 ||115.50.168.183$all
 ||115.50.168.19$all
@@ -36686,6 +36711,7 @@
 ||115.50.171.172$all
 ||115.50.171.184$all
 ||115.50.171.188$all
+||115.50.171.192$all
 ||115.50.171.196$all
 ||115.50.171.248$all
 ||115.50.171.250$all
@@ -37471,6 +37497,7 @@
 ||115.50.211.56$all
 ||115.50.211.62$all
 ||115.50.211.65$all
+||115.50.211.74$all
 ||115.50.211.8$all
 ||115.50.211.80$all
 ||115.50.212.1$all
@@ -38654,6 +38681,7 @@
 ||115.50.242.244$all
 ||115.50.242.246$all
 ||115.50.242.43$all
+||115.50.242.7$all
 ||115.50.242.81$all
 ||115.50.242.89$all
 ||115.50.243.10$all
@@ -38771,6 +38799,7 @@
 ||115.50.247.245$all
 ||115.50.247.33$all
 ||115.50.247.40$all
+||115.50.247.46$all
 ||115.50.247.47$all
 ||115.50.247.56$all
 ||115.50.247.80$all
@@ -40644,6 +40673,7 @@
 ||115.50.79.50$all
 ||115.50.79.7$all
 ||115.50.79.73$all
+||115.50.79.78$all
 ||115.50.79.95$all
 ||115.50.8.131$all
 ||115.50.8.159$all
@@ -41824,6 +41854,7 @@
 ||115.51.58.162$all
 ||115.51.61.137$all
 ||115.51.7.177$all
+||115.51.7.254$all
 ||115.51.78.11$all
 ||115.51.88.101$all
 ||115.51.88.11$all
@@ -42459,6 +42490,7 @@
 ||115.52.172.58$all
 ||115.52.172.63$all
 ||115.52.172.64$all
+||115.52.172.72$all
 ||115.52.172.74$all
 ||115.52.172.91$all
 ||115.52.172.93$all
@@ -43810,6 +43842,7 @@
 ||115.53.56.72$all
 ||115.53.57.189$all
 ||115.53.58.162$all
+||115.53.58.228$all
 ||115.53.58.24$all
 ||115.53.59.170$all
 ||115.53.59.68$all
@@ -43925,6 +43958,7 @@
 ||115.54.112.31$all
 ||115.54.113.101$all
 ||115.54.113.128$all
+||115.54.113.49$all
 ||115.54.114.20$all
 ||115.54.114.211$all
 ||115.54.115.1$all
@@ -44113,6 +44147,7 @@
 ||115.54.158.17$all
 ||115.54.158.176$all
 ||115.54.158.210$all
+||115.54.158.251$all
 ||115.54.158.255$all
 ||115.54.158.67$all
 ||115.54.159.101$all
@@ -45802,6 +45837,7 @@
 ||115.55.126.58$all
 ||115.55.126.59$all
 ||115.55.126.88$all
+||115.55.127.0$all
 ||115.55.127.101$all
 ||115.55.127.126$all
 ||115.55.127.146$all
@@ -48042,6 +48078,7 @@
 ||115.55.197.78$all
 ||115.55.197.99$all
 ||115.55.198.103$all
+||115.55.198.105$all
 ||115.55.198.117$all
 ||115.55.198.127$all
 ||115.55.198.143$all
@@ -48844,6 +48881,7 @@
 ||115.55.52.113$all
 ||115.55.52.125$all
 ||115.55.52.136$all
+||115.55.52.17$all
 ||115.55.52.200$all
 ||115.55.52.206$all
 ||115.55.52.208$all
@@ -49749,6 +49787,7 @@
 ||115.56.131.136$all
 ||115.56.131.144$all
 ||115.56.131.148$all
+||115.56.131.150$all
 ||115.56.131.166$all
 ||115.56.131.170$all
 ||115.56.131.186$all
@@ -49998,6 +50037,7 @@
 ||115.56.135.237$all
 ||115.56.135.247$all
 ||115.56.135.250$all
+||115.56.135.255$all
 ||115.56.135.28$all
 ||115.56.135.33$all
 ||115.56.135.36$all
@@ -50418,6 +50458,7 @@
 ||115.56.142.39$all
 ||115.56.142.4$all
 ||115.56.142.44$all
+||115.56.142.45$all
 ||115.56.142.49$all
 ||115.56.142.5$all
 ||115.56.142.66$all
@@ -50745,6 +50786,7 @@
 ||115.56.150.130$all
 ||115.56.150.139$all
 ||115.56.150.14$all
+||115.56.150.149$all
 ||115.56.150.150$all
 ||115.56.150.152$all
 ||115.56.150.156$all
@@ -50994,6 +51036,7 @@
 ||115.56.155.38$all
 ||115.56.155.42$all
 ||115.56.155.43$all
+||115.56.155.50$all
 ||115.56.155.51$all
 ||115.56.155.54$all
 ||115.56.155.64$all
@@ -52595,6 +52638,7 @@
 ||115.56.27.88$all
 ||115.56.3.209$all
 ||115.56.31.10$all
+||115.56.31.11$all
 ||115.56.31.156$all
 ||115.56.31.170$all
 ||115.56.31.176$all
@@ -54743,6 +54787,7 @@
 ||115.58.91.225$all
 ||115.58.91.240$all
 ||115.58.91.52$all
+||115.58.91.65$all
 ||115.58.91.74$all
 ||115.58.91.86$all
 ||115.58.91.9$all
@@ -57993,6 +58038,7 @@
 ||115.61.112.13$all
 ||115.61.112.14$all
 ||115.61.112.140$all
+||115.61.112.159$all
 ||115.61.112.161$all
 ||115.61.112.168$all
 ||115.61.112.185$all
@@ -58630,6 +58676,7 @@
 ||115.61.158.55$all
 ||115.61.158.90$all
 ||115.61.158.93$all
+||115.61.158.98$all
 ||115.61.159.102$all
 ||115.61.159.115$all
 ||115.61.159.118$all
@@ -60154,6 +60201,7 @@
 ||115.62.170.41$all
 ||115.62.170.82$all
 ||115.62.170.91$all
+||115.62.171.143$all
 ||115.62.171.177$all
 ||115.62.171.71$all
 ||115.62.171.81$all
@@ -60548,6 +60596,7 @@
 ||115.63.131.168$all
 ||115.63.131.169$all
 ||115.63.131.170$all
+||115.63.131.173$all
 ||115.63.131.176$all
 ||115.63.131.229$all
 ||115.63.131.230$all
@@ -60779,6 +60828,7 @@
 ||115.63.139.178$all
 ||115.63.139.183$all
 ||115.63.139.186$all
+||115.63.139.187$all
 ||115.63.139.229$all
 ||115.63.139.246$all
 ||115.63.139.25$all
@@ -68429,6 +68479,7 @@
 ||115.97.139.254$all
 ||115.97.139.28$all
 ||115.97.139.3$all
+||115.97.139.32$all
 ||115.97.139.35$all
 ||115.97.139.4$all
 ||115.97.139.43$all
@@ -92781,6 +92832,7 @@
 ||116.68.98.160$all
 ||116.68.98.163$all
 ||116.68.98.17$all
+||116.68.98.173$all
 ||116.68.98.178$all
 ||116.68.98.182$all
 ||116.68.98.184$all
@@ -94891,6 +94943,7 @@
 ||116.72.28.187$all
 ||116.72.28.204$all
 ||116.72.28.226$all
+||116.72.28.239$all
 ||116.72.28.48$all
 ||116.72.28.49$all
 ||116.72.28.76$all
@@ -96508,6 +96561,7 @@
 ||116.73.52.121$all
 ||116.73.52.122$all
 ||116.73.52.124$all
+||116.73.52.125$all
 ||116.73.52.127$all
 ||116.73.52.13$all
 ||116.73.52.132$all
@@ -98339,6 +98393,7 @@
 ||116.73.99.95$all
 ||116.73.99.97$all
 ||116.74.101.118$all
+||116.74.101.150$all
 ||116.74.101.161$all
 ||116.74.101.177$all
 ||116.74.101.210$all
@@ -100255,6 +100310,7 @@
 ||116.74.23.37$all
 ||116.74.23.44$all
 ||116.74.23.45$all
+||116.74.23.46$all
 ||116.74.23.48$all
 ||116.74.23.51$all
 ||116.74.23.52$all
@@ -100346,6 +100402,7 @@
 ||116.74.24.75$all
 ||116.74.24.76$all
 ||116.74.24.79$all
+||116.74.24.8$all
 ||116.74.24.82$all
 ||116.74.24.84$all
 ||116.74.24.85$all
@@ -111716,6 +111773,7 @@
 ||116.88.65.131$all
 ||116.9.145.199$all
 ||116.9.43.106$all
+||116.9.43.220$all
 ||116.9.43.235$all
 ||116.90.238.142$all
 ||116.91.202.79$all
@@ -112817,6 +112875,7 @@
 ||117.194.148.188$all
 ||117.194.148.189$all
 ||117.194.148.190$all
+||117.194.148.198$all
 ||117.194.148.202$all
 ||117.194.148.205$all
 ||117.194.148.207$all
@@ -113099,6 +113158,7 @@
 ||117.194.151.176$all
 ||117.194.151.178$all
 ||117.194.151.180$all
+||117.194.151.184$all
 ||117.194.151.192$all
 ||117.194.151.196$all
 ||117.194.151.198$all
@@ -114050,6 +114110,7 @@
 ||117.194.164.97$all
 ||117.194.164.99$all
 ||117.194.165.0$all
+||117.194.165.1$all
 ||117.194.165.100$all
 ||117.194.165.101$all
 ||117.194.165.102$all
@@ -114741,6 +114802,7 @@
 ||117.196.48.178$all
 ||117.196.48.179$all
 ||117.196.48.180$all
+||117.196.48.181$all
 ||117.196.48.183$all
 ||117.196.48.184$all
 ||117.196.48.185$all
@@ -115031,6 +115093,7 @@
 ||117.196.50.147$all
 ||117.196.50.15$all
 ||117.196.50.150$all
+||117.196.50.154$all
 ||117.196.50.158$all
 ||117.196.50.161$all
 ||117.196.50.164$all
@@ -115074,6 +115137,7 @@
 ||117.196.50.23$all
 ||117.196.50.230$all
 ||117.196.50.236$all
+||117.196.50.239$all
 ||117.196.50.24$all
 ||117.196.50.240$all
 ||117.196.50.241$all
@@ -115118,6 +115182,7 @@
 ||117.196.50.7$all
 ||117.196.50.71$all
 ||117.196.50.72$all
+||117.196.50.76$all
 ||117.196.50.77$all
 ||117.196.50.78$all
 ||117.196.50.79$all
@@ -115996,6 +116061,7 @@
 ||117.202.66.40$all
 ||117.202.66.41$all
 ||117.202.66.42$all
+||117.202.66.44$all
 ||117.202.66.45$all
 ||117.202.66.46$all
 ||117.202.66.47$all
@@ -117612,6 +117678,7 @@
 ||117.207.47.96$all
 ||117.207.5.156$all
 ||117.207.50.5$all
+||117.208.132.10$all
 ||117.208.132.101$all
 ||117.208.132.102$all
 ||117.208.132.103$all
@@ -117885,6 +117952,7 @@
 ||117.208.133.86$all
 ||117.208.133.87$all
 ||117.208.133.9$all
+||117.208.133.91$all
 ||117.208.133.92$all
 ||117.208.133.97$all
 ||117.208.134.0$all
@@ -119326,6 +119394,7 @@
 ||117.213.41.74$all
 ||117.213.41.75$all
 ||117.213.41.78$all
+||117.213.41.8$all
 ||117.213.41.80$all
 ||117.213.41.82$all
 ||117.213.41.83$all
@@ -120269,6 +120338,7 @@
 ||117.213.47.134$all
 ||117.213.47.136$all
 ||117.213.47.138$all
+||117.213.47.139$all
 ||117.213.47.14$all
 ||117.213.47.140$all
 ||117.213.47.142$all
@@ -120528,6 +120598,7 @@
 ||117.215.210.230$all
 ||117.215.210.243$all
 ||117.215.210.245$all
+||117.215.210.249$all
 ||117.215.210.25$all
 ||117.215.210.250$all
 ||117.215.210.251$all
@@ -120589,6 +120660,7 @@
 ||117.215.212.153$all
 ||117.215.212.166$all
 ||117.215.212.168$all
+||117.215.212.174$all
 ||117.215.212.176$all
 ||117.215.212.180$all
 ||117.215.212.182$all
@@ -120730,6 +120802,7 @@
 ||117.215.248.158$all
 ||117.215.248.17$all
 ||117.215.248.181$all
+||117.215.248.198$all
 ||117.215.248.20$all
 ||117.215.248.201$all
 ||117.215.248.205$all
@@ -121573,6 +121646,7 @@
 ||117.222.162.70$all
 ||117.222.162.71$all
 ||117.222.162.72$all
+||117.222.162.73$all
 ||117.222.162.74$all
 ||117.222.162.75$all
 ||117.222.162.76$all
@@ -122346,6 +122420,7 @@
 ||117.222.166.28$all
 ||117.222.166.3$all
 ||117.222.166.30$all
+||117.222.166.36$all
 ||117.222.166.38$all
 ||117.222.166.39$all
 ||117.222.166.4$all
@@ -122822,6 +122897,7 @@
 ||117.222.170.217$all
 ||117.222.170.223$all
 ||117.222.170.224$all
+||117.222.170.234$all
 ||117.222.170.237$all
 ||117.222.170.238$all
 ||117.222.170.239$all
@@ -124470,6 +124546,7 @@
 ||117.242.210.238$all
 ||117.242.210.239$all
 ||117.242.210.24$all
+||117.242.210.240$all
 ||117.242.210.241$all
 ||117.242.210.244$all
 ||117.242.210.246$all
@@ -124750,6 +124827,7 @@
 ||117.242.48.212$all
 ||117.242.48.232$all
 ||117.242.48.57$all
+||117.242.49.157$all
 ||117.242.49.166$all
 ||117.242.49.185$all
 ||117.242.49.21$all
@@ -126495,6 +126573,7 @@
 ||117.248.63.61$all
 ||117.248.63.62$all
 ||117.248.63.67$all
+||117.248.63.70$all
 ||117.248.63.73$all
 ||117.248.63.74$all
 ||117.248.63.75$all
@@ -127587,6 +127666,7 @@
 ||117.251.63.206$all
 ||117.251.63.207$all
 ||117.251.63.209$all
+||117.251.63.21$all
 ||117.251.63.211$all
 ||117.251.63.212$all
 ||117.251.63.214$all
@@ -128462,6 +128542,7 @@
 ||118.113.244.200$all
 ||118.113.245.110$all
 ||118.114.216.131$all
+||118.114.84.237$all
 ||118.116.192.103$all
 ||118.116.192.53$all
 ||118.117.167.48$all
@@ -128781,6 +128862,7 @@
 ||118.172.224.136$all
 ||118.172.224.179$all
 ||118.172.224.205$all
+||118.172.224.37$all
 ||118.172.231.79$all
 ||118.172.232.164$all
 ||118.172.234.157$all
@@ -130317,6 +130399,7 @@
 ||118.79.91.203$all
 ||118.79.92.29$all
 ||118.79.93.194$all
+||118.79.96.11$all
 ||118.79.96.249$all
 ||118.79.96.9$all
 ||118.79.97.100$all
@@ -130634,6 +130717,7 @@
 ||119.118.128.127$all
 ||119.118.139.228$all
 ||119.118.143.250$all
+||119.118.150.84$all
 ||119.118.161.115$all
 ||119.118.167.179$all
 ||119.118.172.168$all
@@ -131014,6 +131098,7 @@
 ||119.123.173.46$all
 ||119.123.173.73$all
 ||119.123.173.91$all
+||119.123.173.95$all
 ||119.123.173.96$all
 ||119.123.174.102$all
 ||119.123.174.11$all
@@ -131058,6 +131143,7 @@
 ||119.123.175.174$all
 ||119.123.175.175$all
 ||119.123.175.185$all
+||119.123.175.210$all
 ||119.123.175.215$all
 ||119.123.175.222$all
 ||119.123.175.228$all
@@ -131276,6 +131362,7 @@
 ||119.123.219.194$all
 ||119.123.219.204$all
 ||119.123.219.230$all
+||119.123.219.232$all
 ||119.123.219.234$all
 ||119.123.219.240$all
 ||119.123.219.247$all
@@ -131319,6 +131406,7 @@
 ||119.123.221.5$all
 ||119.123.221.6$all
 ||119.123.221.74$all
+||119.123.221.94$all
 ||119.123.222.0$all
 ||119.123.222.112$all
 ||119.123.222.128$all
@@ -131459,6 +131547,7 @@
 ||119.123.239.109$all
 ||119.123.239.117$all
 ||119.123.239.122$all
+||119.123.239.131$all
 ||119.123.239.142$all
 ||119.123.239.153$all
 ||119.123.239.180$all
@@ -137600,6 +137689,7 @@
 ||120.57.214.195$all
 ||120.57.214.200$all
 ||120.57.214.223$all
+||120.57.214.228$all
 ||120.57.214.251$all
 ||120.57.214.38$all
 ||120.57.214.44$all
@@ -139452,6 +139542,7 @@
 ||120.6.233.250$all
 ||120.6.239.231$all
 ||120.6.240.130$all
+||120.6.241.130$all
 ||120.6.242.41$all
 ||120.6.248.88$all
 ||120.6.4.156$all
@@ -140464,6 +140555,7 @@
 ||120.85.196.179$all
 ||120.85.196.196$all
 ||120.85.196.205$all
+||120.85.196.211$all
 ||120.85.196.217$all
 ||120.85.196.220$all
 ||120.85.196.23$all
@@ -140563,6 +140655,7 @@
 ||120.85.199.91$all
 ||120.85.199.97$all
 ||120.85.208.103$all
+||120.85.208.107$all
 ||120.85.208.111$all
 ||120.85.208.114$all
 ||120.85.208.121$all
@@ -140741,6 +140834,7 @@
 ||120.85.238.0$all
 ||120.85.238.10$all
 ||120.85.238.107$all
+||120.85.238.129$all
 ||120.85.238.13$all
 ||120.85.238.137$all
 ||120.85.238.139$all
@@ -140757,6 +140851,7 @@
 ||120.85.238.218$all
 ||120.85.238.219$all
 ||120.85.238.233$all
+||120.85.238.238$all
 ||120.85.238.240$all
 ||120.85.238.244$all
 ||120.85.238.25$all
@@ -145415,6 +145510,7 @@
 ||123.11.125.93$all
 ||123.11.126.117$all
 ||123.11.126.2$all
+||123.11.126.225$all
 ||123.11.126.241$all
 ||123.11.126.62$all
 ||123.11.126.76$all
@@ -146832,6 +146928,7 @@
 ||123.11.62.73$all
 ||123.11.62.76$all
 ||123.11.63.112$all
+||123.11.63.113$all
 ||123.11.63.133$all
 ||123.11.63.170$all
 ||123.11.63.180$all
@@ -147456,6 +147553,7 @@
 ||123.12.185.95$all
 ||123.12.186.64$all
 ||123.12.187.224$all
+||123.12.189.247$all
 ||123.12.189.252$all
 ||123.12.189.93$all
 ||123.12.19.142$all
@@ -147567,6 +147665,7 @@
 ||123.12.225.250$all
 ||123.12.225.254$all
 ||123.12.225.62$all
+||123.12.225.70$all
 ||123.12.225.90$all
 ||123.12.225.94$all
 ||123.12.226.11$all
@@ -147907,6 +148006,7 @@
 ||123.12.243.76$all
 ||123.12.243.82$all
 ||123.12.243.83$all
+||123.12.243.85$all
 ||123.12.243.89$all
 ||123.12.243.95$all
 ||123.12.243.99$all
@@ -149465,6 +149565,7 @@
 ||123.130.254.2$all
 ||123.130.26.116$all
 ||123.130.27.172$all
+||123.130.27.19$all
 ||123.130.28.103$all
 ||123.130.28.105$all
 ||123.130.28.213$all
@@ -150430,6 +150531,7 @@
 ||123.14.127.174$all
 ||123.14.127.209$all
 ||123.14.127.219$all
+||123.14.127.238$all
 ||123.14.127.243$all
 ||123.14.127.250$all
 ||123.14.127.33$all
@@ -150772,6 +150874,7 @@
 ||123.14.173.130$all
 ||123.14.173.154$all
 ||123.14.173.159$all
+||123.14.173.199$all
 ||123.14.173.202$all
 ||123.14.173.218$all
 ||123.14.174.128$all
@@ -151260,6 +151363,7 @@
 ||123.14.249.250$all
 ||123.14.249.253$all
 ||123.14.249.30$all
+||123.14.249.33$all
 ||123.14.249.34$all
 ||123.14.249.38$all
 ||123.14.249.46$all
@@ -151512,6 +151616,7 @@
 ||123.14.34.184$all
 ||123.14.34.200$all
 ||123.14.34.222$all
+||123.14.34.240$all
 ||123.14.34.246$all
 ||123.14.34.36$all
 ||123.14.34.42$all
@@ -151567,6 +151672,7 @@
 ||123.14.37.215$all
 ||123.14.37.228$all
 ||123.14.37.231$all
+||123.14.37.32$all
 ||123.14.37.81$all
 ||123.14.38.0$all
 ||123.14.38.11$all
@@ -151714,6 +151820,7 @@
 ||123.14.50.184$all
 ||123.14.50.185$all
 ||123.14.50.207$all
+||123.14.50.214$all
 ||123.14.50.221$all
 ||123.14.50.251$all
 ||123.14.50.3$all
@@ -152494,6 +152601,7 @@
 ||123.153.59.88$all
 ||123.153.80.178$all
 ||123.153.88.252$all
+||123.154.116.116$all
 ||123.154.116.130$all
 ||123.154.116.155$all
 ||123.154.116.19$all
@@ -154354,6 +154462,7 @@
 ||123.4.194.144$all
 ||123.4.194.147$all
 ||123.4.194.15$all
+||123.4.194.152$all
 ||123.4.194.167$all
 ||123.4.194.173$all
 ||123.4.194.18$all
@@ -154566,6 +154675,7 @@
 ||123.4.213.128$all
 ||123.4.213.152$all
 ||123.4.213.169$all
+||123.4.213.239$all
 ||123.4.213.74$all
 ||123.4.213.83$all
 ||123.4.214.10$all
@@ -155118,6 +155228,7 @@
 ||123.4.45.112$all
 ||123.4.45.192$all
 ||123.4.45.221$all
+||123.4.45.31$all
 ||123.4.45.4$all
 ||123.4.45.7$all
 ||123.4.46.136$all
@@ -159756,6 +159867,7 @@
 ||123.8.71.235$all
 ||123.8.71.243$all
 ||123.8.71.246$all
+||123.8.71.27$all
 ||123.8.71.32$all
 ||123.8.71.7$all
 ||123.8.71.82$all
@@ -161028,6 +161140,7 @@
 ||123.9.239.80$all
 ||123.9.240.102$all
 ||123.9.240.103$all
+||123.9.240.115$all
 ||123.9.240.138$all
 ||123.9.240.146$all
 ||123.9.240.16$all
@@ -162387,6 +162500,7 @@
 ||124.131.136.92$all
 ||124.131.137.113$all
 ||124.131.137.137$all
+||124.131.137.147$all
 ||124.131.137.183$all
 ||124.131.137.190$all
 ||124.131.137.192$all
@@ -162747,6 +162861,7 @@
 ||124.131.23.131$all
 ||124.131.23.177$all
 ||124.131.239.254$all
+||124.131.24.185$all
 ||124.131.24.187$all
 ||124.131.24.219$all
 ||124.131.24.229$all
@@ -164137,6 +164252,7 @@
 ||124.92.133.100$all
 ||124.92.135.150$all
 ||124.92.135.30$all
+||124.92.135.37$all
 ||124.92.137.146$all
 ||124.92.137.71$all
 ||124.92.139.198$all
@@ -164380,6 +164496,7 @@
 ||125.106.44.171$all
 ||125.106.45.123$all
 ||125.106.45.200$all
+||125.106.46.225$all
 ||125.106.47.217$all
 ||125.106.48.237$all
 ||125.106.48.250$all
@@ -167521,6 +167638,7 @@
 ||125.41.164.56$all
 ||125.41.164.59$all
 ||125.41.164.6$all
+||125.41.164.60$all
 ||125.41.164.69$all
 ||125.41.164.92$all
 ||125.41.164.93$all
@@ -167716,6 +167834,7 @@
 ||125.41.184.230$all
 ||125.41.184.251$all
 ||125.41.185.110$all
+||125.41.185.186$all
 ||125.41.185.237$all
 ||125.41.185.252$all
 ||125.41.185.65$all
@@ -167874,6 +167993,7 @@
 ||125.41.191.8$all
 ||125.41.191.88$all
 ||125.41.196.104$all
+||125.41.196.114$all
 ||125.41.196.119$all
 ||125.41.196.128$all
 ||125.41.196.132$all
@@ -169762,6 +169882,7 @@
 ||125.41.97.224$all
 ||125.41.97.226$all
 ||125.41.97.228$all
+||125.41.97.231$all
 ||125.41.97.234$all
 ||125.41.97.237$all
 ||125.41.97.238$all
@@ -173148,6 +173269,7 @@
 ||125.43.6.111$all
 ||125.43.6.114$all
 ||125.43.6.138$all
+||125.43.6.186$all
 ||125.43.6.191$all
 ||125.43.6.204$all
 ||125.43.6.216$all
@@ -173242,6 +173364,7 @@
 ||125.43.63.252$all
 ||125.43.63.39$all
 ||125.43.63.46$all
+||125.43.63.47$all
 ||125.43.63.49$all
 ||125.43.63.50$all
 ||125.43.63.55$all
@@ -174995,6 +175118,7 @@
 ||125.44.207.72$all
 ||125.44.207.91$all
 ||125.44.207.97$all
+||125.44.208.152$all
 ||125.44.208.153$all
 ||125.44.208.164$all
 ||125.44.208.165$all
@@ -175473,6 +175597,7 @@
 ||125.44.227.242$all
 ||125.44.227.248$all
 ||125.44.227.4$all
+||125.44.227.51$all
 ||125.44.227.65$all
 ||125.44.227.69$all
 ||125.44.228.124$all
@@ -176416,6 +176541,7 @@
 ||125.44.70.28$all
 ||125.44.70.31$all
 ||125.44.70.5$all
+||125.44.70.64$all
 ||125.44.70.68$all
 ||125.44.70.87$all
 ||125.44.71.10$all
@@ -177128,6 +177254,7 @@
 ||125.45.43.19$all
 ||125.45.43.190$all
 ||125.45.43.209$all
+||125.45.43.63$all
 ||125.45.43.78$all
 ||125.45.48.101$all
 ||125.45.48.154$all
@@ -178195,6 +178322,7 @@
 ||125.46.165.83$all
 ||125.46.166.10$all
 ||125.46.166.101$all
+||125.46.166.112$all
 ||125.46.166.121$all
 ||125.46.166.123$all
 ||125.46.166.125$all
@@ -179427,6 +179555,7 @@
 ||125.47.124.60$all
 ||125.47.124.62$all
 ||125.47.125.129$all
+||125.47.125.16$all
 ||125.47.126.230$all
 ||125.47.126.53$all
 ||125.47.126.63$all
@@ -180396,6 +180525,7 @@
 ||125.47.248.117$all
 ||125.47.248.119$all
 ||125.47.248.124$all
+||125.47.248.131$all
 ||125.47.248.135$all
 ||125.47.248.141$all
 ||125.47.248.142$all
@@ -180902,9 +181032,11 @@
 ||125.47.37.56$all
 ||125.47.37.68$all
 ||125.47.38.10$all
+||125.47.38.114$all
 ||125.47.38.119$all
 ||125.47.38.124$all
 ||125.47.38.132$all
+||125.47.38.142$all
 ||125.47.38.152$all
 ||125.47.38.168$all
 ||125.47.38.17$all
@@ -181005,6 +181137,7 @@
 ||125.47.47.198$all
 ||125.47.47.209$all
 ||125.47.47.21$all
+||125.47.47.212$all
 ||125.47.47.217$all
 ||125.47.47.220$all
 ||125.47.47.233$all
@@ -183001,6 +183134,7 @@
 ||125.99.220.202$all
 ||125.99.220.216$all
 ||125.99.222.152$all
+||125.99.222.2$all
 ||125.99.222.245$all
 ||125.99.222.76$all
 ||125.99.223.227$all
@@ -185551,6 +185685,7 @@
 ||139.213.7.128$all
 ||139.213.7.230$all
 ||139.213.96.26$all
+||139.213.97.191$all
 ||139.213.97.23$all
 ||139.214.62.66$all
 ||139.214.62.96$all
@@ -185779,6 +185914,7 @@
 ||14.109.109.129$all
 ||14.109.111.219$all
 ||14.109.112.100$all
+||14.109.126.96$all
 ||14.113.12.153$all
 ||14.113.13.184$all
 ||14.113.14.145$all
@@ -186798,6 +186934,7 @@
 ||140.237.28.148$all
 ||140.237.29.28$all
 ||140.237.30.113$all
+||140.237.30.172$all
 ||140.237.30.179$all
 ||140.237.30.188$all
 ||140.237.31.197$all
@@ -187601,6 +187738,7 @@
 ||149.255.15.112$all
 ||149.255.15.121$all
 ||149.255.15.134$all
+||149.255.15.172$all
 ||149.255.15.180$all
 ||149.255.15.182$all
 ||149.255.15.184$all
@@ -190286,6 +190424,7 @@
 ||163.125.2.36$all
 ||163.125.2.67$all
 ||163.125.200.107$all
+||163.125.200.118$all
 ||163.125.200.126$all
 ||163.125.200.129$all
 ||163.125.200.13$all
@@ -190307,6 +190446,7 @@
 ||163.125.200.230$all
 ||163.125.200.233$all
 ||163.125.200.238$all
+||163.125.200.242$all
 ||163.125.200.247$all
 ||163.125.200.37$all
 ||163.125.200.40$all
@@ -190395,6 +190535,7 @@
 ||163.125.202.235$all
 ||163.125.202.245$all
 ||163.125.202.246$all
+||163.125.202.255$all
 ||163.125.202.27$all
 ||163.125.202.4$all
 ||163.125.202.57$all
@@ -190402,6 +190543,7 @@
 ||163.125.202.74$all
 ||163.125.202.8$all
 ||163.125.202.83$all
+||163.125.202.87$all
 ||163.125.202.9$all
 ||163.125.203.10$all
 ||163.125.203.118$all
@@ -190419,6 +190561,7 @@
 ||163.125.203.213$all
 ||163.125.203.214$all
 ||163.125.203.23$all
+||163.125.203.236$all
 ||163.125.203.32$all
 ||163.125.203.33$all
 ||163.125.203.4$all
@@ -190477,6 +190620,7 @@
 ||163.125.206.133$all
 ||163.125.206.145$all
 ||163.125.206.151$all
+||163.125.206.16$all
 ||163.125.206.162$all
 ||163.125.206.164$all
 ||163.125.206.187$all
@@ -190804,6 +190948,7 @@
 ||163.204.21.75$all
 ||163.204.210.243$all
 ||163.204.210.34$all
+||163.204.211.136$all
 ||163.204.211.205$all
 ||163.204.211.228$all
 ||163.204.211.47$all
@@ -191891,6 +192036,7 @@
 ||168.187.202.184$all
 ||168.187.234.86$all
 ||168.194.110.39$all
+||168.194.146.145$all
 ||168.194.176.180$all
 ||168.194.214.107$all
 ||168.194.214.113$all
@@ -192890,6 +193036,7 @@
 ||171.125.122.33$all
 ||171.125.122.54$all
 ||171.125.122.90$all
+||171.125.122.91$all
 ||171.125.123.88$all
 ||171.125.124.133$all
 ||171.125.124.58$all
@@ -193153,6 +193300,7 @@
 ||171.125.65.193$all
 ||171.125.65.202$all
 ||171.125.65.22$all
+||171.125.65.89$all
 ||171.125.66.6$all
 ||171.125.68.45$all
 ||171.125.7.181$all
@@ -198105,6 +198253,7 @@
 ||175.164.59.67$all
 ||175.164.6.45$all
 ||175.164.61.169$all
+||175.164.61.215$all
 ||175.164.63.75$all
 ||175.164.63.94$all
 ||175.164.66.17$all
@@ -198247,6 +198396,7 @@
 ||175.169.118.51$all
 ||175.169.127.142$all
 ||175.169.127.205$all
+||175.169.13.182$all
 ||175.169.15.220$all
 ||175.169.160.119$all
 ||175.169.163.231$all
@@ -201150,6 +201300,7 @@
 ||178.141.41.122$all
 ||178.141.41.125$all
 ||178.141.41.239$all
+||178.141.44.152$all
 ||178.141.44.159$all
 ||178.141.44.184$all
 ||178.141.44.21$all
@@ -201413,6 +201564,7 @@
 ||178.175.1.155$all
 ||178.175.1.157$all
 ||178.175.1.159$all
+||178.175.1.16$all
 ||178.175.1.161$all
 ||178.175.1.162$all
 ||178.175.1.164$all
@@ -201420,6 +201572,7 @@
 ||178.175.1.172$all
 ||178.175.1.174$all
 ||178.175.1.175$all
+||178.175.1.176$all
 ||178.175.1.178$all
 ||178.175.1.179$all
 ||178.175.1.182$all
@@ -201455,6 +201608,7 @@
 ||178.175.1.33$all
 ||178.175.1.34$all
 ||178.175.1.43$all
+||178.175.1.44$all
 ||178.175.1.46$all
 ||178.175.1.48$all
 ||178.175.1.5$all
@@ -201484,6 +201638,7 @@
 ||178.175.10.108$all
 ||178.175.10.113$all
 ||178.175.10.12$all
+||178.175.10.121$all
 ||178.175.10.124$all
 ||178.175.10.125$all
 ||178.175.10.133$all
@@ -201503,6 +201658,7 @@
 ||178.175.10.173$all
 ||178.175.10.175$all
 ||178.175.10.177$all
+||178.175.10.178$all
 ||178.175.10.182$all
 ||178.175.10.184$all
 ||178.175.10.186$all
@@ -201581,6 +201737,7 @@
 ||178.175.100.185$all
 ||178.175.100.187$all
 ||178.175.100.190$all
+||178.175.100.191$all
 ||178.175.100.193$all
 ||178.175.100.2$all
 ||178.175.100.201$all
@@ -201619,6 +201776,7 @@
 ||178.175.100.48$all
 ||178.175.100.49$all
 ||178.175.100.5$all
+||178.175.100.52$all
 ||178.175.100.54$all
 ||178.175.100.58$all
 ||178.175.100.61$all
@@ -201668,11 +201826,13 @@
 ||178.175.101.168$all
 ||178.175.101.170$all
 ||178.175.101.171$all
+||178.175.101.173$all
 ||178.175.101.174$all
 ||178.175.101.177$all
 ||178.175.101.186$all
 ||178.175.101.187$all
 ||178.175.101.189$all
+||178.175.101.191$all
 ||178.175.101.194$all
 ||178.175.101.196$all
 ||178.175.101.199$all
@@ -201884,8 +202044,10 @@
 ||178.175.103.233$all
 ||178.175.103.234$all
 ||178.175.103.239$all
+||178.175.103.24$all
 ||178.175.103.242$all
 ||178.175.103.245$all
+||178.175.103.246$all
 ||178.175.103.253$all
 ||178.175.103.26$all
 ||178.175.103.27$all
@@ -201951,6 +202113,7 @@
 ||178.175.104.145$all
 ||178.175.104.148$all
 ||178.175.104.15$all
+||178.175.104.151$all
 ||178.175.104.152$all
 ||178.175.104.153$all
 ||178.175.104.154$all
@@ -201959,6 +202122,7 @@
 ||178.175.104.16$all
 ||178.175.104.161$all
 ||178.175.104.163$all
+||178.175.104.166$all
 ||178.175.104.167$all
 ||178.175.104.169$all
 ||178.175.104.17$all
@@ -201978,6 +202142,7 @@
 ||178.175.104.195$all
 ||178.175.104.196$all
 ||178.175.104.198$all
+||178.175.104.199$all
 ||178.175.104.200$all
 ||178.175.104.202$all
 ||178.175.104.206$all
@@ -201991,6 +202156,7 @@
 ||178.175.104.230$all
 ||178.175.104.234$all
 ||178.175.104.235$all
+||178.175.104.239$all
 ||178.175.104.241$all
 ||178.175.104.243$all
 ||178.175.104.244$all
@@ -201999,6 +202165,7 @@
 ||178.175.104.252$all
 ||178.175.104.253$all
 ||178.175.104.255$all
+||178.175.104.26$all
 ||178.175.104.27$all
 ||178.175.104.29$all
 ||178.175.104.34$all
@@ -202076,6 +202243,7 @@
 ||178.175.105.208$all
 ||178.175.105.21$all
 ||178.175.105.213$all
+||178.175.105.214$all
 ||178.175.105.215$all
 ||178.175.105.217$all
 ||178.175.105.220$all
@@ -202084,6 +202252,7 @@
 ||178.175.105.235$all
 ||178.175.105.237$all
 ||178.175.105.238$all
+||178.175.105.240$all
 ||178.175.105.245$all
 ||178.175.105.247$all
 ||178.175.105.248$all
@@ -202125,6 +202294,7 @@
 ||178.175.105.93$all
 ||178.175.105.94$all
 ||178.175.105.96$all
+||178.175.105.99$all
 ||178.175.106.100$all
 ||178.175.106.102$all
 ||178.175.106.103$all
@@ -202144,6 +202314,7 @@
 ||178.175.106.136$all
 ||178.175.106.144$all
 ||178.175.106.146$all
+||178.175.106.149$all
 ||178.175.106.15$all
 ||178.175.106.154$all
 ||178.175.106.156$all
@@ -202205,6 +202376,7 @@
 ||178.175.106.28$all
 ||178.175.106.31$all
 ||178.175.106.32$all
+||178.175.106.36$all
 ||178.175.106.37$all
 ||178.175.106.42$all
 ||178.175.106.44$all
@@ -202224,6 +202396,7 @@
 ||178.175.106.78$all
 ||178.175.106.79$all
 ||178.175.106.8$all
+||178.175.106.83$all
 ||178.175.106.84$all
 ||178.175.106.87$all
 ||178.175.106.9$all
@@ -202575,6 +202748,7 @@
 ||178.175.11.149$all
 ||178.175.11.150$all
 ||178.175.11.154$all
+||178.175.11.155$all
 ||178.175.11.156$all
 ||178.175.11.157$all
 ||178.175.11.158$all
@@ -202608,6 +202782,7 @@
 ||178.175.11.23$all
 ||178.175.11.230$all
 ||178.175.11.235$all
+||178.175.11.241$all
 ||178.175.11.243$all
 ||178.175.11.244$all
 ||178.175.11.246$all
@@ -202692,6 +202867,7 @@
 ||178.175.110.190$all
 ||178.175.110.191$all
 ||178.175.110.192$all
+||178.175.110.194$all
 ||178.175.110.195$all
 ||178.175.110.197$all
 ||178.175.110.198$all
@@ -202842,6 +203018,7 @@
 ||178.175.112.103$all
 ||178.175.112.106$all
 ||178.175.112.109$all
+||178.175.112.110$all
 ||178.175.112.113$all
 ||178.175.112.114$all
 ||178.175.112.117$all
@@ -203071,6 +203248,7 @@
 ||178.175.114.123$all
 ||178.175.114.124$all
 ||178.175.114.125$all
+||178.175.114.127$all
 ||178.175.114.129$all
 ||178.175.114.13$all
 ||178.175.114.135$all
@@ -203281,6 +203459,7 @@
 ||178.175.116.1$all
 ||178.175.116.10$all
 ||178.175.116.100$all
+||178.175.116.101$all
 ||178.175.116.103$all
 ||178.175.116.104$all
 ||178.175.116.106$all
@@ -203307,6 +203486,7 @@
 ||178.175.116.159$all
 ||178.175.116.165$all
 ||178.175.116.169$all
+||178.175.116.170$all
 ||178.175.116.171$all
 ||178.175.116.174$all
 ||178.175.116.175$all
@@ -203787,6 +203967,7 @@
 ||178.175.12.78$all
 ||178.175.12.79$all
 ||178.175.12.91$all
+||178.175.12.93$all
 ||178.175.12.97$all
 ||178.175.120.100$all
 ||178.175.120.101$all
@@ -203868,6 +204049,7 @@
 ||178.175.120.44$all
 ||178.175.120.47$all
 ||178.175.120.49$all
+||178.175.120.5$all
 ||178.175.120.52$all
 ||178.175.120.57$all
 ||178.175.120.58$all
@@ -203920,6 +204102,8 @@
 ||178.175.121.180$all
 ||178.175.121.19$all
 ||178.175.121.190$all
+||178.175.121.192$all
+||178.175.121.193$all
 ||178.175.121.2$all
 ||178.175.121.202$all
 ||178.175.121.204$all
@@ -204161,6 +204345,7 @@
 ||178.175.123.247$all
 ||178.175.123.249$all
 ||178.175.123.255$all
+||178.175.123.26$all
 ||178.175.123.27$all
 ||178.175.123.29$all
 ||178.175.123.3$all
@@ -204581,6 +204766,7 @@
 ||178.175.127.214$all
 ||178.175.127.216$all
 ||178.175.127.217$all
+||178.175.127.219$all
 ||178.175.127.225$all
 ||178.175.127.228$all
 ||178.175.127.23$all
@@ -204603,6 +204789,7 @@
 ||178.175.127.35$all
 ||178.175.127.36$all
 ||178.175.127.38$all
+||178.175.127.43$all
 ||178.175.127.45$all
 ||178.175.127.46$all
 ||178.175.127.53$all
@@ -204626,6 +204813,7 @@
 ||178.175.127.91$all
 ||178.175.127.92$all
 ||178.175.127.95$all
+||178.175.127.97$all
 ||178.175.13.0$all
 ||178.175.13.1$all
 ||178.175.13.101$all
@@ -204720,6 +204908,7 @@
 ||178.175.14.126$all
 ||178.175.14.13$all
 ||178.175.14.130$all
+||178.175.14.131$all
 ||178.175.14.141$all
 ||178.175.14.144$all
 ||178.175.14.152$all
@@ -205047,6 +205236,7 @@
 ||178.175.17.62$all
 ||178.175.17.63$all
 ||178.175.17.64$all
+||178.175.17.66$all
 ||178.175.17.70$all
 ||178.175.17.74$all
 ||178.175.17.77$all
@@ -205259,6 +205449,7 @@
 ||178.175.2.18$all
 ||178.175.2.181$all
 ||178.175.2.184$all
+||178.175.2.186$all
 ||178.175.2.187$all
 ||178.175.2.188$all
 ||178.175.2.189$all
@@ -205413,6 +205604,7 @@
 ||178.175.20.87$all
 ||178.175.20.93$all
 ||178.175.20.96$all
+||178.175.20.97$all
 ||178.175.21.1$all
 ||178.175.21.110$all
 ||178.175.21.115$all
@@ -205610,6 +205802,7 @@
 ||178.175.23.184$all
 ||178.175.23.185$all
 ||178.175.23.187$all
+||178.175.23.19$all
 ||178.175.23.198$all
 ||178.175.23.199$all
 ||178.175.23.201$all
@@ -205702,6 +205895,7 @@
 ||178.175.24.189$all
 ||178.175.24.190$all
 ||178.175.24.191$all
+||178.175.24.198$all
 ||178.175.24.199$all
 ||178.175.24.200$all
 ||178.175.24.204$all
@@ -205975,6 +206169,7 @@
 ||178.175.27.122$all
 ||178.175.27.124$all
 ||178.175.27.125$all
+||178.175.27.137$all
 ||178.175.27.138$all
 ||178.175.27.14$all
 ||178.175.27.143$all
@@ -206027,6 +206222,7 @@
 ||178.175.27.239$all
 ||178.175.27.24$all
 ||178.175.27.241$all
+||178.175.27.244$all
 ||178.175.27.245$all
 ||178.175.27.246$all
 ||178.175.27.247$all
@@ -206115,6 +206311,7 @@
 ||178.175.28.198$all
 ||178.175.28.199$all
 ||178.175.28.20$all
+||178.175.28.200$all
 ||178.175.28.202$all
 ||178.175.28.205$all
 ||178.175.28.206$all
@@ -206140,6 +206337,7 @@
 ||178.175.28.4$all
 ||178.175.28.5$all
 ||178.175.28.50$all
+||178.175.28.51$all
 ||178.175.28.55$all
 ||178.175.28.59$all
 ||178.175.28.6$all
@@ -206147,6 +206345,7 @@
 ||178.175.28.64$all
 ||178.175.28.65$all
 ||178.175.28.66$all
+||178.175.28.69$all
 ||178.175.28.7$all
 ||178.175.28.72$all
 ||178.175.28.74$all
@@ -206196,6 +206395,7 @@
 ||178.175.29.204$all
 ||178.175.29.205$all
 ||178.175.29.207$all
+||178.175.29.208$all
 ||178.175.29.209$all
 ||178.175.29.219$all
 ||178.175.29.220$all
@@ -206232,6 +206432,7 @@
 ||178.175.29.55$all
 ||178.175.29.59$all
 ||178.175.29.6$all
+||178.175.29.7$all
 ||178.175.29.72$all
 ||178.175.29.73$all
 ||178.175.29.77$all
@@ -206308,6 +206509,7 @@
 ||178.175.3.28$all
 ||178.175.3.3$all
 ||178.175.3.31$all
+||178.175.3.32$all
 ||178.175.3.33$all
 ||178.175.3.34$all
 ||178.175.3.4$all
@@ -206320,6 +206522,7 @@
 ||178.175.3.58$all
 ||178.175.3.6$all
 ||178.175.3.62$all
+||178.175.3.66$all
 ||178.175.3.68$all
 ||178.175.3.69$all
 ||178.175.3.72$all
@@ -206329,6 +206532,7 @@
 ||178.175.3.80$all
 ||178.175.3.81$all
 ||178.175.3.85$all
+||178.175.3.87$all
 ||178.175.3.94$all
 ||178.175.3.98$all
 ||178.175.30.0$all
@@ -206487,6 +206691,7 @@
 ||178.175.31.247$all
 ||178.175.31.249$all
 ||178.175.31.251$all
+||178.175.31.252$all
 ||178.175.31.253$all
 ||178.175.31.29$all
 ||178.175.31.3$all
@@ -206518,6 +206723,7 @@
 ||178.175.31.94$all
 ||178.175.31.97$all
 ||178.175.31.98$all
+||178.175.31.99$all
 ||178.175.32.0$all
 ||178.175.32.1$all
 ||178.175.32.100$all
@@ -206537,6 +206743,7 @@
 ||178.175.32.133$all
 ||178.175.32.135$all
 ||178.175.32.138$all
+||178.175.32.14$all
 ||178.175.32.140$all
 ||178.175.32.141$all
 ||178.175.32.142$all
@@ -206586,6 +206793,7 @@
 ||178.175.32.24$all
 ||178.175.32.241$all
 ||178.175.32.243$all
+||178.175.32.244$all
 ||178.175.32.246$all
 ||178.175.32.248$all
 ||178.175.32.249$all
@@ -206657,6 +206865,7 @@
 ||178.175.33.186$all
 ||178.175.33.192$all
 ||178.175.33.193$all
+||178.175.33.196$all
 ||178.175.33.198$all
 ||178.175.33.2$all
 ||178.175.33.202$all
@@ -206682,6 +206891,7 @@
 ||178.175.33.241$all
 ||178.175.33.242$all
 ||178.175.33.244$all
+||178.175.33.245$all
 ||178.175.33.246$all
 ||178.175.33.255$all
 ||178.175.33.26$all
@@ -206900,6 +207110,7 @@
 ||178.175.35.85$all
 ||178.175.35.86$all
 ||178.175.35.89$all
+||178.175.35.91$all
 ||178.175.35.92$all
 ||178.175.35.93$all
 ||178.175.35.96$all
@@ -206982,6 +207193,7 @@
 ||178.175.36.37$all
 ||178.175.36.46$all
 ||178.175.36.47$all
+||178.175.36.5$all
 ||178.175.36.51$all
 ||178.175.36.52$all
 ||178.175.36.56$all
@@ -207100,6 +207312,7 @@
 ||178.175.37.67$all
 ||178.175.37.68$all
 ||178.175.37.70$all
+||178.175.37.71$all
 ||178.175.37.74$all
 ||178.175.37.75$all
 ||178.175.37.76$all
@@ -207219,6 +207432,7 @@
 ||178.175.39.106$all
 ||178.175.39.107$all
 ||178.175.39.11$all
+||178.175.39.110$all
 ||178.175.39.112$all
 ||178.175.39.113$all
 ||178.175.39.121$all
@@ -207289,6 +207503,7 @@
 ||178.175.39.57$all
 ||178.175.39.58$all
 ||178.175.39.61$all
+||178.175.39.63$all
 ||178.175.39.71$all
 ||178.175.39.74$all
 ||178.175.39.76$all
@@ -207536,6 +207751,7 @@
 ||178.175.41.217$all
 ||178.175.41.221$all
 ||178.175.41.223$all
+||178.175.41.224$all
 ||178.175.41.225$all
 ||178.175.41.229$all
 ||178.175.41.23$all
@@ -207624,9 +207840,11 @@
 ||178.175.42.228$all
 ||178.175.42.234$all
 ||178.175.42.235$all
+||178.175.42.240$all
 ||178.175.42.243$all
 ||178.175.42.245$all
 ||178.175.42.247$all
+||178.175.42.25$all
 ||178.175.42.253$all
 ||178.175.42.254$all
 ||178.175.42.255$all
@@ -207804,6 +208022,7 @@
 ||178.175.44.178$all
 ||178.175.44.179$all
 ||178.175.44.186$all
+||178.175.44.188$all
 ||178.175.44.19$all
 ||178.175.44.191$all
 ||178.175.44.194$all
@@ -207932,6 +208151,7 @@
 ||178.175.45.241$all
 ||178.175.45.244$all
 ||178.175.45.246$all
+||178.175.45.25$all
 ||178.175.45.250$all
 ||178.175.45.252$all
 ||178.175.45.253$all
@@ -208290,6 +208510,7 @@
 ||178.175.49.163$all
 ||178.175.49.166$all
 ||178.175.49.169$all
+||178.175.49.177$all
 ||178.175.49.18$all
 ||178.175.49.180$all
 ||178.175.49.185$all
@@ -208303,6 +208524,7 @@
 ||178.175.49.208$all
 ||178.175.49.21$all
 ||178.175.49.213$all
+||178.175.49.214$all
 ||178.175.49.215$all
 ||178.175.49.219$all
 ||178.175.49.221$all
@@ -208320,6 +208542,7 @@
 ||178.175.49.247$all
 ||178.175.49.248$all
 ||178.175.49.251$all
+||178.175.49.252$all
 ||178.175.49.253$all
 ||178.175.49.3$all
 ||178.175.49.31$all
@@ -208429,6 +208652,7 @@
 ||178.175.5.68$all
 ||178.175.5.70$all
 ||178.175.5.71$all
+||178.175.5.79$all
 ||178.175.5.84$all
 ||178.175.5.85$all
 ||178.175.5.88$all
@@ -208460,6 +208684,7 @@
 ||178.175.50.151$all
 ||178.175.50.152$all
 ||178.175.50.165$all
+||178.175.50.168$all
 ||178.175.50.169$all
 ||178.175.50.173$all
 ||178.175.50.174$all
@@ -208497,6 +208722,7 @@
 ||178.175.50.27$all
 ||178.175.50.28$all
 ||178.175.50.3$all
+||178.175.50.32$all
 ||178.175.50.33$all
 ||178.175.50.38$all
 ||178.175.50.40$all
@@ -208641,6 +208867,7 @@
 ||178.175.52.140$all
 ||178.175.52.141$all
 ||178.175.52.142$all
+||178.175.52.146$all
 ||178.175.52.149$all
 ||178.175.52.15$all
 ||178.175.52.153$all
@@ -208662,6 +208889,7 @@
 ||178.175.52.200$all
 ||178.175.52.205$all
 ||178.175.52.206$all
+||178.175.52.21$all
 ||178.175.52.211$all
 ||178.175.52.212$all
 ||178.175.52.216$all
@@ -208831,6 +209059,7 @@
 ||178.175.54.141$all
 ||178.175.54.142$all
 ||178.175.54.147$all
+||178.175.54.15$all
 ||178.175.54.150$all
 ||178.175.54.151$all
 ||178.175.54.154$all
@@ -208838,6 +209067,7 @@
 ||178.175.54.162$all
 ||178.175.54.163$all
 ||178.175.54.165$all
+||178.175.54.167$all
 ||178.175.54.172$all
 ||178.175.54.173$all
 ||178.175.54.178$all
@@ -209069,6 +209299,7 @@
 ||178.175.56.44$all
 ||178.175.56.48$all
 ||178.175.56.50$all
+||178.175.56.52$all
 ||178.175.56.54$all
 ||178.175.56.55$all
 ||178.175.56.57$all
@@ -209104,6 +209335,7 @@
 ||178.175.57.119$all
 ||178.175.57.12$all
 ||178.175.57.121$all
+||178.175.57.124$all
 ||178.175.57.126$all
 ||178.175.57.127$all
 ||178.175.57.129$all
@@ -209188,6 +209420,7 @@
 ||178.175.57.94$all
 ||178.175.57.95$all
 ||178.175.57.96$all
+||178.175.57.99$all
 ||178.175.58.100$all
 ||178.175.58.101$all
 ||178.175.58.105$all
@@ -209329,6 +209562,7 @@
 ||178.175.59.237$all
 ||178.175.59.238$all
 ||178.175.59.239$all
+||178.175.59.241$all
 ||178.175.59.243$all
 ||178.175.59.244$all
 ||178.175.59.245$all
@@ -209537,6 +209771,7 @@
 ||178.175.60.7$all
 ||178.175.60.70$all
 ||178.175.60.75$all
+||178.175.60.76$all
 ||178.175.60.79$all
 ||178.175.60.8$all
 ||178.175.60.80$all
@@ -209627,6 +209862,7 @@
 ||178.175.61.9$all
 ||178.175.61.90$all
 ||178.175.61.91$all
+||178.175.61.95$all
 ||178.175.61.96$all
 ||178.175.61.97$all
 ||178.175.62.1$all
@@ -209642,6 +209878,7 @@
 ||178.175.62.122$all
 ||178.175.62.123$all
 ||178.175.62.128$all
+||178.175.62.141$all
 ||178.175.62.143$all
 ||178.175.62.150$all
 ||178.175.62.151$all
@@ -209780,6 +210017,7 @@
 ||178.175.63.227$all
 ||178.175.63.228$all
 ||178.175.63.229$all
+||178.175.63.230$all
 ||178.175.63.231$all
 ||178.175.63.235$all
 ||178.175.63.239$all
@@ -209805,6 +210043,7 @@
 ||178.175.63.75$all
 ||178.175.63.76$all
 ||178.175.63.77$all
+||178.175.63.78$all
 ||178.175.63.80$all
 ||178.175.63.87$all
 ||178.175.63.88$all
@@ -209838,6 +210077,7 @@
 ||178.175.64.149$all
 ||178.175.64.151$all
 ||178.175.64.154$all
+||178.175.64.155$all
 ||178.175.64.156$all
 ||178.175.64.158$all
 ||178.175.64.163$all
@@ -209958,6 +210198,7 @@
 ||178.175.65.181$all
 ||178.175.65.184$all
 ||178.175.65.186$all
+||178.175.65.19$all
 ||178.175.65.192$all
 ||178.175.65.193$all
 ||178.175.65.194$all
@@ -210202,6 +210443,7 @@
 ||178.175.67.48$all
 ||178.175.67.51$all
 ||178.175.67.54$all
+||178.175.67.55$all
 ||178.175.67.59$all
 ||178.175.67.6$all
 ||178.175.67.60$all
@@ -210238,6 +210480,7 @@
 ||178.175.68.113$all
 ||178.175.68.114$all
 ||178.175.68.115$all
+||178.175.68.116$all
 ||178.175.68.121$all
 ||178.175.68.124$all
 ||178.175.68.125$all
@@ -210912,6 +211155,7 @@
 ||178.175.73.72$all
 ||178.175.73.76$all
 ||178.175.73.77$all
+||178.175.73.78$all
 ||178.175.73.86$all
 ||178.175.73.88$all
 ||178.175.73.89$all
@@ -210971,6 +211215,7 @@
 ||178.175.74.201$all
 ||178.175.74.203$all
 ||178.175.74.204$all
+||178.175.74.205$all
 ||178.175.74.206$all
 ||178.175.74.207$all
 ||178.175.74.21$all
@@ -210988,6 +211233,7 @@
 ||178.175.74.237$all
 ||178.175.74.238$all
 ||178.175.74.241$all
+||178.175.74.247$all
 ||178.175.74.251$all
 ||178.175.74.253$all
 ||178.175.74.30$all
@@ -211181,6 +211427,7 @@
 ||178.175.76.240$all
 ||178.175.76.241$all
 ||178.175.76.244$all
+||178.175.76.246$all
 ||178.175.76.248$all
 ||178.175.76.27$all
 ||178.175.76.29$all
@@ -211260,6 +211507,7 @@
 ||178.175.77.242$all
 ||178.175.77.244$all
 ||178.175.77.246$all
+||178.175.77.248$all
 ||178.175.77.250$all
 ||178.175.77.251$all
 ||178.175.77.252$all
@@ -211267,6 +211515,7 @@
 ||178.175.77.31$all
 ||178.175.77.32$all
 ||178.175.77.33$all
+||178.175.77.34$all
 ||178.175.77.37$all
 ||178.175.77.38$all
 ||178.175.77.40$all
@@ -211367,6 +211616,7 @@
 ||178.175.78.48$all
 ||178.175.78.50$all
 ||178.175.78.51$all
+||178.175.78.57$all
 ||178.175.78.58$all
 ||178.175.78.60$all
 ||178.175.78.64$all
@@ -211519,6 +211769,7 @@
 ||178.175.8.217$all
 ||178.175.8.223$all
 ||178.175.8.225$all
+||178.175.8.227$all
 ||178.175.8.233$all
 ||178.175.8.238$all
 ||178.175.8.24$all
@@ -211535,6 +211786,7 @@
 ||178.175.8.60$all
 ||178.175.8.61$all
 ||178.175.8.63$all
+||178.175.8.64$all
 ||178.175.8.67$all
 ||178.175.8.69$all
 ||178.175.8.72$all
@@ -211650,6 +211902,7 @@
 ||178.175.80.82$all
 ||178.175.80.86$all
 ||178.175.80.87$all
+||178.175.80.89$all
 ||178.175.80.90$all
 ||178.175.80.91$all
 ||178.175.80.92$all
@@ -211701,6 +211954,7 @@
 ||178.175.81.185$all
 ||178.175.81.186$all
 ||178.175.81.189$all
+||178.175.81.19$all
 ||178.175.81.192$all
 ||178.175.81.194$all
 ||178.175.81.197$all
@@ -211815,6 +212069,7 @@
 ||178.175.82.224$all
 ||178.175.82.226$all
 ||178.175.82.228$all
+||178.175.82.23$all
 ||178.175.82.230$all
 ||178.175.82.233$all
 ||178.175.82.235$all
@@ -211876,11 +212131,13 @@
 ||178.175.83.125$all
 ||178.175.83.130$all
 ||178.175.83.133$all
+||178.175.83.136$all
 ||178.175.83.137$all
 ||178.175.83.138$all
 ||178.175.83.139$all
 ||178.175.83.141$all
 ||178.175.83.143$all
+||178.175.83.144$all
 ||178.175.83.145$all
 ||178.175.83.147$all
 ||178.175.83.15$all
@@ -211997,6 +212254,7 @@
 ||178.175.84.158$all
 ||178.175.84.159$all
 ||178.175.84.16$all
+||178.175.84.17$all
 ||178.175.84.170$all
 ||178.175.84.178$all
 ||178.175.84.180$all
@@ -212450,10 +212708,12 @@
 ||178.175.88.230$all
 ||178.175.88.236$all
 ||178.175.88.237$all
+||178.175.88.24$all
 ||178.175.88.241$all
 ||178.175.88.242$all
 ||178.175.88.243$all
 ||178.175.88.246$all
+||178.175.88.248$all
 ||178.175.88.251$all
 ||178.175.88.253$all
 ||178.175.88.254$all
@@ -212554,6 +212814,7 @@
 ||178.175.89.25$all
 ||178.175.89.253$all
 ||178.175.89.28$all
+||178.175.89.30$all
 ||178.175.89.31$all
 ||178.175.89.33$all
 ||178.175.89.37$all
@@ -212691,6 +212952,7 @@
 ||178.175.90.177$all
 ||178.175.90.178$all
 ||178.175.90.179$all
+||178.175.90.185$all
 ||178.175.90.186$all
 ||178.175.90.187$all
 ||178.175.90.188$all
@@ -212745,6 +213007,7 @@
 ||178.175.90.79$all
 ||178.175.90.8$all
 ||178.175.90.80$all
+||178.175.90.81$all
 ||178.175.90.85$all
 ||178.175.90.89$all
 ||178.175.90.90$all
@@ -212937,6 +213200,7 @@
 ||178.175.92.42$all
 ||178.175.92.43$all
 ||178.175.92.45$all
+||178.175.92.48$all
 ||178.175.92.51$all
 ||178.175.92.54$all
 ||178.175.92.61$all
@@ -212997,6 +213261,7 @@
 ||178.175.93.196$all
 ||178.175.93.197$all
 ||178.175.93.198$all
+||178.175.93.199$all
 ||178.175.93.200$all
 ||178.175.93.202$all
 ||178.175.93.203$all
@@ -213188,6 +213453,7 @@
 ||178.175.95.154$all
 ||178.175.95.156$all
 ||178.175.95.158$all
+||178.175.95.163$all
 ||178.175.95.164$all
 ||178.175.95.165$all
 ||178.175.95.166$all
@@ -213289,6 +213555,7 @@
 ||178.175.96.169$all
 ||178.175.96.180$all
 ||178.175.96.181$all
+||178.175.96.187$all
 ||178.175.96.189$all
 ||178.175.96.192$all
 ||178.175.96.195$all
@@ -213340,6 +213607,7 @@
 ||178.175.96.70$all
 ||178.175.96.75$all
 ||178.175.96.8$all
+||178.175.96.81$all
 ||178.175.96.82$all
 ||178.175.96.88$all
 ||178.175.96.95$all
@@ -213408,6 +213676,7 @@
 ||178.175.97.219$all
 ||178.175.97.220$all
 ||178.175.97.224$all
+||178.175.97.225$all
 ||178.175.97.23$all
 ||178.175.97.230$all
 ||178.175.97.231$all
@@ -213472,6 +213741,7 @@
 ||178.175.98.205$all
 ||178.175.98.206$all
 ||178.175.98.207$all
+||178.175.98.216$all
 ||178.175.98.217$all
 ||178.175.98.221$all
 ||178.175.98.224$all
@@ -214142,6 +214412,7 @@
 ||178.95.195.240$all
 ||178.95.197.16$all
 ||178.95.197.55$all
+||178.95.197.91$all
 ||178.95.198.146$all
 ||178.95.199.144$all
 ||178.95.199.175$all
@@ -214463,6 +214734,7 @@
 ||179.42.107.127$all
 ||179.42.107.128$all
 ||179.42.107.137$all
+||179.42.107.139$all
 ||179.42.107.141$all
 ||179.42.107.144$all
 ||179.42.107.149$all
@@ -215828,6 +216100,7 @@
 ||180.188.224.104$all
 ||180.188.236.174$all
 ||180.188.236.247$all
+||180.188.236.32$all
 ||180.188.236.9$all
 ||180.188.241.111$all
 ||180.188.241.115$all
@@ -216012,6 +216285,7 @@
 ||180.253.17.128$all
 ||180.253.191.125$all
 ||180.253.27.248$all
+||180.253.99.109$all
 ||180.254.167.231$all
 ||180.254.241.245$all
 ||180.254.53.113$all
@@ -217190,6 +217464,7 @@
 ||182.112.28.104$all
 ||182.112.28.108$all
 ||182.112.28.116$all
+||182.112.28.118$all
 ||182.112.28.122$all
 ||182.112.28.123$all
 ||182.112.28.13$all
@@ -217424,6 +217699,7 @@
 ||182.112.34.187$all
 ||182.112.34.20$all
 ||182.112.34.202$all
+||182.112.34.220$all
 ||182.112.34.233$all
 ||182.112.34.25$all
 ||182.112.34.34$all
@@ -219677,6 +219953,7 @@
 ||182.113.238.135$all
 ||182.113.238.136$all
 ||182.113.238.165$all
+||182.113.238.197$all
 ||182.113.238.199$all
 ||182.113.238.20$all
 ||182.113.238.28$all
@@ -219871,6 +220148,7 @@
 ||182.113.29.230$all
 ||182.113.29.241$all
 ||182.113.29.245$all
+||182.113.29.28$all
 ||182.113.29.44$all
 ||182.113.29.46$all
 ||182.113.29.54$all
@@ -221882,6 +222160,7 @@
 ||182.114.76.254$all
 ||182.114.76.39$all
 ||182.114.76.41$all
+||182.114.76.42$all
 ||182.114.76.50$all
 ||182.114.76.67$all
 ||182.114.76.81$all
@@ -223932,6 +224211,7 @@
 ||182.116.116.61$all
 ||182.116.116.64$all
 ||182.116.116.68$all
+||182.116.116.70$all
 ||182.116.116.73$all
 ||182.116.116.75$all
 ||182.116.116.76$all
@@ -224108,6 +224388,7 @@
 ||182.116.119.53$all
 ||182.116.119.56$all
 ||182.116.119.59$all
+||182.116.119.66$all
 ||182.116.119.68$all
 ||182.116.119.7$all
 ||182.116.119.74$all
@@ -224294,6 +224575,7 @@
 ||182.116.36.149$all
 ||182.116.36.15$all
 ||182.116.36.174$all
+||182.116.36.175$all
 ||182.116.36.180$all
 ||182.116.36.195$all
 ||182.116.36.199$all
@@ -226604,6 +226886,7 @@
 ||182.117.13.21$all
 ||182.117.13.32$all
 ||182.117.13.4$all
+||182.117.13.57$all
 ||182.117.13.71$all
 ||182.117.13.73$all
 ||182.117.13.75$all
@@ -229972,6 +230255,7 @@
 ||182.118.164.227$all
 ||182.118.164.248$all
 ||182.118.165.190$all
+||182.118.166.128$all
 ||182.118.166.153$all
 ||182.118.166.36$all
 ||182.118.166.82$all
@@ -230715,6 +230999,7 @@
 ||182.119.15.63$all
 ||182.119.15.68$all
 ||182.119.15.70$all
+||182.119.15.78$all
 ||182.119.15.81$all
 ||182.119.15.86$all
 ||182.119.15.91$all
@@ -230975,6 +231260,7 @@
 ||182.119.166.4$all
 ||182.119.166.64$all
 ||182.119.166.72$all
+||182.119.166.76$all
 ||182.119.166.84$all
 ||182.119.166.9$all
 ||182.119.166.94$all
@@ -231140,6 +231426,7 @@
 ||182.119.179.130$all
 ||182.119.179.169$all
 ||182.119.179.17$all
+||182.119.179.193$all
 ||182.119.179.199$all
 ||182.119.179.202$all
 ||182.119.179.230$all
@@ -231518,6 +231805,7 @@
 ||182.119.196.160$all
 ||182.119.196.182$all
 ||182.119.196.190$all
+||182.119.197.123$all
 ||182.119.199.158$all
 ||182.119.199.85$all
 ||182.119.2.110$all
@@ -231618,6 +231906,7 @@
 ||182.119.202.159$all
 ||182.119.202.170$all
 ||182.119.202.179$all
+||182.119.202.180$all
 ||182.119.202.189$all
 ||182.119.202.20$all
 ||182.119.202.201$all
@@ -231818,6 +232107,7 @@
 ||182.119.21.39$all
 ||182.119.21.46$all
 ||182.119.21.54$all
+||182.119.21.68$all
 ||182.119.21.76$all
 ||182.119.21.79$all
 ||182.119.21.81$all
@@ -233461,6 +233751,7 @@
 ||182.119.88.4$all
 ||182.119.88.54$all
 ||182.119.88.88$all
+||182.119.89.107$all
 ||182.119.89.11$all
 ||182.119.89.123$all
 ||182.119.89.126$all
@@ -236311,6 +236602,7 @@
 ||182.121.15.199$all
 ||182.121.15.203$all
 ||182.121.15.219$all
+||182.121.15.223$all
 ||182.121.15.227$all
 ||182.121.15.237$all
 ||182.121.15.252$all
@@ -238191,6 +238483,7 @@
 ||182.121.254.117$all
 ||182.121.254.127$all
 ||182.121.254.132$all
+||182.121.254.147$all
 ||182.121.254.15$all
 ||182.121.254.152$all
 ||182.121.254.198$all
@@ -239237,6 +239530,7 @@
 ||182.121.54.8$all
 ||182.121.54.81$all
 ||182.121.54.95$all
+||182.121.55.106$all
 ||182.121.55.109$all
 ||182.121.55.112$all
 ||182.121.55.122$all
@@ -241957,6 +242251,7 @@
 ||182.123.241.130$all
 ||182.123.241.172$all
 ||182.123.241.173$all
+||182.123.241.195$all
 ||182.123.241.200$all
 ||182.123.241.214$all
 ||182.123.241.23$all
@@ -242767,6 +243062,7 @@
 ||182.124.200.94$all
 ||182.124.201.176$all
 ||182.124.201.186$all
+||182.124.201.207$all
 ||182.124.201.222$all
 ||182.124.202.211$all
 ||182.124.202.241$all
@@ -244288,6 +244584,7 @@
 ||182.126.123.185$all
 ||182.126.123.188$all
 ||182.126.123.189$all
+||182.126.123.19$all
 ||182.126.123.191$all
 ||182.126.123.193$all
 ||182.126.123.199$all
@@ -246549,6 +246846,7 @@
 ||182.127.106.176$all
 ||182.127.106.216$all
 ||182.127.106.217$all
+||182.127.106.43$all
 ||182.127.106.5$all
 ||182.127.106.53$all
 ||182.127.106.57$all
@@ -249995,6 +250293,7 @@
 ||182.127.93.229$all
 ||182.127.93.230$all
 ||182.127.93.35$all
+||182.127.93.38$all
 ||182.127.93.39$all
 ||182.127.93.4$all
 ||182.127.93.42$all
@@ -250442,6 +250741,7 @@
 ||182.245.26.132$all
 ||182.245.26.171$all
 ||182.245.27.165$all
+||182.245.28.162$all
 ||182.245.28.80$all
 ||182.245.34.249$all
 ||182.245.34.32$all
@@ -251107,6 +251407,7 @@
 ||182.56.192.77$all
 ||182.56.193.147$all
 ||182.56.193.161$all
+||182.56.193.251$all
 ||182.56.193.26$all
 ||182.56.193.39$all
 ||182.56.193.46$all
@@ -255725,6 +256026,7 @@
 ||182.59.222.42$all
 ||182.59.222.60$all
 ||182.59.222.96$all
+||182.59.223.113$all
 ||182.59.223.124$all
 ||182.59.223.127$all
 ||182.59.223.131$all
@@ -255916,6 +256218,7 @@
 ||182.59.235.100$all
 ||182.59.235.107$all
 ||182.59.235.121$all
+||182.59.235.150$all
 ||182.59.235.151$all
 ||182.59.235.157$all
 ||182.59.235.164$all
@@ -258274,6 +258577,7 @@
 ||183.185.113.113$all
 ||183.185.115.92$all
 ||183.185.125.227$all
+||183.185.162.225$all
 ||183.185.168.107$all
 ||183.185.168.165$all
 ||183.185.169.102$all
@@ -258668,6 +258972,7 @@
 ||183.188.90.55$all
 ||183.188.91.12$all
 ||183.188.92.208$all
+||183.188.93.116$all
 ||183.188.93.21$all
 ||183.188.94.13$all
 ||183.188.94.195$all
@@ -262177,6 +262482,7 @@
 ||186.33.112.208$all
 ||186.33.112.209$all
 ||186.33.112.210$all
+||186.33.112.211$all
 ||186.33.112.214$all
 ||186.33.112.216$all
 ||186.33.112.218$all
@@ -262264,6 +262570,7 @@
 ||186.33.112.95$all
 ||186.33.112.96$all
 ||186.33.112.97$all
+||186.33.113.137$all
 ||186.33.113.2$all
 ||186.33.113.241$all
 ||186.33.113.5$all
@@ -263546,6 +263853,7 @@
 ||188.116.36.88$all
 ||188.119.112.125$all
 ||188.119.120.135$all
+||188.119.45.194$all
 ||188.119.45.205$all
 ||188.119.49.1$all
 ||188.119.58.176$all
@@ -265890,6 +266198,7 @@
 ||190.72.32.132$all
 ||190.72.62.232$all
 ||190.73.101.231$all
+||190.73.12.149$all
 ||190.73.71.174$all
 ||190.74.22.100$all
 ||190.75.113.109$all
@@ -267086,6 +267395,7 @@
 ||193.38.55.126$all
 ||193.38.55.59$all
 ||193.38.55.73$all
+||193.38.55.9$all
 ||193.39.185.202$all
 ||193.39.185.207$all
 ||193.39.185.214$all
@@ -269616,6 +269926,7 @@
 ||2.68.190.234$all
 ||2.68.192.214$all
 ||2.68.234.169$all
+||2.68.59.23$all
 ||2.68.78.147$all
 ||2.82.200.218$all
 ||2.82.28.27$all
@@ -270901,6 +271212,7 @@
 ||202.164.139.120$all
 ||202.164.139.121$all
 ||202.164.139.123$all
+||202.164.139.124$all
 ||202.164.139.125$all
 ||202.164.139.127$all
 ||202.164.139.128$all
@@ -270995,6 +271307,7 @@
 ||202.164.139.243$all
 ||202.164.139.246$all
 ||202.164.139.247$all
+||202.164.139.248$all
 ||202.164.139.249$all
 ||202.164.139.25$all
 ||202.164.139.252$all
@@ -275338,6 +275651,7 @@
 ||209.133.223.130$all
 ||209.14.30.109$all
 ||209.14.30.121$all
+||209.14.30.132$all
 ||209.14.30.135$all
 ||209.14.30.136$all
 ||209.14.30.156$all
@@ -275349,6 +275663,7 @@
 ||209.14.30.205$all
 ||209.14.30.30$all
 ||209.14.30.54$all
+||209.14.31.111$all
 ||209.14.31.125$all
 ||209.14.31.162$all
 ||209.14.31.163$all
@@ -278065,6 +278380,7 @@
 ||218.32.118.1$all
 ||218.32.118.185$all
 ||218.32.124.170$all
+||218.32.96.158$all
 ||218.32.98.172$all
 ||218.35.198.109$all
 ||218.35.205.235$all
@@ -278163,6 +278479,7 @@
 ||218.57.107.48$all
 ||218.57.109.101$all
 ||218.57.109.155$all
+||218.57.109.48$all
 ||218.57.109.58$all
 ||218.57.115.102$all
 ||218.57.115.124$all
@@ -279709,6 +280026,7 @@
 ||219.154.116.154$all
 ||219.154.116.156$all
 ||219.154.116.166$all
+||219.154.116.168$all
 ||219.154.116.17$all
 ||219.154.116.171$all
 ||219.154.116.185$all
@@ -280362,6 +280680,7 @@
 ||219.154.142.196$all
 ||219.154.142.210$all
 ||219.154.142.239$all
+||219.154.142.35$all
 ||219.154.142.4$all
 ||219.154.142.41$all
 ||219.154.142.43$all
@@ -280497,6 +280816,7 @@
 ||219.154.176.189$all
 ||219.154.176.24$all
 ||219.154.177.205$all
+||219.154.178.138$all
 ||219.154.178.175$all
 ||219.154.178.69$all
 ||219.154.178.72$all
@@ -280705,6 +281025,7 @@
 ||219.154.41.137$all
 ||219.154.41.183$all
 ||219.154.41.31$all
+||219.154.41.36$all
 ||219.154.41.51$all
 ||219.154.42.109$all
 ||219.154.42.121$all
@@ -281014,6 +281335,7 @@
 ||219.155.11.212$all
 ||219.155.11.220$all
 ||219.155.11.240$all
+||219.155.11.252$all
 ||219.155.11.28$all
 ||219.155.11.36$all
 ||219.155.11.41$all
@@ -281652,6 +281974,7 @@
 ||219.155.209.230$all
 ||219.155.209.232$all
 ||219.155.209.25$all
+||219.155.209.253$all
 ||219.155.209.35$all
 ||219.155.209.54$all
 ||219.155.209.74$all
@@ -283024,6 +283347,7 @@
 ||219.155.86.128$all
 ||219.155.86.136$all
 ||219.155.86.145$all
+||219.155.86.156$all
 ||219.155.86.17$all
 ||219.155.86.182$all
 ||219.155.86.191$all
@@ -283854,6 +284178,7 @@
 ||219.156.175.190$all
 ||219.156.175.225$all
 ||219.156.176.129$all
+||219.156.176.153$all
 ||219.156.176.184$all
 ||219.156.176.20$all
 ||219.156.176.64$all
@@ -283864,6 +284189,7 @@
 ||219.156.177.212$all
 ||219.156.177.232$all
 ||219.156.177.71$all
+||219.156.178.130$all
 ||219.156.178.133$all
 ||219.156.178.137$all
 ||219.156.178.179$all
@@ -284514,6 +284840,7 @@
 ||219.156.65.250$all
 ||219.156.65.251$all
 ||219.156.65.27$all
+||219.156.65.47$all
 ||219.156.65.48$all
 ||219.156.65.70$all
 ||219.156.65.71$all
@@ -286178,6 +286505,7 @@
 ||219.157.214.216$all
 ||219.157.214.22$all
 ||219.157.214.221$all
+||219.157.214.235$all
 ||219.157.214.236$all
 ||219.157.214.24$all
 ||219.157.214.31$all
@@ -289990,6 +290318,7 @@
 ||221.13.191.75$all
 ||221.13.191.91$all
 ||221.13.208.118$all
+||221.13.208.159$all
 ||221.13.208.8$all
 ||221.13.210.251$all
 ||221.13.211.121$all
@@ -290739,6 +291068,7 @@
 ||221.14.184.24$all
 ||221.14.184.32$all
 ||221.14.184.76$all
+||221.14.185.105$all
 ||221.14.185.112$all
 ||221.14.185.157$all
 ||221.14.185.4$all
@@ -290860,6 +291190,7 @@
 ||221.14.46.48$all
 ||221.14.47.162$all
 ||221.14.47.182$all
+||221.14.47.189$all
 ||221.14.47.46$all
 ||221.14.47.77$all
 ||221.14.47.82$all
@@ -290868,6 +291199,7 @@
 ||221.14.56.169$all
 ||221.14.56.252$all
 ||221.14.56.67$all
+||221.14.57.175$all
 ||221.14.57.62$all
 ||221.14.58.27$all
 ||221.14.58.5$all
@@ -291019,6 +291351,7 @@
 ||221.15.111.49$all
 ||221.15.111.82$all
 ||221.15.111.96$all
+||221.15.112.103$all
 ||221.15.112.186$all
 ||221.15.112.203$all
 ||221.15.112.220$all
@@ -291660,6 +291993,7 @@
 ||221.15.155.179$all
 ||221.15.155.180$all
 ||221.15.155.184$all
+||221.15.155.186$all
 ||221.15.155.194$all
 ||221.15.155.197$all
 ||221.15.155.199$all
@@ -292395,6 +292729,7 @@
 ||221.15.190.179$all
 ||221.15.190.18$all
 ||221.15.190.188$all
+||221.15.190.2$all
 ||221.15.190.232$all
 ||221.15.190.234$all
 ||221.15.190.247$all
@@ -294674,6 +295009,7 @@
 ||221.201.54.42$all
 ||221.201.54.97$all
 ||221.202.232.175$all
+||221.202.232.230$all
 ||221.202.232.5$all
 ||221.202.234.170$all
 ||221.202.235.198$all
@@ -294968,6 +295304,7 @@
 ||221.214.249.112$all
 ||221.214.249.181$all
 ||221.214.249.199$all
+||221.214.251.109$all
 ||221.214.251.162$all
 ||221.214.251.91$all
 ||221.214.254.15$all
@@ -296727,6 +297064,7 @@
 ||222.136.76.154$all
 ||222.136.76.84$all
 ||222.136.77.141$all
+||222.136.77.190$all
 ||222.136.77.3$all
 ||222.136.77.91$all
 ||222.136.78.29$all
@@ -298114,6 +298452,7 @@
 ||222.137.161.73$all
 ||222.137.161.8$all
 ||222.137.161.85$all
+||222.137.161.88$all
 ||222.137.161.91$all
 ||222.137.161.95$all
 ||222.137.161.96$all
@@ -299290,6 +299629,7 @@
 ||222.137.220.204$all
 ||222.137.220.207$all
 ||222.137.220.212$all
+||222.137.220.215$all
 ||222.137.220.219$all
 ||222.137.220.226$all
 ||222.137.220.244$all
@@ -299499,6 +299839,7 @@
 ||222.137.237.181$all
 ||222.137.237.187$all
 ||222.137.237.190$all
+||222.137.237.203$all
 ||222.137.237.208$all
 ||222.137.237.212$all
 ||222.137.237.217$all
@@ -299981,6 +300322,7 @@
 ||222.137.53.125$all
 ||222.137.53.191$all
 ||222.137.53.192$all
+||222.137.53.193$all
 ||222.137.53.229$all
 ||222.137.53.242$all
 ||222.137.53.255$all
@@ -300893,6 +301235,7 @@
 ||222.138.118.186$all
 ||222.138.118.190$all
 ||222.138.118.191$all
+||222.138.118.192$all
 ||222.138.118.195$all
 ||222.138.118.196$all
 ||222.138.118.2$all
@@ -301755,6 +302098,7 @@
 ||222.138.183.111$all
 ||222.138.183.116$all
 ||222.138.183.117$all
+||222.138.183.120$all
 ||222.138.183.123$all
 ||222.138.183.126$all
 ||222.138.183.129$all
@@ -302147,6 +302491,7 @@
 ||222.138.213.192$all
 ||222.138.213.202$all
 ||222.138.213.219$all
+||222.138.213.235$all
 ||222.138.213.239$all
 ||222.138.213.245$all
 ||222.138.213.31$all
@@ -302776,6 +303121,7 @@
 ||222.138.50.32$all
 ||222.138.50.50$all
 ||222.138.50.75$all
+||222.138.51.203$all
 ||222.138.51.69$all
 ||222.138.52.108$all
 ||222.138.52.200$all
@@ -303026,6 +303372,7 @@
 ||222.139.106.121$all
 ||222.139.106.154$all
 ||222.139.106.230$all
+||222.139.106.55$all
 ||222.139.107.10$all
 ||222.139.107.113$all
 ||222.139.107.137$all
@@ -304552,6 +304899,7 @@
 ||222.140.179.11$all
 ||222.140.179.120$all
 ||222.140.179.14$all
+||222.140.179.142$all
 ||222.140.179.16$all
 ||222.140.179.168$all
 ||222.140.179.178$all
@@ -304791,6 +305139,7 @@
 ||222.140.207.76$all
 ||222.140.207.85$all
 ||222.140.208.132$all
+||222.140.208.18$all
 ||222.140.208.205$all
 ||222.140.208.219$all
 ||222.140.208.45$all
@@ -305111,6 +305460,7 @@
 ||222.141.101.240$all
 ||222.141.101.251$all
 ||222.141.101.254$all
+||222.141.101.39$all
 ||222.141.101.55$all
 ||222.141.101.87$all
 ||222.141.101.92$all
@@ -306134,6 +306484,7 @@
 ||222.141.40.47$all
 ||222.141.40.58$all
 ||222.141.40.65$all
+||222.141.40.69$all
 ||222.141.40.7$all
 ||222.141.40.73$all
 ||222.141.40.75$all
@@ -308422,6 +308773,7 @@
 ||222.81.155.83$all
 ||222.81.155.88$all
 ||222.81.156.100$all
+||222.81.156.229$all
 ||222.81.157.146$all
 ||222.81.157.148$all
 ||222.81.157.177$all
@@ -309914,6 +310266,7 @@
 ||27.153.140.109$all
 ||27.153.141.43$all
 ||27.153.141.80$all
+||27.153.142.115$all
 ||27.153.142.228$all
 ||27.153.142.44$all
 ||27.153.143.113$all
@@ -313911,6 +314264,7 @@
 ||27.208.200.128$all
 ||27.208.200.67$all
 ||27.208.201.212$all
+||27.208.202.165$all
 ||27.208.202.25$all
 ||27.208.203.172$all
 ||27.208.205.119$all
@@ -313961,6 +314315,7 @@
 ||27.208.55.230$all
 ||27.208.55.65$all
 ||27.208.63.93$all
+||27.208.70.115$all
 ||27.208.70.207$all
 ||27.208.72.67$all
 ||27.208.76.142$all
@@ -315016,6 +315371,7 @@
 ||27.213.165.198$all
 ||27.213.166.136$all
 ||27.213.166.174$all
+||27.213.166.50$all
 ||27.213.167.154$all
 ||27.213.167.175$all
 ||27.213.167.180$all
@@ -315740,6 +316096,7 @@
 ||27.215.253.149$all
 ||27.215.254.134$all
 ||27.215.255.209$all
+||27.215.27.143$all
 ||27.215.28.105$all
 ||27.215.28.45$all
 ||27.215.3.1$all
@@ -320118,6 +320475,7 @@
 ||27.41.159.205$all
 ||27.41.159.216$all
 ||27.41.159.26$all
+||27.41.159.28$all
 ||27.41.159.33$all
 ||27.41.159.58$all
 ||27.41.159.76$all
@@ -320867,6 +321225,7 @@
 ||27.41.37.128$all
 ||27.41.37.131$all
 ||27.41.37.133$all
+||27.41.37.155$all
 ||27.41.37.171$all
 ||27.41.37.180$all
 ||27.41.37.187$all
@@ -321015,6 +321374,7 @@
 ||27.41.89.195$all
 ||27.41.89.50$all
 ||27.41.89.89$all
+||27.41.9.105$all
 ||27.41.9.113$all
 ||27.41.9.130$all
 ||27.41.9.135$all
@@ -321067,6 +321427,7 @@
 ||27.41.97.172$all
 ||27.41.97.191$all
 ||27.41.97.2$all
+||27.41.97.36$all
 ||27.41.97.40$all
 ||27.41.97.6$all
 ||27.41.97.94$all
@@ -321101,10 +321462,12 @@
 ||27.43.105.64$all
 ||27.43.106.242$all
 ||27.43.107.181$all
+||27.43.108.78$all
 ||27.43.109.21$all
 ||27.43.110.101$all
 ||27.43.110.185$all
 ||27.43.110.198$all
+||27.43.111.161$all
 ||27.43.111.217$all
 ||27.43.111.46$all
 ||27.43.115.108$all
@@ -321116,6 +321479,7 @@
 ||27.43.116.9$all
 ||27.43.116.96$all
 ||27.43.117.15$all
+||27.43.117.66$all
 ||27.43.117.89$all
 ||27.43.118.111$all
 ||27.43.118.150$all
@@ -321247,6 +321611,7 @@
 ||27.46.22.67$all
 ||27.46.22.83$all
 ||27.46.22.9$all
+||27.46.23.10$all
 ||27.46.23.123$all
 ||27.46.23.181$all
 ||27.46.23.188$all
@@ -321292,6 +321657,7 @@
 ||27.46.44.233$all
 ||27.46.44.235$all
 ||27.46.44.237$all
+||27.46.44.239$all
 ||27.46.44.246$all
 ||27.46.44.254$all
 ||27.46.44.31$all
@@ -321351,6 +321717,7 @@
 ||27.46.45.7$all
 ||27.46.45.82$all
 ||27.46.45.85$all
+||27.46.45.86$all
 ||27.46.45.88$all
 ||27.46.45.89$all
 ||27.46.45.90$all
@@ -322771,6 +323138,7 @@
 ||27.5.30.70$all
 ||27.5.30.71$all
 ||27.5.30.72$all
+||27.5.30.79$all
 ||27.5.30.81$all
 ||27.5.30.82$all
 ||27.5.30.87$all
@@ -323230,6 +323598,7 @@
 ||27.5.36.221$all
 ||27.5.36.222$all
 ||27.5.36.230$all
+||27.5.36.232$all
 ||27.5.36.233$all
 ||27.5.36.234$all
 ||27.5.36.238$all
@@ -323745,6 +324114,7 @@
 ||27.5.41.143$all
 ||27.5.41.144$all
 ||27.5.41.145$all
+||27.5.41.146$all
 ||27.5.41.148$all
 ||27.5.41.149$all
 ||27.5.41.155$all
@@ -326260,6 +326630,7 @@
 ||27.6.122.19$all
 ||27.6.122.192$all
 ||27.6.122.193$all
+||27.6.122.194$all
 ||27.6.122.197$all
 ||27.6.122.2$all
 ||27.6.122.202$all
@@ -331762,6 +332133,7 @@
 ||27.6.240.156$all
 ||27.6.240.161$all
 ||27.6.240.169$all
+||27.6.240.171$all
 ||27.6.240.175$all
 ||27.6.240.181$all
 ||27.6.240.183$all
@@ -331983,6 +332355,7 @@
 ||27.6.243.113$all
 ||27.6.243.117$all
 ||27.6.243.12$all
+||27.6.243.122$all
 ||27.6.243.126$all
 ||27.6.243.127$all
 ||27.6.243.128$all
@@ -332672,6 +333045,7 @@
 ||27.6.34.217$all
 ||27.6.34.60$all
 ||27.6.38.222$all
+||27.6.38.96$all
 ||27.6.4.101$all
 ||27.6.4.102$all
 ||27.6.4.106$all
@@ -345138,6 +345512,7 @@
 ||36.251.18.2$all
 ||36.251.18.40$all
 ||36.251.18.44$all
+||36.251.18.63$all
 ||36.251.19.213$all
 ||36.251.19.231$all
 ||36.251.19.249$all
@@ -345742,6 +346117,7 @@
 ||36.42.107.77$all
 ||36.42.107.99$all
 ||36.43.10.121$all
+||36.43.11.16$all
 ||36.43.11.211$all
 ||36.43.12.163$all
 ||36.43.64.10$all
@@ -345879,6 +346255,7 @@
 ||36.81.158.24$all
 ||36.81.187.39$all
 ||36.81.209.186$all
+||36.81.23.38$all
 ||36.81.230.140$all
 ||36.81.31.124$all
 ||36.82.179.161$all
@@ -349350,6 +349727,7 @@
 ||39.77.44.29$all
 ||39.77.44.32$all
 ||39.77.46.7$all
+||39.77.48.213$all
 ||39.77.49.13$all
 ||39.77.5.113$all
 ||39.77.5.214$all
@@ -349779,6 +350157,7 @@
 ||39.79.162.176$all
 ||39.79.163.104$all
 ||39.79.163.173$all
+||39.79.163.188$all
 ||39.79.163.252$all
 ||39.79.163.96$all
 ||39.79.164.165$all
@@ -350243,6 +350622,7 @@
 ||39.80.35.201$all
 ||39.80.36.151$all
 ||39.80.36.64$all
+||39.80.37.182$all
 ||39.80.38.117$all
 ||39.80.38.27$all
 ||39.80.39.207$all
@@ -353929,6 +354309,7 @@
 ||42.224.122.174$all
 ||42.224.122.176$all
 ||42.224.122.182$all
+||42.224.122.183$all
 ||42.224.122.186$all
 ||42.224.122.19$all
 ||42.224.122.191$all
@@ -355551,6 +355932,7 @@
 ||42.224.188.115$all
 ||42.224.188.137$all
 ||42.224.188.176$all
+||42.224.188.223$all
 ||42.224.188.241$all
 ||42.224.188.250$all
 ||42.224.188.85$all
@@ -355558,6 +355940,7 @@
 ||42.224.189.121$all
 ||42.224.189.153$all
 ||42.224.189.208$all
+||42.224.189.79$all
 ||42.224.189.88$all
 ||42.224.189.89$all
 ||42.224.189.90$all
@@ -356601,6 +356984,7 @@
 ||42.224.249.178$all
 ||42.224.249.18$all
 ||42.224.249.182$all
+||42.224.249.188$all
 ||42.224.249.190$all
 ||42.224.249.195$all
 ||42.224.249.208$all
@@ -357047,6 +357431,7 @@
 ||42.224.3.171$all
 ||42.224.3.179$all
 ||42.224.3.180$all
+||42.224.3.187$all
 ||42.224.3.192$all
 ||42.224.3.205$all
 ||42.224.3.206$all
@@ -357763,6 +358148,7 @@
 ||42.224.52.56$all
 ||42.224.52.58$all
 ||42.224.52.8$all
+||42.224.52.81$all
 ||42.224.52.97$all
 ||42.224.53.120$all
 ||42.224.53.130$all
@@ -357904,6 +358290,7 @@
 ||42.224.59.245$all
 ||42.224.59.247$all
 ||42.224.59.249$all
+||42.224.59.251$all
 ||42.224.59.68$all
 ||42.224.59.73$all
 ||42.224.59.74$all
@@ -358283,6 +358670,7 @@
 ||42.224.68.67$all
 ||42.224.68.69$all
 ||42.224.68.70$all
+||42.224.68.72$all
 ||42.224.68.74$all
 ||42.224.68.78$all
 ||42.224.68.79$all
@@ -362145,6 +362533,7 @@
 ||42.228.196.177$all
 ||42.228.196.193$all
 ||42.228.196.218$all
+||42.228.196.68$all
 ||42.228.196.89$all
 ||42.228.197.136$all
 ||42.228.197.142$all
@@ -366989,6 +367378,7 @@
 ||42.230.46.198$all
 ||42.230.46.231$all
 ||42.230.46.246$all
+||42.230.46.55$all
 ||42.230.46.70$all
 ||42.230.46.9$all
 ||42.230.46.93$all
@@ -369414,6 +369804,7 @@
 ||42.231.95.195$all
 ||42.231.95.210$all
 ||42.231.95.230$all
+||42.231.95.247$all
 ||42.231.95.99$all
 ||42.231.96.105$all
 ||42.231.96.176$all
@@ -370350,6 +370741,7 @@
 ||42.232.45.85$all
 ||42.232.46.1$all
 ||42.232.46.129$all
+||42.232.46.169$all
 ||42.232.46.73$all
 ||42.232.46.86$all
 ||42.232.47.212$all
@@ -371046,6 +371438,7 @@
 ||42.233.159.141$all
 ||42.233.159.168$all
 ||42.233.159.19$all
+||42.233.159.21$all
 ||42.233.159.223$all
 ||42.233.159.228$all
 ||42.233.159.230$all
@@ -372569,6 +372962,7 @@
 ||42.234.246.77$all
 ||42.234.247.171$all
 ||42.234.247.4$all
+||42.234.247.41$all
 ||42.234.247.44$all
 ||42.234.247.55$all
 ||42.234.247.57$all
@@ -375857,6 +376251,7 @@
 ||42.235.81.88$all
 ||42.235.82.0$all
 ||42.235.82.108$all
+||42.235.82.112$all
 ||42.235.82.118$all
 ||42.235.82.129$all
 ||42.235.82.141$all
@@ -375887,6 +376282,7 @@
 ||42.235.82.44$all
 ||42.235.82.45$all
 ||42.235.82.46$all
+||42.235.82.52$all
 ||42.235.82.53$all
 ||42.235.82.54$all
 ||42.235.82.60$all
@@ -376077,6 +376473,7 @@
 ||42.235.86.87$all
 ||42.235.86.95$all
 ||42.235.87.1$all
+||42.235.87.100$all
 ||42.235.87.102$all
 ||42.235.87.103$all
 ||42.235.87.121$all
@@ -377262,6 +377659,7 @@
 ||42.237.14.202$all
 ||42.237.14.74$all
 ||42.237.14.8$all
+||42.237.142.157$all
 ||42.237.15.110$all
 ||42.237.15.142$all
 ||42.237.15.153$all
@@ -377371,6 +377769,7 @@
 ||42.237.24.108$all
 ||42.237.24.129$all
 ||42.237.24.14$all
+||42.237.24.151$all
 ||42.237.24.166$all
 ||42.237.24.220$all
 ||42.237.24.23$all
@@ -377623,6 +378022,7 @@
 ||42.237.60.219$all
 ||42.237.60.254$all
 ||42.237.60.42$all
+||42.237.60.73$all
 ||42.237.61.107$all
 ||42.237.61.152$all
 ||42.237.61.246$all
@@ -378252,6 +378652,7 @@
 ||42.238.227.72$all
 ||42.238.227.86$all
 ||42.238.227.95$all
+||42.238.228.0$all
 ||42.238.228.122$all
 ||42.238.228.132$all
 ||42.238.228.220$all
@@ -378440,6 +378841,7 @@
 ||42.238.250.202$all
 ||42.238.250.246$all
 ||42.238.250.248$all
+||42.238.250.56$all
 ||42.238.251.226$all
 ||42.238.251.47$all
 ||42.238.251.61$all
@@ -378956,6 +379358,7 @@
 ||42.239.154.85$all
 ||42.239.155.124$all
 ||42.239.155.143$all
+||42.239.155.147$all
 ||42.239.155.158$all
 ||42.239.155.159$all
 ||42.239.155.165$all
@@ -379224,6 +379627,7 @@
 ||42.239.201.20$all
 ||42.239.201.86$all
 ||42.239.202.100$all
+||42.239.202.121$all
 ||42.239.202.145$all
 ||42.239.202.227$all
 ||42.239.202.229$all
@@ -379318,6 +379722,7 @@
 ||42.239.217.21$all
 ||42.239.217.228$all
 ||42.239.217.56$all
+||42.239.218.137$all
 ||42.239.218.141$all
 ||42.239.218.157$all
 ||42.239.218.63$all
@@ -381577,6 +381982,7 @@
 ||45.176.108.154$all
 ||45.176.108.157$all
 ||45.176.108.161$all
+||45.176.108.164$all
 ||45.176.108.168$all
 ||45.176.108.170$all
 ||45.176.108.18$all
@@ -386717,6 +387123,7 @@
 ||5.39.218.162$all
 ||5.39.219.130$all
 ||5.39.223.68$all
+||5.42.37.74$all
 ||5.42.48.223$all
 ||5.42.82.17$all
 ||5.42.92.195$all
@@ -387478,6 +387885,7 @@
 ||58.11.78.109$all
 ||58.114.245.23$all
 ||58.114.246.26$all
+||58.115.108.164$all
 ||58.115.160.50$all
 ||58.115.162.92$all
 ||58.115.166.148$all
@@ -388147,6 +388555,7 @@
 ||58.248.116.190$all
 ||58.248.116.199$all
 ||58.248.116.2$all
+||58.248.116.21$all
 ||58.248.116.210$all
 ||58.248.116.216$all
 ||58.248.116.222$all
@@ -388177,6 +388586,7 @@
 ||58.248.117.218$all
 ||58.248.117.226$all
 ||58.248.117.233$all
+||58.248.117.238$all
 ||58.248.117.244$all
 ||58.248.117.253$all
 ||58.248.117.4$all
@@ -388333,6 +388743,7 @@
 ||58.248.142.11$all
 ||58.248.142.111$all
 ||58.248.142.116$all
+||58.248.142.132$all
 ||58.248.142.137$all
 ||58.248.142.138$all
 ||58.248.142.148$all
@@ -388358,6 +388769,7 @@
 ||58.248.142.239$all
 ||58.248.142.24$all
 ||58.248.142.4$all
+||58.248.142.5$all
 ||58.248.142.53$all
 ||58.248.142.64$all
 ||58.248.142.67$all
@@ -388490,6 +388902,7 @@
 ||58.248.147.159$all
 ||58.248.147.179$all
 ||58.248.147.182$all
+||58.248.147.196$all
 ||58.248.147.208$all
 ||58.248.147.224$all
 ||58.248.147.226$all
@@ -388592,6 +389005,7 @@
 ||58.248.151.247$all
 ||58.248.151.248$all
 ||58.248.151.25$all
+||58.248.151.33$all
 ||58.248.151.4$all
 ||58.248.151.48$all
 ||58.248.151.6$all
@@ -388685,6 +389099,7 @@
 ||58.248.74.230$all
 ||58.248.74.236$all
 ||58.248.74.24$all
+||58.248.74.240$all
 ||58.248.74.241$all
 ||58.248.74.246$all
 ||58.248.74.41$all
@@ -389364,6 +389779,7 @@
 ||58.249.72.49$all
 ||58.249.72.67$all
 ||58.249.72.69$all
+||58.249.72.88$all
 ||58.249.72.95$all
 ||58.249.72.98$all
 ||58.249.73.1$all
@@ -389420,6 +389836,7 @@
 ||58.249.74.222$all
 ||58.249.74.227$all
 ||58.249.74.235$all
+||58.249.74.243$all
 ||58.249.74.245$all
 ||58.249.74.248$all
 ||58.249.74.35$all
@@ -389445,6 +389862,7 @@
 ||58.249.75.194$all
 ||58.249.75.20$all
 ||58.249.75.209$all
+||58.249.75.213$all
 ||58.249.75.214$all
 ||58.249.75.218$all
 ||58.249.75.233$all
@@ -389617,6 +390035,7 @@
 ||58.249.80.242$all
 ||58.249.80.245$all
 ||58.249.80.246$all
+||58.249.80.25$all
 ||58.249.80.37$all
 ||58.249.80.38$all
 ||58.249.80.46$all
@@ -389902,6 +390321,7 @@
 ||58.249.89.143$all
 ||58.249.89.15$all
 ||58.249.89.157$all
+||58.249.89.158$all
 ||58.249.89.160$all
 ||58.249.89.162$all
 ||58.249.89.167$all
@@ -390310,6 +390730,7 @@
 ||58.255.140.125$all
 ||58.255.140.146$all
 ||58.255.140.149$all
+||58.255.140.150$all
 ||58.255.140.156$all
 ||58.255.140.190$all
 ||58.255.140.21$all
@@ -390885,6 +391306,7 @@
 ||59.127.10.103$all
 ||59.127.108.38$all
 ||59.127.109.11$all
+||59.127.11.50$all
 ||59.127.124.161$all
 ||59.127.125.164$all
 ||59.127.130.170$all
@@ -395722,6 +396144,7 @@
 ||59.92.176.201$all
 ||59.92.176.202$all
 ||59.92.176.209$all
+||59.92.176.21$all
 ||59.92.176.218$all
 ||59.92.176.221$all
 ||59.92.176.222$all
@@ -395731,6 +396154,7 @@
 ||59.92.176.233$all
 ||59.92.176.235$all
 ||59.92.176.236$all
+||59.92.176.24$all
 ||59.92.176.243$all
 ||59.92.176.244$all
 ||59.92.176.245$all
@@ -395745,6 +396169,7 @@
 ||59.92.176.40$all
 ||59.92.176.41$all
 ||59.92.176.44$all
+||59.92.176.45$all
 ||59.92.176.47$all
 ||59.92.176.55$all
 ||59.92.176.56$all
@@ -395952,7 +396377,9 @@
 ||59.92.179.114$all
 ||59.92.179.115$all
 ||59.92.179.119$all
+||59.92.179.12$all
 ||59.92.179.123$all
+||59.92.179.124$all
 ||59.92.179.125$all
 ||59.92.179.13$all
 ||59.92.179.14$all
@@ -396025,6 +396452,7 @@
 ||59.92.18.145$all
 ||59.92.18.152$all
 ||59.92.18.155$all
+||59.92.18.156$all
 ||59.92.18.159$all
 ||59.92.18.161$all
 ||59.92.18.170$all
@@ -396348,6 +396776,7 @@
 ||59.92.181.221$all
 ||59.92.181.222$all
 ||59.92.181.223$all
+||59.92.181.224$all
 ||59.92.181.225$all
 ||59.92.181.226$all
 ||59.92.181.227$all
@@ -396471,6 +396900,7 @@
 ||59.92.182.138$all
 ||59.92.182.14$all
 ||59.92.182.140$all
+||59.92.182.141$all
 ||59.92.182.144$all
 ||59.92.182.145$all
 ||59.92.182.147$all
@@ -396833,6 +397263,7 @@
 ||59.92.19.211$all
 ||59.92.19.212$all
 ||59.92.19.229$all
+||59.92.19.230$all
 ||59.92.19.235$all
 ||59.92.19.24$all
 ||59.92.19.244$all
@@ -398162,6 +398593,7 @@
 ||59.93.19.99$all
 ||59.93.20.0$all
 ||59.93.20.1$all
+||59.93.20.104$all
 ||59.93.20.106$all
 ||59.93.20.107$all
 ||59.93.20.110$all
@@ -398237,6 +398669,7 @@
 ||59.93.21.111$all
 ||59.93.21.115$all
 ||59.93.21.117$all
+||59.93.21.119$all
 ||59.93.21.121$all
 ||59.93.21.126$all
 ||59.93.21.127$all
@@ -401204,6 +401637,7 @@
 ||59.96.37.177$all
 ||59.96.37.179$all
 ||59.96.37.180$all
+||59.96.37.181$all
 ||59.96.37.182$all
 ||59.96.37.183$all
 ||59.96.37.185$all
@@ -401280,6 +401714,7 @@
 ||59.96.37.34$all
 ||59.96.37.35$all
 ||59.96.37.37$all
+||59.96.37.38$all
 ||59.96.37.39$all
 ||59.96.37.4$all
 ||59.96.37.40$all
@@ -401666,6 +402101,7 @@
 ||59.96.39.241$all
 ||59.96.39.242$all
 ||59.96.39.243$all
+||59.96.39.244$all
 ||59.96.39.246$all
 ||59.96.39.247$all
 ||59.96.39.248$all
@@ -404091,6 +404527,7 @@
 ||59.99.139.184$all
 ||59.99.139.186$all
 ||59.99.139.189$all
+||59.99.139.19$all
 ||59.99.139.190$all
 ||59.99.139.191$all
 ||59.99.139.192$all
@@ -404145,6 +404582,7 @@
 ||59.99.139.64$all
 ||59.99.139.66$all
 ||59.99.139.68$all
+||59.99.139.71$all
 ||59.99.139.73$all
 ||59.99.139.76$all
 ||59.99.139.78$all
@@ -404438,6 +404876,7 @@
 ||59.99.142.157$all
 ||59.99.142.158$all
 ||59.99.142.159$all
+||59.99.142.163$all
 ||59.99.142.164$all
 ||59.99.142.165$all
 ||59.99.142.167$all
@@ -404540,6 +404979,7 @@
 ||59.99.143.112$all
 ||59.99.143.113$all
 ||59.99.143.114$all
+||59.99.143.115$all
 ||59.99.143.117$all
 ||59.99.143.119$all
 ||59.99.143.120$all
@@ -404837,6 +405277,7 @@
 ||59.99.190.18$all
 ||59.99.190.182$all
 ||59.99.190.187$all
+||59.99.190.189$all
 ||59.99.190.190$all
 ||59.99.190.191$all
 ||59.99.190.192$all
@@ -405669,6 +406110,7 @@
 ||59.99.44.123$all
 ||59.99.44.124$all
 ||59.99.44.125$all
+||59.99.44.126$all
 ||59.99.44.129$all
 ||59.99.44.131$all
 ||59.99.44.132$all
@@ -405863,6 +406305,7 @@
 ||59.99.45.153$all
 ||59.99.45.154$all
 ||59.99.45.155$all
+||59.99.45.156$all
 ||59.99.45.158$all
 ||59.99.45.16$all
 ||59.99.45.160$all
@@ -406039,6 +406482,7 @@
 ||59.99.46.166$all
 ||59.99.46.167$all
 ||59.99.46.168$all
+||59.99.46.170$all
 ||59.99.46.171$all
 ||59.99.46.172$all
 ||59.99.46.174$all
@@ -406046,6 +406490,7 @@
 ||59.99.46.176$all
 ||59.99.46.177$all
 ||59.99.46.18$all
+||59.99.46.180$all
 ||59.99.46.181$all
 ||59.99.46.182$all
 ||59.99.46.183$all
@@ -406998,6 +407443,7 @@
 ||59.99.95.161$all
 ||59.99.95.162$all
 ||59.99.95.164$all
+||59.99.95.166$all
 ||59.99.95.167$all
 ||59.99.95.168$all
 ||59.99.95.169$all
@@ -408322,6 +408768,7 @@
 ||60.212.11.156$all
 ||60.212.110.19$all
 ||60.212.110.3$all
+||60.212.111.39$all
 ||60.212.117.125$all
 ||60.212.117.206$all
 ||60.212.117.51$all
@@ -408688,6 +409135,7 @@
 ||60.214.217.79$all
 ||60.214.217.82$all
 ||60.214.217.85$all
+||60.214.217.96$all
 ||60.214.218.136$all
 ||60.214.218.192$all
 ||60.214.218.196$all
@@ -408780,6 +409228,7 @@
 ||60.214.32.138$all
 ||60.214.32.150$all
 ||60.214.32.151$all
+||60.214.32.17$all
 ||60.214.32.236$all
 ||60.214.32.243$all
 ||60.214.32.244$all
@@ -418963,6 +419412,7 @@
 ||61.128.83.148$all
 ||61.128.88.38$all
 ||61.129.101.57$all
+||61.130.195.121$all
 ||61.130.195.172$all
 ||61.130.198.170$all
 ||61.130.224.119$all
@@ -421473,6 +421923,7 @@
 ||61.3.151.37$all
 ||61.3.151.38$all
 ||61.3.151.56$all
+||61.3.151.60$all
 ||61.3.151.66$all
 ||61.3.151.70$all
 ||61.3.151.84$all
@@ -421750,6 +422201,7 @@
 ||61.52.103.2$all
 ||61.52.103.20$all
 ||61.52.103.21$all
+||61.52.103.217$all
 ||61.52.103.220$all
 ||61.52.103.228$all
 ||61.52.103.229$all
@@ -421788,6 +422240,7 @@
 ||61.52.103.91$all
 ||61.52.103.93$all
 ||61.52.103.99$all
+||61.52.109.9$all
 ||61.52.11.12$all
 ||61.52.11.15$all
 ||61.52.11.2$all
@@ -422139,6 +422592,7 @@
 ||61.52.166.218$all
 ||61.52.167.246$all
 ||61.52.167.249$all
+||61.52.167.66$all
 ||61.52.167.89$all
 ||61.52.168.106$all
 ||61.52.168.121$all
@@ -422978,6 +423432,7 @@
 ||61.52.211.31$all
 ||61.52.211.38$all
 ||61.52.211.59$all
+||61.52.211.61$all
 ||61.52.211.75$all
 ||61.52.211.76$all
 ||61.52.211.77$all
@@ -423628,6 +424083,7 @@
 ||61.52.30.159$all
 ||61.52.30.160$all
 ||61.52.30.161$all
+||61.52.30.172$all
 ||61.52.30.174$all
 ||61.52.30.176$all
 ||61.52.30.178$all
@@ -423874,6 +424330,7 @@
 ||61.52.4.127$all
 ||61.52.4.138$all
 ||61.52.4.151$all
+||61.52.4.214$all
 ||61.52.4.220$all
 ||61.52.4.59$all
 ||61.52.4.81$all
@@ -423927,6 +424384,7 @@
 ||61.52.42.112$all
 ||61.52.42.134$all
 ||61.52.42.138$all
+||61.52.42.174$all
 ||61.52.42.192$all
 ||61.52.42.196$all
 ||61.52.42.20$all
@@ -425401,6 +425859,7 @@
 ||61.52.98.210$all
 ||61.52.98.214$all
 ||61.52.98.215$all
+||61.52.98.22$all
 ||61.52.98.220$all
 ||61.52.98.231$all
 ||61.52.98.244$all
@@ -429968,6 +430427,7 @@
 ||62.76.5.154$all
 ||62.77.210.124$all
 ||62.78.131.240$all
+||62.78.82.93$all
 ||62.80.167.71$all
 ||62.80.231.196$all
 ||62.80.235.224$all
@@ -430802,6 +431262,7 @@
 ||68.183.24.160$all
 ||68.183.24.34$all
 ||68.183.25.231$all
+||68.183.25.71$all
 ||68.183.26.100$all
 ||68.183.26.166$all
 ||68.183.26.74$all
@@ -430933,6 +431394,7 @@
 ||68.99.179.195$all
 ||68.99.179.89$all
 ||68.99.180.30$all
+||68468438438.xyz$all
 ||68h7.com$all
 ||68yuanzhijia.xyz/wp-admin/y2kbcwlezlkontymoscer2ggetzbjqxb0oybicpckgboagxr7t/$all
 ||69.10.193.239$all
@@ -431991,6 +432453,7 @@
 ||77.43.248.83$all
 ||77.43.250.181$all
 ||77.43.250.205$all
+||77.43.250.246$all
 ||77.43.251.170$all
 ||77.43.251.196$all
 ||77.43.251.77$all
@@ -432092,6 +432555,7 @@
 ||77.49.200.235$all
 ||77.51.189.86$all
 ||77.52.180.138$all
+||77.53.144.46$all
 ||77.53.145.33$all
 ||77.53.2.182$all
 ||77.53.246.179$all
@@ -438421,6 +438885,7 @@
 ||999.buzz$all
 ||999.co.id$all
 ||999.rajaojek.com$all
+||999080321newfolder1002002131-service1002.space$all
 ||999102com.cn$all
 ||99bkx.com$all
 ||99centsdigitals.com$all
@@ -440034,7 +440499,7 @@
 ||adventureexplorer.in$all
 ||adventurehr.com$all
 ||adventureitdate.com$all
-||adventureits.com/wp-content/6399952952/q54d7zyhe/$all
+||adventureits.com$all
 ||adventuremania.com$all
 ||adventureracen.nl/cgi-bin/parts_service/$all
 ||adventurersafaris.com$all
@@ -441092,6 +441557,7 @@
 ||akatanomastos.net$all
 ||akatlot.com$all
 ||akatsolution.net$all
+||akauk09.top$all
 ||akaunting.redocom.com$all
 ||akawork.io$all
 ||akbaara.com$all
@@ -441175,6 +441641,7 @@
 ||akowa.projet-test.com$all
 ||akowalska.ecrm.pl$all
 ||akpeugono.com$all
+||akpgi08.top$all
 ||akpp-service.top$all
 ||akppservis30.ru$all
 ||akprokonaija.com$all
@@ -447024,6 +447491,7 @@
 ||b2streeteats.com$all
 ||b3shop.net$all
 ||b4512652-a-62cb3a1a-s-sites.googlegroups.com$all
+||b4ad7b79-534a-4e83-953e-c36da8cf27d9.s3.amazonaws.com/ww/setup.exe$all
 ||b4ckdoorarchive.com$all
 ||b4events.it$all
 ||b5.doshimotai.ru$all
@@ -454042,7 +454510,7 @@
 ||camelmorocco.com$all
 ||camelotbrasil.com$all
 ||camelotorganics.com$all
-||cameltrektours.com/wordpress_fille/overview/$all
+||cameltrektours.com$all
 ||camenisch-software.ch$all
 ||camera.risami.net$all
 ||camera88.vn$all
@@ -456017,9 +456485,14 @@
 ||cdn.discordapp.com/attachments/821484577327022114/821484844893732874/2tgyjedsrgftyuikjsedrfgtgh.txt$all
 ||cdn.discordapp.com/attachments/821484577327022114/821484978260672592/ytguj3tgyhjedrgtgyfhjrft.txt$all
 ||cdn.discordapp.com/attachments/821511904769998921/821511945881911306/panam.exe$all
+||cdn.discordapp.com/attachments/821809080812437507/824392185902006272/mmp1_1.exe$all
 ||cdn.discordapp.com/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso$all
 ||cdn.discordapp.com/attachments/823624203529486349/823684377765871646/we.jpg$all
 ||cdn.discordapp.com/attachments/823801311480250391/824870560605274122/bilfx1x.exe$all
+||cdn.discordapp.com/attachments/823810712891555890/824413943526195210/runpetest.exe$all
+||cdn.discordapp.com/attachments/824689793140129857/824690055498170398/token_stealer.bat$all
+||cdn.discordapp.com/attachments/824689793140129857/824690065988386816/sendhookfile.exe$all
+||cdn.discordapp.com/attachments/824689793140129857/824691026852970496/photo.exe$all
 ||cdn.discordapp.com/attachments/824721527890641000/824721774205206618/2_5388614236127628287.exe$all
 ||cdn.discordapp.com/attachments/824721527890641000/824722602072997949/222.exe$all
 ||cdn.discordapp.com:443/attachments/790590543397781576/820879760904683561/system.exe$all
@@ -464674,6 +465147,8 @@
 ||digitalangels.eu$all
 ||digitalankur.com$all
 ||digitalassets.ams3.digitaloceanspaces.com/hahaza/visual19.exe$all
+||digitalassets.ams3.digitaloceanspaces.com/hold/schost.exe$all
+||digitalassets.ams3.digitaloceanspaces.com/modern/five.exe$all
 ||digitalassets.ams3.digitaloceanspaces.com/randf/multitimerrt.exe$all
 ||digitalaxom.in$all
 ||digitalbazar.com$all
@@ -465315,6 +465790,7 @@
 ||dl-97674424.md-downloads.com$all
 ||dl-gameplayer.dmm.com/product/apkggame/giga_baldrbringerextendcode/giga_baldrbringerextendcode/win/src/content/data/data/uninstall.exe$all
 ||dl-gameplayer.dmm.com/product/apkggame/nel_narikiri/nel_narikiri/win/src/content/data/%e3%81%aa%e3%82%8a%e3%81%8d%e3%82%8a%e3%83%90%e3%82%ab%e3%83%83%e3%83%97%e3%83%ab%ef%bc%81.exe$all
+||dl-link.link$all
 ||dl-link.live$all
 ||dl-link.network$all
 ||dl-rw.com$all
@@ -483280,6 +483756,7 @@
 ||duckhouse.org$all
 ||duckiesplumbing.com.au$all
 ||duckpvp.xyz$all
+||duckrambo.com$all
 ||ducks.org.tw$all
 ||ducontcl.esy.es$all
 ||ducro.nl$all
@@ -490784,7 +491261,7 @@
 ||freedomsec.com.br$all
 ||freedomsolutionsuk.co.uk$all
 ||freedomtoshine.co$all
-||freedomwellnesstherapy.com/wp-includes/1a0fhsde7zdx9/$all
+||freedomwellnesstherapy.com$all
 ||freedownloadbravebrowser.com$all
 ||freeeeweb-com.umbler.net$all
 ||freeezguru.com$all
@@ -493212,6 +493689,7 @@
 ||gislegal.ir$all
 ||gisselltejeda.com$all
 ||gist.githubusercontent.com/jamme1020031/b0d4eadf162334049858b225bbac3017/raw/309944c554ba111c4b563fbf34ce416062516465/ilike.txt$all
+||gist.githubusercontent.com/jamme1020031/ef880bfeed7c6314b365c84b5999a27c/raw/4b3456ebe9e1a9717598dd416450e0eafe856311/fuuuuu.txt$all
 ||gist.githubusercontent.com/raigabrielmaia/4384962bcff6896cc89eb7b68924f62d/raw/1788cb8fc869dd68f507a462dee4dd6453e0ed24/avast.mp3$all
 ||gist.githubusercontent.com/raigabrielmaia/4384962bcff6896cc89eb7b68924f62d/raw/1788cb8fc869dd68f507a462dee4dd6453e0ed24/avastt.mp3$all
 ||gist.githubusercontent.com/raigabrielmaia/4384962bcff6896cc89eb7b68924f62d/raw/1788cb8fc869dd68f507a462dee4dd6453e0ed24/nod.mp3$all
@@ -499266,7 +499744,7 @@
 ||iappco.ir$all
 ||iar.webprojemiz.com$all
 ||iarpp.ro$all
-||iasdcentralbucaramanga.com/wp-includes/bt9vl1jt8gwkyrcfxcxtur1avcka98qreu1pvdx24wxdbzbfzsyfvs9g7ldu6h/$all
+||iasdcentralbucaramanga.com$all
 ||iasgoogle.com$all
 ||iashelpdesk.in$all
 ||iasira.dm.files.1drv.com$all
@@ -501658,6 +502136,7 @@
 ||investigadoresforenses-abcjuris.com$all
 ||investigatorsnorthwest.co.uk$all
 ||investime.info$all
+||investinae.com$all
 ||investingbazar.com$all
 ||investingpivot.co.uk$all
 ||investinscs.com$all
@@ -503962,7 +504441,7 @@
 ||joeundrosky.com$all
 ||joezer-online.com$all
 ||jofox.nl$all
-||jofre.eu/wp-content/themes/basic/css/msg.jpg$all
+||jofre.eu$all
 ||jogaae.jfoaigh.com$all
 ||joghataisalam.ir$all
 ||joghatay.ir$all
@@ -508544,7 +509023,8 @@
 ||laparoscopysales.com$all
 ||lapartenza-khl.com$all
 ||lapc.com.pk$all
-||lapcare.com$all
+||lapcare.com/wp-content/9fotgty/$all
+||lapcare.com/wp-content/o2bwo/$all
 ||lapcentervn.xyz$all
 ||lapchallenge.co.uk$all
 ||lapelimmortelle.com.au$all
@@ -509714,7 +510194,10 @@
 ||lglab.co.uk$all
 ||lgmi.org.uk$all
 ||lgonlinecenter.com$all
-||lgpass.com$all
+||lgpass.com/images/closed_resource/security_portal/575383_fczjbnodcixu/$all
+||lgpass.com/images/common_resource/interior_cloud/637368803912_d35jil4kauy8qn/$all
+||lgpass.com/images/d1q66rszmw123555/$all
+||lgpass.com/images/wk128/$all
 ||lgrp35.vatelstudents.fr$all
 ||lgs.ec$all
 ||lgservis.net$all
@@ -517449,7 +517932,7 @@
 ||mojang.com.br$all
 ||mojehaftom.com$all
 ||mojewnetrza.pl$all
-||mojno--vse.ru$all
+||mojno--vse.ru/content/6tqjfutopvigfknidf0sfae6guwnsxjjicomwynq0qmfksrit2be2/$all
 ||mojo-studios.co.uk$all
 ||mojorockstar.com$all
 ||mojstudent.net$all
@@ -517986,7 +518469,14 @@
 ||motzadministraties.nl$all
 ||mouas.xyz$all
 ||mouaysha.com$all
-||moufed.com$all
+||moufed.com/uu/bin_xcmcfzvl198.bin$all
+||moufed.com/wi/bin_ofekr30.bin$all
+||moufed.com/wi/bin_ygdafxi87.bin$all
+||moufed.com/wii/bin_ucpwetyk79.bin$all
+||moufed.com/wu/azor_gzufukw49.bin$all
+||moufed.com/wu/bin_ksbky53.bin$all
+||moufed.com/wu/bin_lzszqq48.bin$all
+||moufed.com/wu/bin_xiaudeklm176.bin$all
 ||moulin-de-la-hunelle.be$all
 ||mouni11.xyz$all
 ||mounicmadiraju.com$all
@@ -519358,7 +519848,7 @@
 ||mytemplate.ro$all
 ||mytempucheck.com$all
 ||mytest.alessioatzeni.com$all
-||mytestingserver.ml/wp-admin/41m/$all
+||mytestingserver.ml$all
 ||mytestwp.cf$all
 ||mytex.pe$all
 ||mythelxis.gr$all
@@ -521640,7 +522130,7 @@
 ||no1angelsescort.com$all
 ||no1spinningfields.90degrees.digital$all
 ||no1websitedesigner.com$all
-||no2politics.com/files/us_us/doc/invoice-069345/$all
+||no2politics.com$all
 ||no70.fun$all
 ||noabuseshere.top$all
 ||noach.nl$all
@@ -523153,6 +523643,7 @@
 ||ol.cognitiononline.in$all
 ||olacabattachment.com$all
 ||oladi.sulinet.hu$all
+||olafyoutrue.xyz$all
 ||olahnyomda.hu$all
 ||olairdryport.com$all
 ||olalekan419.000webhostapp.com$all
@@ -526741,7 +527232,7 @@
 ||ostappnp.myjino.ru$all
 ||ostaz.ml$all
 ||osteklenie-balkonov.tomsk.ru$all
-||ostemeda.lt/wp-content/s/$all
+||ostemeda.lt$all
 ||osteoliv.com$all
 ||osteopatasitgesblog.es$all
 ||osteopathin-husum.de$all
@@ -535247,9 +535738,7 @@
 ||physicianmedical-legalconsulting.com$all
 ||physicscafe.com.sg$all
 ||physio-bo.de$all
-||physio-svdh.ch/sitepage/wzfnncemhvoqidqzhnzkj82qdhk3jyqj39x1djl9pwrakgmuel0xtr/$all
-||physio-svdh.ch/wp-admin/kk/$all
-||physio-svdh.ch/wp-admin/reporting/kv8wbwskaa0txl3jxs/$all
+||physio-svdh.ch$all
 ||physio-veda.de$all
 ||physiodelacomba.ch/userfiles/xing.txt$all
 ||physionize.com$all
@@ -539465,7 +539954,7 @@
 ||radiolajee.com$all
 ||radioland.eu$all
 ||radiolavariada.net$all
-||radiolevi.ro/wp-content/vdbb/$all
+||radiolevi.ro$all
 ||radiomaismg.com.br$all
 ||radiomaxima.cl$all
 ||radiomega-hit.com$all
@@ -540008,6 +540497,7 @@
 ||raw.githubusercontent.com/i87924hgasdhg/hgytiryty/master/busybox$all
 ||raw.githubusercontent.com/idumkyf/za5u0i/gh-pages/h4qpxjhvr.jpeg$all
 ||raw.githubusercontent.com/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe$all
+||raw.githubusercontent.com/itroublve/token-browser-password-stealer-creator/master/avoid%20me/tokenstealer.vbs$all
 ||raw.githubusercontent.com/itroublve/token-browser-password-stealer-creator/master/avoid%20me/tokenstealer2.vbs$all
 ||raw.githubusercontent.com/jocofid282/tewsa/master/blow.exe$all
 ||raw.githubusercontent.com/jocofid282/tewsa/master/dera$all
@@ -542933,6 +543423,7 @@
 ||s-vrach.com.ua$all
 ||s-zone.uz$all
 ||s.51shijuan.com$all
+||s.lletlee.com$all
 ||s.oooooooooo.ga$all
 ||s.put.re$all
 ||s.thechinesemuslim.com$all
@@ -545364,7 +545855,7 @@
 ||seioodsoi.club$all
 ||seis.me$all
 ||seismophonic.com$all
-||seitaiken.net/wp-admin/qz9b/$all
+||seitaiken.net$all
 ||seitenstreifen.ch$all
 ||seivenco.com$all
 ||seiz-ib.de$all
@@ -562684,7 +563175,7 @@
 ||url.emailprotection.link/?bcp_lqdelwbkhxktoiznr8rouhtt9w4qlfovfoxc0z5zmn6k8ji5zi9v7qbcrvrgeprp065w1sneu27jfm6lqozrkxpwdzwxoqhcuebeujx-pj0fn_jidanzngihd_cy1/$all
 ||url.emailprotection.link/?bgmvicpuho15c9_q9hiofgnmkaco0q_lujjcaeowkfik_hdtt1uqmbkpovhxykckgjoqoytv_u0g2umkhd4mbi9ms8vo3vliq2clouuaa6no2a7ij5ljfsouoeememvmi/$all
 ||url.emailprotection.link/?bizyxbw1fdagsfcc1n6ep1awpdx9dr0brnjjqwgyaofpw98limviipvrszjnzzluclpeqqdywfxwnwudvwrljcufuhl2_nha0bs8wz9jmbahcciikbseljewayzbe_cnd/$all
-||url.sg$all
+||url.sg/rwtho$all
 ||url2.mailanyone.net/v1/?m=1hibcm-0003zv-63&i=57e1b682&c=sb1blj46bk32u6f729r5t_slvkx-heewxh20_zdn9-3ktcc0-kn35fykilpydgeyvrbwqwb5h__fk383wtdakqftjlelxz06jbaglri5jmujnydjkasqxwdtg2hn-_be1dzrnthvvhigyhm_tvbew342habp8dtit9jjlieuc2x-ipgdgipe7y_c9jhe69532gmnxozb5wifjfbstzicagmtpg6yxmreaf0sq2dgo-ksy54hetfhn6gwm4kiw2vvcqx17a9bm6ykn8bwpwdjwg/$all
 ||url3.mailanyone.net$all
 ||url5459.41southbar.com$all
diff --git a/urlhaus-filter-agh-online.txt b/urlhaus-filter-agh-online.txt
index 66cbadbe..cffbacf3 100644
--- a/urlhaus-filter-agh-online.txt
+++ b/urlhaus-filter-agh-online.txt
@@ -1,5 +1,5 @@
 ! Title: Online Malicious URL Blocklist (AdGuard Home)
-! Updated: Sat, 27 Mar 2021 12:12:22 UTC
+! Updated: Sun, 28 Mar 2021 00:12:34 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -7,19 +7,20 @@
 ||0-24bpautomentes.hu^
 ||0cl.sldov.ru^
 ||1.11.234.99^
+||1.186.151.219^
 ||1.222.140.251^
-||1.222.166.69^
 ||1.222.196.60^
 ||1.245.4.163^
 ||1.246.222.107^
 ||1.246.222.109^
 ||1.246.222.113^
 ||1.246.222.127^
-||1.246.222.134^
+||1.246.222.14^
 ||1.246.222.153^
 ||1.246.222.165^
 ||1.246.222.16^
 ||1.246.222.228^
+||1.246.222.232^
 ||1.246.222.234^
 ||1.246.222.237^
 ||1.246.222.245^
@@ -33,6 +34,7 @@
 ||1.246.222.69^
 ||1.246.222.80^
 ||1.246.222.8^
+||1.246.222.94^
 ||1.246.222.98^
 ||1.246.223.103^
 ||1.246.223.105^
@@ -47,10 +49,10 @@
 ||1.246.223.18^
 ||1.246.223.32^
 ||1.246.223.35^
-||1.246.223.48^
 ||1.246.223.49^
 ||1.246.223.4^
 ||1.246.223.54^
+||1.246.223.58^
 ||1.246.223.59^
 ||1.246.223.61^
 ||1.246.223.6^
@@ -70,7 +72,6 @@
 ||100.8.77.4^
 ||1008691.com^
 ||101.108.130.108^
-||101.109.246.33^
 ||101.16.183.179^
 ||101.16.98.170^
 ||101.229.85.127^
@@ -83,35 +84,40 @@
 ||101.30.38.204^
 ||101.64.119.250^
 ||101.64.161.70^
+||101.66.81.70^
 ||101.75.157.99^
 ||102.130.115.14^
 ||102.141.240.139^
 ||103.107.113.22^
 ||103.124.104.118^
 ||103.125.218.107^
+||103.126.35.40^
 ||103.139.89.205^
 ||103.141.138.12^
 ||103.145.13.24^
 ||103.146.174.208^
+||103.153.92.76^
 ||103.156.221.66^
 ||103.159.155.214^
 ||103.16.145.25^
 ||103.207.1.146^
+||103.214.191.141^
 ||103.217.215.21^
 ||103.224.200.40^
 ||103.238.228.3^
 ||103.238.228.4^
 ||103.240.249.121^
+||103.245.49.180^
 ||103.4.117.26^
 ||103.66.78.171^
 ||103.79.112.254^
-||103.82.145.111^
 ||103.82.98.170^
 ||103.84.240.130^
 ||103.84.240.228^
 ||103.84.241.123^
 ||103.84.241.94^
 ||103.91.245.12^
+||103.91.245.14^
 ||103.91.245.16^
 ||103.91.245.17^
 ||103.91.245.19^
@@ -123,6 +129,9 @@
 ||103.91.245.3^
 ||103.91.245.41^
 ||103.91.245.46^
+||103.91.245.49^
+||103.91.245.54^
+||103.91.245.58^
 ||103.92.25.90^
 ||103.92.25.95^
 ||104.184.75.123^
@@ -155,7 +164,6 @@
 ||109.124.90.229^
 ||109.233.196.232^
 ||109.235.7.228^
-||109.248.58.238^
 ||109.86.85.253^
 ||109.95.200.102^
 ||109.95.200.230^
@@ -181,14 +189,12 @@
 ||110.255.101.184^
 ||110.255.167.147^
 ||110.35.145.127^
-||110.35.208.21^
+||110.35.209.175^
 ||110.35.221.77^
-||110.35.223.92^
-||110.35.225.24^
-||110.35.233.147^
 ||110.35.235.57^
 ||110.35.4.2^
 ||110fss.net^
+||111.118.111.207^
 ||111.118.88.61^
 ||111.119.245.114^
 ||111.125.67.125^
@@ -228,17 +234,15 @@
 ||111.38.26.243^
 ||111.38.8.81^
 ||111.61.52.53^
-||112.105.117.227^
-||112.111.100.236^
 ||112.111.108.184^
 ||112.111.31.175^
 ||112.122.62.224^
-||112.123.200.47^
+||112.122.63.70^
 ||112.132.134.106^
 ||112.132.147.102^
 ||112.159.108.96^
+||112.167.165.139^
 ||112.170.124.75^
-||112.170.219.168^
 ||112.170.233.9^
 ||112.186.210.211^
 ||112.186.96.252^
@@ -250,10 +254,8 @@
 ||112.225.52.145^
 ||112.225.82.4^
 ||112.226.118.229^
-||112.226.176.167^
 ||112.226.195.104^
 ||112.226.202.111^
-||112.226.205.96^
 ||112.226.67.193^
 ||112.226.92.34^
 ||112.228.180.95^
@@ -263,7 +265,6 @@
 ||112.229.188.28^
 ||112.229.199.19^
 ||112.230.251.85^
-||112.234.121.107^
 ||112.234.134.244^
 ||112.234.16.252^
 ||112.234.194.178^
@@ -293,18 +294,21 @@
 ||112.242.106.228^
 ||112.242.18.128^
 ||112.242.2.247^
+||112.242.97.131^
 ||112.243.115.183^
 ||112.245.12.89^
+||112.245.178.153^
 ||112.245.5.141^
 ||112.245.8.24^
 ||112.246.162.50^
 ||112.246.180.49^
 ||112.247.100.14^
-||112.247.14.135^
+||112.247.16.222^
 ||112.247.161.45^
 ||112.247.191.118^
 ||112.247.214.146^
 ||112.247.240.226^
+||112.247.25.42^
 ||112.247.81.173^
 ||112.247.82.122^
 ||112.248.148.90^
@@ -329,6 +333,8 @@
 ||112.252.239.103^
 ||112.252.245.249^
 ||112.252.46.212^
+||112.254.128.160^
+||112.254.188.228^
 ||112.254.208.123^
 ||112.254.32.5^
 ||112.255.127.212^
@@ -344,7 +350,6 @@
 ||112.27.124.113^
 ||112.27.124.117^
 ||112.27.124.119^
-||112.27.124.120^
 ||112.27.124.122^
 ||112.27.124.124^
 ||112.27.124.127^
@@ -356,7 +361,6 @@
 ||112.27.124.136^
 ||112.27.124.138^
 ||112.27.124.139^
-||112.27.124.140^
 ||112.27.124.142^
 ||112.27.124.143^
 ||112.27.124.146^
@@ -372,6 +376,7 @@
 ||112.27.124.168^
 ||112.27.124.171^
 ||112.27.124.172^
+||112.27.124.174^
 ||112.27.124.175^
 ||112.27.124.176^
 ||112.27.124.178^
@@ -390,16 +395,19 @@
 ||112.27.88.116^
 ||112.27.91.212^
 ||112.27.91.247^
+||112.30.1.133^
 ||112.30.1.149^
 ||112.30.1.150^
 ||112.30.1.158^
-||112.30.1.159^
+||112.30.1.164^
 ||112.30.1.168^
 ||112.30.1.177^
 ||112.30.1.178^
 ||112.30.1.181^
+||112.30.1.182^
 ||112.30.1.188^
 ||112.30.1.190^
+||112.30.1.194^
 ||112.30.1.197^
 ||112.30.1.211^
 ||112.30.1.219^
@@ -414,15 +422,15 @@
 ||112.30.1.90^
 ||112.30.1.91^
 ||112.30.100.228^
-||112.30.110.27^
 ||112.30.110.30^
 ||112.30.110.31^
+||112.30.110.36^
 ||112.30.110.37^
 ||112.30.110.38^
 ||112.30.110.41^
 ||112.30.110.42^
 ||112.30.110.43^
-||112.30.110.45^
+||112.30.110.51^
 ||112.30.110.52^
 ||112.30.110.57^
 ||112.30.110.58^
@@ -438,6 +446,7 @@
 ||112.30.4.136^
 ||112.30.4.37^
 ||112.30.4.52^
+||112.30.4.53^
 ||112.30.4.57^
 ||112.30.4.61^
 ||112.30.4.70^
@@ -447,6 +456,7 @@
 ||112.31.176.16^
 ||112.31.211.135^
 ||112.31.82.160^
+||112.31.87.98^
 ||112.53.224.79^
 ||112.65.53.175^
 ||112.72.153.37^
@@ -455,6 +465,8 @@
 ||112.72.162.53^
 ||112.72.176.112^
 ||112.72.176.84^
+||112.72.226.202^
+||112.72.231.35^
 ||112.78.45.158^
 ||112.80.118.16^
 ||112.80.127.91^
@@ -473,31 +485,24 @@
 ||112.9.140.247^
 ||112.91.219.195^
 ||112.93.29.211^
-||112.95.80.165^
 ||113.0.74.25^
 ||113.11.95.254^
 ||113.110.204.254^
-||113.110.243.79^
-||113.116.150.147^
-||113.116.176.26^
-||113.116.44.33^
-||113.116.89.82^
 ||113.118.13.194^
-||113.118.133.113^
-||113.118.250.227^
-||113.118.6.104^
+||113.118.159.178^
+||113.119.37.141^
 ||113.122.238.68^
 ||113.122.59.84^
 ||113.161.58.249^
 ||113.172.250.35^
 ||113.189.243.248^
+||113.193.29.42^
 ||113.194.133.9^
 ||113.194.135.154^
 ||113.195.163.26^
 ||113.195.166.46^
 ||113.195.168.190^
 ||113.201.219.47^
-||113.225.171.27^
 ||113.226.42.250^
 ||113.227.128.9^
 ||113.227.169.170^
@@ -505,28 +510,22 @@
 ||113.227.35.229^
 ||113.231.211.131^
 ||113.231.93.142^
-||113.232.211.182^
+||113.232.156.157^
 ||113.234.224.130^
 ||113.235.116.209^
 ||113.253.144.141^
 ||113.254.169.251^
 ||113.59.128.133^
-||113.59.133.16^
-||113.59.144.42^
 ||113.59.154.21^
 ||113.59.191.47^
 ||113.61.204.205^
 ||113.86.204.13^
 ||113.87.203.239^
-||113.87.227.222^
-||113.88.100.120^
-||113.88.104.194^
-||113.88.111.36^
-||113.88.209.47^
 ||113.88.232.36^
 ||113.88.38.232^
+||113.88.39.21^
+||113.90.27.218^
 ||113.92.93.208^
-||114.199.204.37^
 ||114.199.253.235^
 ||114.224.203.128^
 ||114.226.100.56^
@@ -537,7 +536,6 @@
 ||114.229.52.14^
 ||114.234.189.154^
 ||114.235.115.236^
-||114.30.54.64^
 ||114.79.161.94^
 ||114.79.172.42^
 ||115.165.216.112^
@@ -545,45 +543,49 @@
 ||115.193.83.0^
 ||115.201.38.185^
 ||115.201.98.176^
+||115.205.197.221^
 ||115.208.97.42^
 ||115.209.234.226^
 ||115.223.159.80^
 ||115.229.250.130^
-||115.23.88.135^
 ||115.42.47.36^
 ||115.48.163.47^
 ||115.48.179.43^
 ||115.48.188.17^
-||115.48.200.115^
-||115.48.49.84^
+||115.48.201.26^
+||115.48.41.101^
 ||115.49.124.80^
 ||115.49.158.175^
+||115.49.24.63^
 ||115.49.36.220^
-||115.49.43.52^
-||115.49.80.117^
-||115.49.96.88^
-||115.50.15.24^
+||115.49.79.131^
+||115.50.1.41^
+||115.50.168.160^
+||115.50.171.192^
+||115.50.175.205^
 ||115.50.19.136^
 ||115.50.20.73^
 ||115.50.206.128^
-||115.50.226.30^
-||115.50.228.168^
+||115.50.211.74^
 ||115.50.238.227^
 ||115.50.239.77^
-||115.50.240.72^
+||115.50.242.7^
+||115.50.247.46^
 ||115.50.61.82^
+||115.50.79.78^
 ||115.50.91.30^
 ||115.50.96.254^
-||115.51.104.85^
-||115.51.106.209^
+||115.51.7.254^
 ||115.52.17.196^
+||115.52.172.72^
 ||115.53.200.130^
 ||115.53.224.134^
 ||115.53.234.210^
-||115.53.238.224^
+||115.53.58.228^
+||115.54.113.49^
 ||115.54.123.147^
-||115.54.70.108^
-||115.55.105.154^
+||115.54.158.251^
+||115.55.127.0^
 ||115.55.144.42^
 ||115.55.145.147^
 ||115.55.157.96^
@@ -591,64 +593,67 @@
 ||115.55.158.250^
 ||115.55.161.38^
 ||115.55.179.168^
+||115.55.198.105^
 ||115.55.206.35^
 ||115.55.206.78^
 ||115.55.26.94^
 ||115.55.42.200^
+||115.55.52.17^
 ||115.56.111.63^
 ||115.56.114.17^
-||115.56.132.61^
+||115.56.131.150^
 ||115.56.133.96^
 ||115.56.134.79^
+||115.56.135.255^
 ||115.56.137.48^
 ||115.56.139.122^
-||115.56.143.241^
+||115.56.142.45^
 ||115.56.145.102^
 ||115.56.148.22^
+||115.56.150.149^
 ||115.56.151.65^
 ||115.56.151.68^
 ||115.56.154.147^
-||115.56.175.2^
+||115.56.155.50^
 ||115.56.189.162^
+||115.56.31.11^
 ||115.56.31.54^
 ||115.56.98.205^
 ||115.56.99.235^
 ||115.58.132.199^
 ||115.58.134.143^
-||115.58.161.17^
+||115.58.86.217^
 ||115.58.90.143^
+||115.58.91.65^
 ||115.59.198.69^
-||115.59.209.196^
 ||115.59.212.193^
 ||115.59.214.107^
 ||115.59.228.237^
-||115.59.235.229^
 ||115.59.253.202^
 ||115.59.57.171^
 ||115.59.82.123^
-||115.61.102.110^
+||115.61.103.197^
+||115.61.112.159^
 ||115.61.118.201^
 ||115.61.118.90^
-||115.61.139.74^
-||115.62.152.207^
+||115.61.158.98^
 ||115.62.155.83^
+||115.62.171.143^
 ||115.62.26.39^
+||115.63.131.173^
 ||115.63.139.175^
 ||115.63.141.147^
 ||115.63.180.149^
 ||115.63.189.77^
 ||115.63.21.130^
-||115.63.37.6^
 ||115.63.53.188^
 ||115.73.3.11^
 ||115.75.217.79^
 ||115.78.133.146^
 ||115.92.174.231^
-||115.96.61.246^
-||115.97.136.10^
+||115.97.139.32^
 ||116.124.219.2^
 ||116.149.243.14^
-||116.2.100.221^
 ||116.206.164.46^
 ||116.207.71.237^
 ||116.211.100.26^
@@ -656,22 +661,27 @@
 ||116.212.142.215^
 ||116.30.4.2^
 ||116.30.95.156^
-||116.72.51.230^
-||116.73.222.118^
-||116.75.199.105^
-||116.75.212.119^
+||116.72.28.239^
+||116.73.52.125^
+||116.74.101.150^
+||116.74.17.122^
+||116.75.193.33^
+||116.75.198.85^
+||116.75.212.81^
 ||116.76.114.71^
+||116.9.43.220^
 ||117.11.234.35^
 ||117.12.48.157^
 ||117.156.69.22^
-||117.192.224.103^
-||117.192.225.161^
-||117.192.225.195^
-||117.192.227.137^
-||117.194.160.78^
-||117.194.163.210^
-||117.194.166.103^
-||117.194.166.20^
+||117.194.148.198^
+||117.194.160.203^
+||117.194.164.123^
+||117.194.167.131^
+||117.196.48.148^
+||117.196.48.181^
+||117.196.50.154^
+||117.196.50.239^
+||117.196.50.76^
 ||117.20.204.138^
 ||117.20.204.5^
 ||117.20.210.52^
@@ -679,43 +689,17 @@
 ||117.20.243.40^
 ||117.200.76.54^
 ||117.200.76.60^
-||117.202.67.238^
-||117.202.67.246^
-||117.202.67.4^
-||117.202.70.96^
-||117.202.71.179^
-||117.207.5.156^
-||117.208.134.226^
-||117.208.134.64^
-||117.213.11.104^
-||117.213.14.17^
-||117.213.14.30^
-||117.213.14.62^
-||117.213.15.179^
-||117.213.43.219^
-||117.213.44.116^
-||117.213.46.160^
-||117.213.47.183^
-||117.213.8.163^
-||117.215.248.14^
-||117.215.251.253^
-||117.222.160.108^
-||117.222.162.50^
-||117.222.164.19^
-||117.222.164.21^
-||117.222.169.141^
-||117.222.172.16^
-||117.222.174.16^
+||117.202.67.92^
+||117.208.132.10^
+||117.208.132.45^
+||117.213.44.102^
+||117.222.161.42^
+||117.222.164.100^
+||117.222.164.189^
+||117.222.173.218^
+||117.222.175.120^
 ||117.241.64.105^
-||117.241.67.141^
-||117.242.208.153^
-||117.242.208.95^
-||117.247.200.129^
-||117.247.202.150^
-||117.247.203.156^
-||117.247.204.118^
-||117.247.204.66^
-||117.251.60.194^
+||117.248.62.29^
 ||117.26.235.164^
 ||117.27.10.73^
 ||117.60.204.190^
@@ -727,7 +711,8 @@
 ||117.91.240.50^
 ||117.93.115.242^
 ||117.93.79.40^
-||118.172.80.79^
+||118.114.84.237^
+||118.172.176.41^
 ||118.176.104.35^
 ||118.176.157.64^
 ||118.176.7.132^
@@ -749,10 +734,8 @@
 ||118.250.51.192^
 ||118.42.125.246^
 ||118.43.180.33^
-||118.68.245.69^
 ||118.70.83.140^
 ||118.75.120.136^
-||118.75.200.198^
 ||118.75.240.136^
 ||118.75.240.239^
 ||118.75.50.253^
@@ -763,23 +746,21 @@
 ||118.79.218.157^
 ||118.79.50.203^
 ||118.79.58.82^
+||118.79.96.11^
 ||118.83.79.43^
-||118.91.24.27^
+||118.91.41.135^
 ||118.99.179.164^
 ||118.99.183.235^
 ||118.99.239.217^
 ||119.100.40.250^
 ||119.108.251.176^
-||119.109.34.245^
 ||119.112.22.58^
-||119.112.27.20^
 ||119.115.247.23^
+||119.118.150.84^
+||119.119.176.198^
 ||119.119.52.202^
-||119.123.125.139^
-||119.123.216.42^
-||119.123.218.76^
-||119.123.221.158^
-||119.123.237.218^
+||119.123.173.95^
+||119.123.175.210^
 ||119.14.143.145^
 ||119.147.213.57^
 ||119.162.109.111^
@@ -837,7 +818,6 @@
 ||119.189.227.244^
 ||119.190.211.99^
 ||119.190.234.181^
-||119.190.240.238^
 ||119.191.150.85^
 ||119.191.187.206^
 ||119.191.215.221^
@@ -849,13 +829,12 @@
 ||119.251.12.85^
 ||119.251.14.251^
 ||119.56.131.155^
+||119.56.140.73^
 ||119.56.143.46^
 ||119.56.143.71^
-||119.56.144.75^
 ||119.56.148.115^
 ||119.56.155.57^
 ||119.56.172.28^
-||119.56.195.90^
 ||119.96.37.55^
 ||119.96.70.116^
 ||119.99.188.187^
@@ -870,6 +849,7 @@
 ||12.207.39.227^
 ||120.12.153.54^
 ||120.12.212.5^
+||120.12.231.61^
 ||120.142.222.22^
 ||120.150.213.110^
 ||120.151.248.134^
@@ -892,6 +872,7 @@
 ||120.193.91.201^
 ||120.193.91.202^
 ||120.193.91.204^
+||120.193.91.205^
 ||120.193.91.207^
 ||120.193.91.208^
 ||120.193.91.212^
@@ -913,31 +894,28 @@
 ||120.5.15.95^
 ||120.50.66.60^
 ||120.50.93.115^
+||120.57.214.228^
 ||120.57.98.208^
 ||120.6.141.142^
+||120.6.241.130^
 ||120.6.8.11^
 ||120.69.131.51^
 ||120.7.75.99^
 ||120.7.90.104^
 ||120.83.189.232^
 ||120.85.165.112^
-||120.85.169.113^
-||120.85.170.109^
-||120.85.173.234^
 ||120.85.185.141^
-||120.85.236.95^
+||120.85.196.211^
+||120.85.208.107^
 ||120.85.238.10^
-||120.85.238.244^
 ||120.9.32.51^
 ||121.100.114.164^
 ||121.100.96.8^
 ||121.121.44.222^
 ||121.123.53.25^
 ||121.127.155.220^
-||121.136.249.5^
 ||121.141.11.56^
 ||121.15.142.137^
-||121.151.78.190^
 ||121.159.22.144^
 ||121.17.103.176^
 ||121.170.234.142^
@@ -955,32 +933,25 @@
 ||121.25.101.86^
 ||121.254.43.215^
 ||121.254.76.17^
-||121.61.101.93^
 ||121.61.102.1^
 ||121.61.107.189^
 ||121.61.97.195^
 ||121.61.98.151^
 ||121.88.99.236^
 ||122.100.150.204^
-||122.137.52.122^
 ||122.160.147.53^
 ||122.176.44.34^
 ||122.188.86.225^
-||122.190.19.204^
-||122.192.190.203^
 ||122.199.66.28^
 ||122.199.72.23^
 ||122.199.79.27^
 ||122.202.37.85^
 ||122.202.41.23^
 ||122.252.199.3^
-||122.252.250.22^
 ||122.254.183.207^
 ||122.254.29.37^
 ||122.254.33.214^
 ||123.0.240.58^
-||123.10.131.225^
-||123.10.41.32^
 ||123.10.83.136^
 ||123.11.11.207^
 ||123.11.4.168^
@@ -993,16 +964,19 @@
 ||123.110.19.248^
 ||123.110.200.98^
 ||123.110.238.188^
-||123.12.7.82^
+||123.12.189.247^
+||123.12.225.70^
+||123.12.235.159^
+||123.12.243.85^
 ||123.128.128.205^
 ||123.128.133.91^
 ||123.128.177.161^
 ||123.129.84.36^
 ||123.129.88.123^
-||123.13.44.60^
 ||123.130.202.8^
 ||123.130.208.52^
 ||123.130.23.110^
+||123.130.27.19^
 ||123.130.37.182^
 ||123.130.61.210^
 ||123.130.77.225^
@@ -1014,16 +988,19 @@
 ||123.133.98.135^
 ||123.134.14.130^
 ||123.134.50.186^
-||123.135.157.193^
 ||123.135.39.36^
 ||123.135.71.150^
-||123.14.172.149^
-||123.14.86.82^
+||123.14.127.238^
+||123.14.173.199^
+||123.14.249.33^
+||123.14.34.240^
+||123.14.37.32^
+||123.14.50.214^
 ||123.14.93.154^
 ||123.144.211.86^
 ||123.152.42.4^
-||123.152.43.21^
 ||123.153.80.178^
+||123.154.116.116^
 ||123.154.236.114^
 ||123.154.94.1^
 ||123.155.118.36^
@@ -1060,22 +1037,23 @@
 ||123.28.217.23^
 ||123.4.11.40^
 ||123.4.166.2^
-||123.4.176.22^
 ||123.4.177.93^
-||123.4.193.171^
+||123.4.194.152^
 ||123.4.209.154^
 ||123.4.241.118^
+||123.4.45.31^
 ||123.4.76.117^
 ||123.4.83.66^
 ||123.4.85.149^
-||123.5.123.60^
 ||123.5.143.203^
 ||123.5.146.238^
 ||123.5.190.167^
 ||123.5.5.242^
 ||123.5.8.211^
 ||123.8.56.94^
+||123.8.71.27^
 ||123.9.194.169^
+||123.9.240.115^
 ||123.9.245.207^
 ||124.105.105.222^
 ||124.129.162.169^
@@ -1087,7 +1065,9 @@
 ||124.131.130.95^
 ||124.131.131.71^
 ||124.131.136.75^
+||124.131.137.147^
 ||124.131.151.135^
+||124.131.24.185^
 ||124.131.26.243^
 ||124.131.26.78^
 ||124.131.41.48^
@@ -1111,7 +1091,6 @@
 ||124.199.56.198^
 ||124.226.24.117^
 ||124.230.174.233^
-||124.234.6.130^
 ||124.254.254.61^
 ||124.5.92.20^
 ||124.6.0.4^
@@ -1119,8 +1098,8 @@
 ||124.7.254.85^
 ||124.80.46.73^
 ||124.91.237.147^
+||124.92.135.37^
 ||124.93.94.207^
-||124.95.17.41^
 ||125.105.219.169^
 ||125.126.69.95^
 ||125.128.28.161^
@@ -1131,65 +1110,64 @@
 ||125.36.148.42^
 ||125.40.1.127^
 ||125.40.113.66^
-||125.40.160.116^
-||125.40.17.14^
-||125.40.237.130^
 ||125.40.25.140^
 ||125.40.65.120^
 ||125.40.73.6^
 ||125.40.74.153^
 ||125.40.75.22^
+||125.41.141.41^
+||125.41.164.60^
+||125.41.185.186^
+||125.41.196.114^
 ||125.41.208.139^
-||125.41.244.43^
 ||125.41.6.192^
 ||125.41.7.204^
 ||125.41.74.22^
 ||125.41.96.238^
 ||125.41.96.33^
+||125.41.97.231^
 ||125.41.97.81^
 ||125.42.107.136^
 ||125.42.124.114^
-||125.42.98.24^
-||125.42.98.35^
 ||125.43.112.123^
 ||125.43.112.182^
 ||125.43.133.130^
 ||125.43.167.192^
-||125.43.2.169^
-||125.43.21.157^
 ||125.43.215.244^
-||125.43.26.36^
 ||125.43.33.20^
-||125.43.37.138^
 ||125.43.53.50^
 ||125.43.53.9^
+||125.43.6.186^
 ||125.43.60.218^
-||125.43.73.19^
-||125.43.92.62^
+||125.43.63.47^
 ||125.44.10.125^
 ||125.44.107.182^
 ||125.44.175.118^
 ||125.44.198.62^
+||125.44.208.152^
 ||125.44.212.131^
-||125.44.243.220^
-||125.44.31.79^
+||125.44.227.51^
+||125.44.70.64^
 ||125.44.8.227^
 ||125.45.153.91^
+||125.45.43.63^
 ||125.45.55.146^
-||125.46.138.117^
+||125.46.166.112^
 ||125.46.166.125^
 ||125.46.205.88^
 ||125.46.206.160^
 ||125.46.217.52^
 ||125.46.241.237^
+||125.47.125.16^
 ||125.47.241.188^
 ||125.47.245.200^
+||125.47.248.131^
 ||125.47.250.98^
-||125.47.252.106^
-||125.47.254.154^
 ||125.47.254.44^
 ||125.47.28.18^
+||125.47.38.142^
 ||125.47.45.218^
+||125.47.47.212^
 ||125.47.57.80^
 ||125.47.91.51^
 ||125.79.192.197^
@@ -1202,12 +1180,13 @@
 ||139.159.226.180^
 ||139.170.173.198^
 ||139.170.174.162^
+||139.213.97.191^
 ||139.216.102.151^
 ||139.227.46.137^
 ||14.102.17.222^
 ||14.102.97.204^
+||14.109.126.96^
 ||14.136.80.242^
-||14.138.109.129^
 ||14.138.109.26^
 ||14.138.8.215^
 ||14.138.8.51^
@@ -1225,27 +1204,25 @@
 ||14.55.29.2^
 ||14.98.184.178^
 ||140.237.30.113^
+||140.237.30.172^
 ||140.237.5.43^
+||140.240.151.177^
 ||142.11.216.5^
 ||142.177.56.127^
 ||146.71.79.230^
 ||148.69.108.177^
 ||149.20.176.179^
-||149.255.15.112^
 ||149.255.15.134^
+||149.255.15.172^
 ||149.255.15.180^
 ||149.255.15.182^
 ||149.255.15.184^
-||149.255.15.191^
 ||149.255.15.213^
-||149.255.15.235^
-||149.255.15.27^
 ||149.255.15.43^
 ||149.255.15.87^
 ||149.255.15.99^
 ||149.3.124.194^
-||149.3.36.210^
-||149.3.85.55^
+||149.3.73.210^
 ||150.116.207.99^
 ||151.177.163.87^
 ||151.33.230.191^
@@ -1258,7 +1235,6 @@
 ||153.34.135.92^
 ||153.34.23.76^
 ||153.34.29.28^
-||153.35.111.46^
 ||153.35.27.49^
 ||153.36.126.35^
 ||158.101.165.14^
@@ -1269,27 +1245,28 @@
 ||162.191.205.175^
 ||162.194.28.60^
 ||162.209.98.174^
-||163.125.125.6^
-||163.125.157.64^
+||162.212.203.250^
 ||163.125.18.93^
 ||163.125.193.148^
-||163.125.195.248^
-||163.125.200.199^
+||163.125.200.118^
+||163.125.200.242^
 ||163.125.202.193^
-||163.125.202.195^
-||163.125.202.21^
+||163.125.202.255^
+||163.125.202.87^
 ||163.125.203.198^
+||163.125.203.236^
 ||163.125.204.156^
-||163.125.204.244^
 ||163.125.204.34^
-||163.125.207.61^
-||163.125.243.131^
+||163.125.206.16^
 ||163.125.255.165^
 ||163.204.208.169^
+||163.204.211.136^
 ||163.204.211.228^
 ||163.204.211.58^
 ||163.53.206.228^
 ||165.90.16.5^
+||168.194.146.145^
+||168.205.223.254^
 ||168.90.204.207^
 ||170.81.238.178^
 ||171.113.36.216^
@@ -1303,11 +1280,13 @@
 ||171.120.125.147^
 ||171.121.6.162^
 ||171.123.134.239^
+||171.125.122.91^
 ||171.125.242.71^
 ||171.125.30.233^
 ||171.125.30.93^
 ||171.125.64.223^
 ||171.125.65.22^
+||171.125.65.89^
 ||171.125.75.68^
 ||171.126.70.133^
 ||171.223.72.123^
@@ -1321,7 +1300,6 @@
 ||171.36.249.91^
 ||171.38.145.146^
 ||171.38.148.69^
-||171.38.217.222^
 ||171.38.219.189^
 ||171.38.223.110^
 ||171.38.223.213^
@@ -1353,12 +1331,13 @@
 ||175.145.200.216^
 ||175.146.17.227^
 ||175.150.168.92^
-||175.153.144.2^
 ||175.162.137.166^
 ||175.162.195.27^
 ||175.162.69.13^
+||175.164.61.215^
 ||175.165.90.198^
 ||175.168.139.182^
+||175.169.13.182^
 ||175.17.90.14^
 ||175.174.93.57^
 ||175.199.33.139^
@@ -1375,10 +1354,8 @@
 ||176.111.174.67^
 ||176.113.161.104^
 ||176.113.161.113^
-||176.113.161.120^
 ||176.113.161.128^
-||176.113.161.138^
-||176.113.161.59^
+||176.113.161.60^
 ||176.113.161.65^
 ||176.113.161.66^
 ||176.113.161.76^
@@ -1392,37 +1369,36 @@
 ||176.123.7.127^
 ||176.123.9.243^
 ||176.124.7.225^
+||176.221.251.238^
 ||176.240.40.142^
 ||176.240.84.106^
 ||177.11.92.78^
 ||177.131.226.235^
 ||177.229.64.218^
-||177.44.61.243^
-||177.86.235.143^
+||177.54.82.154^
 ||178.124.182.187^
-||178.141.125.98^
+||178.134.185.112^
 ||178.141.25.82^
+||178.141.44.152^
 ||178.141.45.2^
 ||178.141.57.166^
 ||178.150.174.65^
 ||178.151.143.2^
 ||178.165.122.141^
 ||178.175.0.140^
-||178.175.0.42^
-||178.175.0.47^
 ||178.175.1.139^
-||178.175.1.143^
 ||178.175.1.153^
+||178.175.1.176^
 ||178.175.1.182^
-||178.175.1.224^
 ||178.175.1.244^
-||178.175.1.247^
 ||178.175.1.249^
 ||178.175.1.250^
 ||178.175.1.252^
+||178.175.1.44^
 ||178.175.1.80^
-||178.175.1.99^
-||178.175.10.102^
+||178.175.10.104^
+||178.175.10.121^
+||178.175.10.178^
 ||178.175.10.34^
 ||178.175.10.42^
 ||178.175.10.71^
@@ -1430,118 +1406,117 @@
 ||178.175.100.110^
 ||178.175.100.129^
 ||178.175.100.180^
-||178.175.100.187^
-||178.175.100.190^
+||178.175.100.191^
 ||178.175.100.218^
 ||178.175.100.34^
 ||178.175.100.4^
-||178.175.100.87^
+||178.175.100.52^
 ||178.175.101.110^
-||178.175.101.243^
+||178.175.101.173^
+||178.175.101.191^
 ||178.175.102.134^
-||178.175.102.152^
-||178.175.102.190^
+||178.175.102.14^
 ||178.175.102.221^
-||178.175.102.228^
 ||178.175.102.245^
 ||178.175.102.35^
 ||178.175.102.53^
 ||178.175.103.172^
-||178.175.103.195^
+||178.175.103.246^
+||178.175.103.24^
 ||178.175.103.27^
 ||178.175.104.106^
 ||178.175.104.110^
 ||178.175.104.120^
 ||178.175.104.140^
+||178.175.104.151^
 ||178.175.104.155^
-||178.175.104.169^
 ||178.175.104.16^
-||178.175.104.183^
-||178.175.104.196^
+||178.175.104.199^
 ||178.175.104.206^
+||178.175.104.239^
 ||178.175.104.49^
+||178.175.105.122^
 ||178.175.105.125^
 ||178.175.105.146^
 ||178.175.105.197^
 ||178.175.105.217^
-||178.175.105.220^
+||178.175.105.240^
 ||178.175.105.245^
+||178.175.105.248^
 ||178.175.106.104^
 ||178.175.106.106^
 ||178.175.106.118^
+||178.175.106.149^
 ||178.175.106.18^
 ||178.175.106.193^
+||178.175.106.36^
 ||178.175.106.37^
 ||178.175.106.77^
+||178.175.106.83^
 ||178.175.107.0^
 ||178.175.107.133^
 ||178.175.107.149^
 ||178.175.107.240^
 ||178.175.107.245^
 ||178.175.107.83^
+||178.175.108.65^
 ||178.175.108.87^
 ||178.175.108.94^
 ||178.175.109.132^
 ||178.175.109.140^
+||178.175.109.227^
 ||178.175.109.37^
 ||178.175.109.77^
-||178.175.11.109^
+||178.175.11.155^
 ||178.175.11.165^
 ||178.175.11.176^
-||178.175.11.184^
 ||178.175.11.204^
+||178.175.11.241^
 ||178.175.11.57^
 ||178.175.11.6^
 ||178.175.110.155^
 ||178.175.110.169^
+||178.175.110.194^
 ||178.175.110.197^
 ||178.175.110.198^
 ||178.175.110.221^
-||178.175.110.250^
 ||178.175.111.105^
 ||178.175.111.159^
 ||178.175.111.187^
 ||178.175.111.190^
-||178.175.111.203^
+||178.175.111.195^
 ||178.175.111.206^
-||178.175.111.36^
 ||178.175.111.98^
 ||178.175.112.139^
 ||178.175.112.147^
 ||178.175.112.159^
 ||178.175.112.46^
 ||178.175.112.4^
-||178.175.112.59^
-||178.175.112.66^
 ||178.175.112.85^
-||178.175.113.174^
 ||178.175.114.200^
 ||178.175.114.254^
-||178.175.114.29^
-||178.175.114.51^
 ||178.175.114.55^
 ||178.175.114.63^
 ||178.175.114.90^
 ||178.175.114.99^
-||178.175.115.138^
+||178.175.115.147^
+||178.175.115.175^
 ||178.175.115.206^
 ||178.175.115.208^
+||178.175.115.88^
+||178.175.116.101^
+||178.175.116.170^
 ||178.175.116.188^
-||178.175.116.200^
 ||178.175.116.227^
 ||178.175.116.48^
 ||178.175.116.64^
-||178.175.117.209^
-||178.175.117.215^
+||178.175.117.12^
 ||178.175.117.39^
-||178.175.117.51^
 ||178.175.118.112^
 ||178.175.118.113^
-||178.175.118.165^
 ||178.175.118.192^
 ||178.175.118.198^
 ||178.175.118.47^
-||178.175.118.60^
 ||178.175.119.215^
 ||178.175.119.237^
 ||178.175.119.26^
@@ -1553,53 +1528,45 @@
 ||178.175.12.40^
 ||178.175.12.53^
 ||178.175.12.70^
+||178.175.12.93^
 ||178.175.12.97^
-||178.175.120.133^
-||178.175.120.162^
 ||178.175.120.184^
-||178.175.120.196^
 ||178.175.120.203^
 ||178.175.120.231^
 ||178.175.120.4^
+||178.175.120.5^
+||178.175.121.104^
 ||178.175.121.116^
-||178.175.121.122^
 ||178.175.121.123^
 ||178.175.121.155^
-||178.175.121.190^
+||178.175.121.192^
+||178.175.121.193^
+||178.175.121.19^
 ||178.175.121.229^
-||178.175.121.63^
-||178.175.121.83^
-||178.175.122.123^
-||178.175.122.130^
-||178.175.122.168^
+||178.175.122.199^
 ||178.175.122.201^
+||178.175.122.208^
 ||178.175.122.217^
 ||178.175.122.245^
 ||178.175.122.26^
 ||178.175.122.28^
 ||178.175.123.191^
-||178.175.123.196^
+||178.175.123.26^
 ||178.175.123.2^
 ||178.175.123.30^
-||178.175.123.40^
 ||178.175.123.56^
 ||178.175.123.7^
 ||178.175.123.90^
 ||178.175.124.109^
 ||178.175.124.122^
-||178.175.124.131^
 ||178.175.124.197^
 ||178.175.124.4^
 ||178.175.124.79^
 ||178.175.124.89^
-||178.175.124.9^
 ||178.175.125.14^
 ||178.175.125.153^
-||178.175.125.174^
-||178.175.125.227^
-||178.175.125.39^
+||178.175.125.56^
 ||178.175.126.167^
-||178.175.126.171^
 ||178.175.126.220^
 ||178.175.126.222^
 ||178.175.126.237^
@@ -1608,27 +1575,26 @@
 ||178.175.126.83^
 ||178.175.126.93^
 ||178.175.127.10^
-||178.175.127.119^
 ||178.175.127.122^
 ||178.175.127.159^
 ||178.175.127.15^
 ||178.175.127.166^
+||178.175.127.168^
 ||178.175.127.176^
+||178.175.127.219^
 ||178.175.127.230^
 ||178.175.127.231^
 ||178.175.127.236^
-||178.175.127.237^
+||178.175.127.43^
 ||178.175.127.63^
 ||178.175.127.64^
 ||178.175.127.75^
-||178.175.13.157^
+||178.175.127.97^
 ||178.175.13.19^
-||178.175.13.1^
 ||178.175.13.220^
 ||178.175.13.237^
-||178.175.13.250^
+||178.175.14.131^
 ||178.175.14.178^
-||178.175.14.185^
 ||178.175.14.230^
 ||178.175.14.60^
 ||178.175.14.69^
@@ -1636,11 +1602,9 @@
 ||178.175.15.199^
 ||178.175.15.215^
 ||178.175.15.217^
-||178.175.15.253^
 ||178.175.15.35^
 ||178.175.15.45^
 ||178.175.15.5^
-||178.175.15.85^
 ||178.175.16.108^
 ||178.175.16.114^
 ||178.175.16.123^
@@ -1648,11 +1612,11 @@
 ||178.175.16.1^
 ||178.175.16.221^
 ||178.175.16.49^
-||178.175.16.59^
 ||178.175.16.73^
 ||178.175.16.97^
+||178.175.17.118^
 ||178.175.17.245^
-||178.175.18.93^
+||178.175.17.66^
 ||178.175.19.163^
 ||178.175.19.174^
 ||178.175.19.229^
@@ -1660,6 +1624,7 @@
 ||178.175.2.108^
 ||178.175.2.110^
 ||178.175.2.123^
+||178.175.2.186^
 ||178.175.2.188^
 ||178.175.2.237^
 ||178.175.2.41^
@@ -1668,22 +1633,21 @@
 ||178.175.2.5^
 ||178.175.20.117^
 ||178.175.20.170^
-||178.175.20.225^
 ||178.175.20.237^
 ||178.175.20.24^
 ||178.175.20.70^
+||178.175.20.97^
 ||178.175.21.149^
-||178.175.21.170^
 ||178.175.21.184^
 ||178.175.21.233^
 ||178.175.21.238^
+||178.175.21.28^
 ||178.175.21.76^
 ||178.175.21.8^
 ||178.175.22.110^
 ||178.175.22.147^
 ||178.175.22.237^
 ||178.175.22.247^
-||178.175.23.102^
 ||178.175.23.156^
 ||178.175.23.228^
 ||178.175.23.250^
@@ -1693,24 +1657,22 @@
 ||178.175.24.171^
 ||178.175.24.172^
 ||178.175.24.177^
-||178.175.24.216^
+||178.175.24.198^
 ||178.175.24.218^
 ||178.175.24.238^
 ||178.175.24.243^
 ||178.175.24.77^
 ||178.175.25.113^
 ||178.175.25.117^
-||178.175.25.169^
+||178.175.25.148^
 ||178.175.25.177^
 ||178.175.25.28^
 ||178.175.25.46^
 ||178.175.25.56^
-||178.175.25.64^
 ||178.175.25.75^
 ||178.175.25.77^
 ||178.175.26.112^
 ||178.175.26.116^
-||178.175.26.164^
 ||178.175.26.165^
 ||178.175.26.209^
 ||178.175.26.215^
@@ -1719,7 +1681,7 @@
 ||178.175.26.246^
 ||178.175.26.34^
 ||178.175.27.106^
-||178.175.27.122^
+||178.175.27.137^
 ||178.175.27.138^
 ||178.175.27.14^
 ||178.175.27.167^
@@ -1727,80 +1689,89 @@
 ||178.175.27.177^
 ||178.175.27.179^
 ||178.175.27.199^
-||178.175.27.202^
 ||178.175.27.215^
 ||178.175.27.225^
 ||178.175.27.233^
 ||178.175.27.239^
+||178.175.27.244^
 ||178.175.27.32^
 ||178.175.27.37^
 ||178.175.27.46^
 ||178.175.27.48^
-||178.175.27.68^
 ||178.175.27.69^
 ||178.175.28.102^
 ||178.175.28.199^
+||178.175.28.200^
+||178.175.28.51^
+||178.175.28.69^
 ||178.175.29.16^
 ||178.175.29.173^
 ||178.175.29.174^
 ||178.175.29.201^
 ||178.175.29.207^
+||178.175.29.208^
 ||178.175.29.220^
 ||178.175.29.2^
+||178.175.29.7^
 ||178.175.3.116^
-||178.175.3.130^
 ||178.175.3.166^
 ||178.175.3.172^
 ||178.175.3.190^
 ||178.175.3.196^
 ||178.175.3.214^
+||178.175.3.66^
+||178.175.3.87^
 ||178.175.30.0^
 ||178.175.30.135^
 ||178.175.30.213^
-||178.175.30.252^
 ||178.175.30.70^
 ||178.175.30.93^
 ||178.175.30.96^
 ||178.175.31.171^
 ||178.175.31.251^
+||178.175.31.252^
 ||178.175.31.6^
+||178.175.31.99^
+||178.175.32.14^
 ||178.175.32.197^
 ||178.175.32.198^
 ||178.175.32.20^
 ||178.175.32.211^
 ||178.175.32.229^
 ||178.175.32.243^
+||178.175.32.244^
 ||178.175.32.2^
 ||178.175.32.89^
-||178.175.32.95^
 ||178.175.33.112^
 ||178.175.33.141^
 ||178.175.33.162^
 ||178.175.33.173^
 ||178.175.33.181^
+||178.175.33.196^
 ||178.175.33.208^
 ||178.175.33.215^
+||178.175.33.21^
 ||178.175.33.228^
 ||178.175.33.234^
+||178.175.33.245^
 ||178.175.33.26^
-||178.175.33.28^
-||178.175.33.2^
-||178.175.33.63^
 ||178.175.34.1^
 ||178.175.34.200^
-||178.175.34.243^
 ||178.175.34.2^
-||178.175.35.144^
+||178.175.34.53^
 ||178.175.35.21^
 ||178.175.35.38^
 ||178.175.35.83^
+||178.175.35.91^
 ||178.175.36.0^
 ||178.175.36.127^
 ||178.175.36.129^
+||178.175.36.184^
 ||178.175.36.218^
 ||178.175.36.231^
 ||178.175.36.245^
 ||178.175.36.33^
+||178.175.36.5^
 ||178.175.37.107^
 ||178.175.37.135^
 ||178.175.37.153^
@@ -1809,25 +1780,26 @@
 ||178.175.37.38^
 ||178.175.37.56^
 ||178.175.37.6^
+||178.175.37.71^
 ||178.175.37.81^
 ||178.175.37.83^
 ||178.175.38.132^
-||178.175.38.141^
 ||178.175.38.165^
-||178.175.38.191^
 ||178.175.38.1^
-||178.175.38.28^
 ||178.175.38.98^
+||178.175.39.110^
+||178.175.39.129^
 ||178.175.39.158^
 ||178.175.39.245^
 ||178.175.39.57^
+||178.175.39.63^
 ||178.175.4.144^
+||178.175.4.192^
 ||178.175.4.219^
-||178.175.4.222^
 ||178.175.4.231^
+||178.175.4.233^
 ||178.175.4.95^
 ||178.175.40.155^
-||178.175.40.166^
 ||178.175.40.226^
 ||178.175.40.228^
 ||178.175.40.41^
@@ -1837,12 +1809,14 @@
 ||178.175.41.203^
 ||178.175.41.34^
 ||178.175.42.171^
+||178.175.42.228^
+||178.175.42.240^
+||178.175.42.25^
 ||178.175.43.106^
 ||178.175.43.121^
 ||178.175.43.138^
 ||178.175.43.147^
 ||178.175.43.1^
-||178.175.43.217^
 ||178.175.43.30^
 ||178.175.43.33^
 ||178.175.43.69^
@@ -1850,7 +1824,6 @@
 ||178.175.44.134^
 ||178.175.44.143^
 ||178.175.44.155^
-||178.175.44.186^
 ||178.175.44.197^
 ||178.175.44.217^
 ||178.175.44.22^
@@ -1859,11 +1832,9 @@
 ||178.175.44.89^
 ||178.175.44.90^
 ||178.175.44.95^
-||178.175.44.96^
-||178.175.45.191^
 ||178.175.45.205^
+||178.175.45.25^
 ||178.175.45.6^
-||178.175.45.87^
 ||178.175.46.119^
 ||178.175.46.187^
 ||178.175.46.224^
@@ -1872,27 +1843,33 @@
 ||178.175.47.141^
 ||178.175.47.151^
 ||178.175.47.168^
+||178.175.47.16^
 ||178.175.47.245^
 ||178.175.48.110^
 ||178.175.48.168^
 ||178.175.49.139^
+||178.175.49.214^
 ||178.175.49.247^
+||178.175.49.252^
 ||178.175.49.3^
 ||178.175.5.17^
 ||178.175.5.51^
+||178.175.5.79^
 ||178.175.50.131^
+||178.175.50.168^
 ||178.175.50.177^
 ||178.175.50.22^
 ||178.175.50.236^
 ||178.175.50.237^
-||178.175.50.27^
+||178.175.50.32^
 ||178.175.51.137^
 ||178.175.51.160^
 ||178.175.51.202^
 ||178.175.51.66^
+||178.175.52.146^
 ||178.175.52.161^
 ||178.175.52.212^
-||178.175.52.71^
+||178.175.52.21^
 ||178.175.52.94^
 ||178.175.53.135^
 ||178.175.53.151^
@@ -1904,15 +1881,15 @@
 ||178.175.53.5^
 ||178.175.53.79^
 ||178.175.54.158^
+||178.175.54.15^
 ||178.175.54.163^
+||178.175.54.167^
 ||178.175.54.205^
-||178.175.54.214^
 ||178.175.54.225^
 ||178.175.54.64^
 ||178.175.55.103^
 ||178.175.55.14^
 ||178.175.55.163^
-||178.175.55.181^
 ||178.175.55.25^
 ||178.175.55.29^
 ||178.175.55.38^
@@ -1922,122 +1899,114 @@
 ||178.175.56.103^
 ||178.175.56.11^
 ||178.175.56.120^
-||178.175.56.18^
-||178.175.56.196^
 ||178.175.56.24^
 ||178.175.56.252^
 ||178.175.56.33^
 ||178.175.56.37^
 ||178.175.56.50^
+||178.175.56.52^
 ||178.175.56.54^
 ||178.175.56.72^
 ||178.175.56.75^
 ||178.175.57.10^
 ||178.175.57.141^
 ||178.175.57.179^
+||178.175.57.99^
 ||178.175.58.28^
-||178.175.58.29^
 ||178.175.58.74^
 ||178.175.58.79^
 ||178.175.59.161^
+||178.175.59.241^
 ||178.175.59.33^
-||178.175.59.47^
 ||178.175.59.54^
 ||178.175.6.134^
 ||178.175.6.157^
 ||178.175.6.189^
+||178.175.6.89^
 ||178.175.60.209^
 ||178.175.60.212^
-||178.175.60.251^
+||178.175.60.76^
 ||178.175.61.156^
 ||178.175.61.163^
 ||178.175.61.171^
+||178.175.61.178^
 ||178.175.61.17^
 ||178.175.61.219^
 ||178.175.61.237^
+||178.175.61.95^
 ||178.175.62.111^
 ||178.175.62.115^
+||178.175.62.141^
 ||178.175.62.166^
 ||178.175.62.168^
-||178.175.62.208^
 ||178.175.62.42^
 ||178.175.62.43^
 ||178.175.62.70^
 ||178.175.62.84^
 ||178.175.62.8^
-||178.175.63.167^
+||178.175.63.192^
 ||178.175.63.21^
-||178.175.63.73^
+||178.175.63.230^
+||178.175.63.78^
 ||178.175.63.96^
 ||178.175.64.12^
+||178.175.64.155^
 ||178.175.64.156^
 ||178.175.64.158^
 ||178.175.64.187^
+||178.175.64.190^
 ||178.175.64.22^
-||178.175.64.30^
-||178.175.64.50^
-||178.175.65.115^
+||178.175.64.231^
+||178.175.65.19^
 ||178.175.65.202^
 ||178.175.65.236^
-||178.175.66.105^
-||178.175.66.123^
 ||178.175.66.186^
 ||178.175.66.192^
 ||178.175.66.199^
 ||178.175.66.211^
 ||178.175.66.228^
-||178.175.66.43^
 ||178.175.66.54^
 ||178.175.66.93^
 ||178.175.67.0^
 ||178.175.67.36^
 ||178.175.67.51^
+||178.175.67.55^
 ||178.175.67.81^
 ||178.175.67.83^
 ||178.175.67.89^
-||178.175.67.8^
-||178.175.68.109^
+||178.175.68.116^
 ||178.175.68.44^
 ||178.175.68.66^
 ||178.175.68.85^
 ||178.175.69.111^
-||178.175.69.112^
 ||178.175.69.119^
 ||178.175.69.128^
 ||178.175.69.18^
-||178.175.69.4^
-||178.175.69.96^
 ||178.175.7.60^
 ||178.175.7.6^
 ||178.175.7.71^
 ||178.175.70.109^
-||178.175.70.12^
-||178.175.70.147^
-||178.175.70.18^
+||178.175.70.10^
 ||178.175.70.196^
 ||178.175.70.218^
 ||178.175.70.246^
-||178.175.70.38^
 ||178.175.70.50^
 ||178.175.70.5^
-||178.175.70.64^
 ||178.175.70.71^
 ||178.175.70.83^
-||178.175.71.202^
+||178.175.70.93^
+||178.175.71.160^
 ||178.175.71.45^
-||178.175.71.55^
 ||178.175.71.84^
 ||178.175.72.108^
-||178.175.72.13^
 ||178.175.72.222^
 ||178.175.72.30^
 ||178.175.72.37^
-||178.175.73.127^
-||178.175.73.77^
+||178.175.72.47^
 ||178.175.73.96^
 ||178.175.74.182^
+||178.175.74.205^
 ||178.175.74.48^
-||178.175.75.130^
 ||178.175.75.181^
 ||178.175.75.19^
 ||178.175.75.84^
@@ -2049,97 +2018,101 @@
 ||178.175.76.21^
 ||178.175.76.83^
 ||178.175.76.9^
+||178.175.77.248^
+||178.175.77.34^
 ||178.175.77.46^
 ||178.175.77.47^
-||178.175.77.71^
-||178.175.78.118^
 ||178.175.78.198^
 ||178.175.78.243^
-||178.175.78.46^
+||178.175.78.57^
 ||178.175.78.97^
 ||178.175.79.17^
 ||178.175.79.244^
 ||178.175.79.247^
 ||178.175.79.69^
 ||178.175.8.100^
+||178.175.8.227^
+||178.175.8.64^
 ||178.175.80.100^
-||178.175.80.114^
 ||178.175.80.129^
-||178.175.80.17^
+||178.175.80.197^
 ||178.175.80.20^
-||178.175.80.35^
 ||178.175.80.41^
 ||178.175.80.61^
+||178.175.80.68^
 ||178.175.80.79^
 ||178.175.80.86^
-||178.175.81.17^
+||178.175.80.89^
 ||178.175.81.192^
+||178.175.81.19^
 ||178.175.81.226^
 ||178.175.81.232^
 ||178.175.81.244^
 ||178.175.81.253^
-||178.175.81.50^
-||178.175.82.137^
-||178.175.82.32^
+||178.175.82.23^
+||178.175.82.73^
+||178.175.83.144^
+||178.175.83.20^
 ||178.175.83.247^
 ||178.175.83.2^
 ||178.175.84.102^
-||178.175.84.109^
 ||178.175.84.159^
+||178.175.84.17^
 ||178.175.84.215^
+||178.175.84.28^
 ||178.175.84.42^
 ||178.175.85.153^
 ||178.175.85.183^
+||178.175.85.230^
 ||178.175.85.23^
-||178.175.85.55^
 ||178.175.85.57^
 ||178.175.86.119^
+||178.175.86.122^
 ||178.175.86.36^
 ||178.175.86.59^
 ||178.175.87.126^
 ||178.175.87.139^
 ||178.175.87.144^
 ||178.175.87.253^
-||178.175.87.68^
-||178.175.88.127^
-||178.175.88.140^
+||178.175.88.160^
 ||178.175.88.166^
 ||178.175.88.181^
 ||178.175.88.182^
+||178.175.88.248^
+||178.175.88.24^
 ||178.175.88.69^
 ||178.175.89.157^
 ||178.175.89.169^
-||178.175.89.24^
+||178.175.89.30^
 ||178.175.9.125^
 ||178.175.9.139^
 ||178.175.9.175^
 ||178.175.9.179^
-||178.175.9.183^
 ||178.175.9.198^
 ||178.175.9.210^
 ||178.175.9.215^
 ||178.175.9.225^
+||178.175.9.64^
 ||178.175.9.84^
 ||178.175.9.95^
 ||178.175.90.122^
 ||178.175.90.167^
 ||178.175.90.172^
-||178.175.90.212^
+||178.175.90.185^
 ||178.175.90.21^
-||178.175.90.244^
 ||178.175.90.4^
 ||178.175.90.74^
+||178.175.90.81^
+||178.175.90.90^
 ||178.175.91.108^
 ||178.175.91.13^
 ||178.175.91.15^
 ||178.175.91.244^
 ||178.175.91.253^
-||178.175.91.40^
 ||178.175.91.96^
-||178.175.92.128^
 ||178.175.92.132^
-||178.175.92.141^
 ||178.175.92.186^
+||178.175.92.200^
 ||178.175.92.215^
 ||178.175.92.231^
 ||178.175.92.253^
@@ -2148,37 +2121,32 @@
 ||178.175.93.143^
 ||178.175.93.150^
 ||178.175.93.159^
-||178.175.93.34^
-||178.175.93.45^
+||178.175.93.199^
+||178.175.93.44^
 ||178.175.93.62^
-||178.175.93.93^
 ||178.175.94.195^
 ||178.175.94.200^
+||178.175.94.27^
 ||178.175.94.40^
 ||178.175.94.55^
+||178.175.95.116^
 ||178.175.95.141^
+||178.175.95.163^
 ||178.175.95.17^
 ||178.175.95.227^
-||178.175.95.237^
 ||178.175.95.4^
 ||178.175.95.56^
-||178.175.96.169^
-||178.175.96.192^
+||178.175.96.81^
 ||178.175.97.128^
 ||178.175.97.135^
-||178.175.97.143^
-||178.175.97.1^
-||178.175.97.78^
+||178.175.98.216^
 ||178.175.98.228^
 ||178.175.98.254^
 ||178.175.98.29^
-||178.175.98.36^
+||178.175.98.44^
 ||178.175.98.68^
 ||178.175.99.123^
 ||178.175.99.130^
-||178.175.99.22^
-||178.175.99.45^
-||178.175.99.88^
 ||178.175.99.91^
 ||178.19.183.14^
 ||178.205.101.33^
@@ -2193,6 +2161,7 @@
 ||178.95.136.35^
 ||179.159.58.134^
 ||179.4.187.39^
+||179.42.107.139^
 ||179.43.157.173^
 ||179.60.84.7^
 ||179.99.210.161^
@@ -2205,7 +2174,6 @@
 ||180.125.44.194^
 ||180.157.66.204^
 ||180.175.236.209^
-||180.175.93.52^
 ||180.176.105.41^
 ||180.176.110.243^
 ||180.176.165.230^
@@ -2216,6 +2184,7 @@
 ||180.177.242.73^
 ||180.218.5.171^
 ||180.248.80.38^
+||180.253.99.109^
 ||180.66.111.36^
 ||180.66.53.93^
 ||180.94.170.166^
@@ -2226,123 +2195,131 @@
 ||181.193.107.10^
 ||181.199.170.222^
 ||181.199.170.230^
-||181.199.170.240^
 ||181.210.45.42^
 ||181.215.47.82^
 ||181.224.242.131^
 ||181.49.236.4^
 ||181.49.59.162^
+||182.112.28.118^
+||182.112.34.220^
 ||182.112.43.249^
 ||182.112.52.131^
+||182.113.238.197^
+||182.113.29.28^
+||182.114.105.40^
 ||182.114.111.64^
-||182.114.24.20^
-||182.114.49.104^
 ||182.114.64.27^
+||182.114.76.42^
 ||182.114.79.103^
 ||182.114.83.88^
 ||182.114.92.90^
 ||182.114.93.96^
-||182.116.101.82^
-||182.116.103.234^
 ||182.116.104.106^
-||182.116.108.180^
+||182.116.105.208^
 ||182.116.108.244^
+||182.116.116.70^
 ||182.116.118.250^
+||182.116.119.66^
+||182.116.36.175^
 ||182.116.60.73^
 ||182.116.61.252^
 ||182.116.80.107^
 ||182.116.94.196^
 ||182.116.99.150^
+||182.117.13.57^
 ||182.117.15.172^
 ||182.117.25.120^
 ||182.117.26.235^
 ||182.117.29.220^
 ||182.117.39.51^
 ||182.117.43.27^
+||182.117.49.127^
 ||182.118.146.181^
+||182.118.166.128^
 ||182.119.100.135^
 ||182.119.109.173^
 ||182.119.118.218^
 ||182.119.14.252^
+||182.119.15.78^
 ||182.119.166.208^
-||182.119.176.209^
+||182.119.166.76^
+||182.119.179.193^
+||182.119.197.123^
+||182.119.202.180^
+||182.119.21.68^
 ||182.119.211.69^
 ||182.119.214.120^
 ||182.119.221.141^
-||182.119.225.30^
+||182.119.226.84^
 ||182.119.255.115^
 ||182.119.7.54^
+||182.119.89.107^
 ||182.120.16.22^
 ||182.120.16.46^
-||182.120.33.117^
 ||182.120.37.251^
 ||182.120.43.0^
-||182.121.11.43^
 ||182.121.129.163^
-||182.121.130.67^
-||182.121.133.46^
 ||182.121.134.70^
-||182.121.158.141^
+||182.121.15.223^
+||182.121.157.35^
 ||182.121.205.201^
 ||182.121.205.237^
 ||182.121.207.195^
-||182.121.40.234^
-||182.121.50.111^
+||182.121.254.147^
+||182.121.55.106^
 ||182.121.66.189^
 ||182.121.9.117^
 ||182.121.94.13^
-||182.122.181.105^
 ||182.122.202.18^
 ||182.123.203.21^
 ||182.123.211.239^
+||182.123.241.195^
 ||182.124.123.107^
 ||182.124.177.48^
 ||182.124.19.87^
+||182.124.201.207^
 ||182.124.88.122^
 ||182.126.113.127^
-||182.126.120.66^
+||182.126.123.19^
 ||182.126.126.203^
 ||182.126.127.254^
-||182.126.181.121^
-||182.126.52.233^
 ||182.126.67.24^
-||182.126.80.108^
 ||182.126.83.79^
 ||182.126.88.138^
+||182.127.0.16^
 ||182.127.103.79^
 ||182.127.104.235^
-||182.127.110.147^
+||182.127.106.43^
 ||182.127.152.3^
 ||182.127.155.157^
-||182.127.209.26^
 ||182.127.221.243^
+||182.127.93.38^
 ||182.160.98.250^
 ||182.172.36.164^
 ||182.233.0.252^
 ||182.235.252.31^
 ||182.53.197.62^
-||182.58.219.8^
+||182.56.193.251^
+||182.59.235.150^
 ||183.105.104.83^
 ||183.105.225.154^
 ||183.109.169.45^
 ||183.11.238.228^
 ||183.136.252.233^
-||183.150.138.131^
 ||183.150.244.122^
 ||183.16.208.30^
 ||183.185.112.19^
+||183.185.162.225^
 ||183.187.163.176^
 ||183.188.151.225^
 ||183.188.180.116^
 ||183.188.188.186^
 ||183.188.228.38^
+||183.188.93.116^
 ||183.83.105.21^
-||183.83.125.235^
 ||183.83.127.89^
 ||183.83.26.115^
-||183.83.99.87^
 ||183.92.195.140^
-||183.95.147.102^
 ||183.97.22.14^
 ||184.164.185.41^
 ||184.175.115.10^
@@ -2384,14 +2361,11 @@
 ||186.225.120.173^
 ||186.232.44.86^
 ||186.28.60.184^
-||186.33.112.218^
-||186.33.112.228^
-||186.33.112.66^
-||186.33.113.241^
 ||186.33.113.77^
 ||186.4.125.48^
 ||186.73.188.132^
 ||187.12.10.98^
+||187.188.124.229^
 ||187.212.200.162^
 ||187.233.208.103^
 ||187.33.71.68^
@@ -2399,12 +2373,12 @@
 ||188.10.231.246^
 ||188.113.102.18^
 ||188.113.81.17^
+||188.119.45.194^
 ||188.13.179.87^
 ||188.138.200.32^
 ||188.152.41.141^
 ||188.169.178.50^
-||188.169.199.59^
-||188.169.36.163^
+||188.169.179.151^
 ||188.169.45.140^
 ||188.242.167.159^
 ||188.242.242.144^
@@ -2438,6 +2412,7 @@
 ||190.216.140.123^
 ||190.35.225.36^
 ||190.65.206.162^
+||190.73.12.149^
 ||190.92.4.231^
 ||190.98.37.135^
 ||190.98.37.200^
@@ -2445,7 +2420,6 @@
 ||191.255.248.220^
 ||192.210.175.130^
 ||192.210.241.200^
-||192.227.185.106^
 ||192.227.209.27^
 ||192.227.220.55^
 ||192.227.228.67^
@@ -2454,6 +2428,7 @@
 ||192.99.240.77^
 ||193.142.146.25^
 ||193.228.135.144^
+||193.38.55.9^
 ||193.91.131.237^
 ||194.147.142.230^
 ||194.15.36.167^
@@ -2470,7 +2445,6 @@
 ||197.50.27.115^
 ||198.23.133.218^
 ||198.23.207.121^
-||198.23.213.57^
 ||198.23.251.105^
 ||198.251.72.110^
 ||198.46.201.76^
@@ -2482,7 +2456,9 @@
 ||2.45.111.158^
 ||2.45.4.24^
 ||2.55.125.182^
+||2.58.69.44^
 ||2.83.152.16^
+||20.185.42.197^
 ||20.dbstrony.pl^
 ||200.105.167.98^
 ||200.111.189.70^
@@ -2495,17 +2471,16 @@
 ||201.187.102.73^
 ||201.200.254.86^
 ||201.203.221.20^
+||201.203.27.37^
 ||201.215.84.97^
 ||201.218.97.142^
 ||202.107.233.41^
+||202.150.176.100^
 ||202.164.153.80^
 ||202.166.217.54^
 ||202.169.234.22^
 ||202.169.234.37^
-||202.169.234.47^
 ||202.169.234.52^
-||202.169.234.55^
-||202.169.234.9^
 ||202.29.95.12^
 ||202.4.124.58^
 ||202.51.176.114^
@@ -2513,12 +2488,10 @@
 ||202.74.236.9^
 ||203.109.201.243^
 ||203.130.69.205^
-||203.170.115.82^
 ||203.189.156.107^
 ||203.204.232.18^
 ||203.229.21.56^
 ||203.236.190.28^
-||203.238.86.202^
 ||203.70.166.107^
 ||203.77.80.159^
 ||203.80.119.166^
@@ -2528,7 +2501,6 @@
 ||203.93.6.28^
 ||204.195.116.171^
 ||205.185.115.74^
-||205.185.123.217^
 ||206.248.137.132^
 ||206.47.41.166^
 ||207.5.32.6^
@@ -2540,6 +2512,7 @@
 ||210.124.149.19^
 ||210.216.152.122^
 ||210.216.153.142^
+||210.57.234.131^
 ||210.57.234.93^
 ||210.57.237.70^
 ||210.57.245.109^
@@ -2561,6 +2534,7 @@
 ||211.247.113.49^
 ||211.247.5.96^
 ||211.36.174.137^
+||211.47.102.51^
 ||211.51.174.149^
 ||212.122.86.105^
 ||212.143.227.22^
@@ -2575,12 +2549,12 @@
 ||213.149.190.193^
 ||213.163.104.12^
 ||213.163.104.138^
-||213.163.104.160^
+||213.163.104.7^
 ||213.163.104.99^
+||213.163.113.100^
 ||213.163.113.135^
 ||213.163.113.225^
 ||213.163.113.237^
-||213.163.113.23^
 ||213.163.113.51^
 ||213.163.114.155^
 ||213.163.114.191^
@@ -2591,7 +2565,9 @@
 ||213.163.115.33^
 ||213.163.115.71^
 ||213.163.116.132^
+||213.163.116.181^
 ||213.163.116.192^
+||213.163.116.197^
 ||213.163.116.203^
 ||213.163.116.33^
 ||213.163.116.85^
@@ -2600,21 +2576,21 @@
 ||213.163.117.97^
 ||213.163.118.129^
 ||213.163.118.144^
+||213.163.118.236^
 ||213.163.118.238^
-||213.163.118.65^
 ||213.163.119.240^
 ||213.163.119.24^
-||213.163.126.104^
 ||213.163.126.20^
 ||213.163.126.243^
+||213.163.126.249^
 ||213.163.126.60^
 ||213.163.126.7^
 ||213.163.126.84^
 ||213.163.127.204^
 ||213.163.127.217^
+||213.163.127.242^
 ||213.163.127.46^
 ||213.189.178.163^
-||213.226.140.23^
 ||213.240.218.15^
 ||213.249.156.189^
 ||213.27.8.6^
@@ -2642,6 +2618,7 @@
 ||218.35.81.81^
 ||218.48.135.50^
 ||218.56.93.129^
+||218.57.109.48^
 ||218.57.53.55^
 ||218.59.116.203^
 ||218.72.198.15^
@@ -2649,33 +2626,37 @@
 ||218.93.102.63^
 ||218.93.102.75^
 ||219.154.103.40^
-||219.154.114.132^
 ||219.154.114.45^
 ||219.154.115.250^
+||219.154.116.168^
 ||219.154.126.205^
+||219.154.142.35^
+||219.154.143.132^
 ||219.154.147.58^
 ||219.154.148.116^
 ||219.154.173.163^
+||219.154.178.138^
+||219.154.41.36^
 ||219.155.102.14^
+||219.155.11.252^
 ||219.155.113.58^
 ||219.155.14.17^
-||219.155.170.22^
+||219.155.209.253^
 ||219.155.24.246^
 ||219.155.243.184^
 ||219.155.26.204^
-||219.155.26.37^
 ||219.155.29.165^
 ||219.155.31.15^
 ||219.155.31.67^
-||219.155.42.216^
+||219.155.86.156^
 ||219.155.98.64^
 ||219.156.131.116^
-||219.156.167.103^
 ||219.156.17.217^
+||219.156.176.153^
 ||219.156.23.29^
 ||219.156.60.224^
+||219.156.65.47^
 ||219.156.88.219^
-||219.156.9.32^
 ||219.157.11.39^
 ||219.157.146.200^
 ||219.157.147.87^
@@ -2683,8 +2664,8 @@
 ||219.157.178.201^
 ||219.157.178.210^
 ||219.157.183.29^
+||219.157.214.235^
 ||219.157.223.241^
-||219.157.223.245^
 ||219.157.42.228^
 ||219.157.67.171^
 ||219.241.6.180^
@@ -2692,6 +2673,7 @@
 ||219.68.1.84^
 ||219.68.163.7^
 ||219.68.171.144^
+||219.68.245.63^
 ||219.68.251.32^
 ||219.68.5.140^
 ||219.69.71.186^
@@ -2703,21 +2685,21 @@
 ||220.133.30.200^
 ||220.200.22.163^
 ||220.71.239.115^
+||220.90.159.188^
 ||221.1.162.82^
 ||221.124.78.15^
-||221.14.11.33^
 ||221.14.122.127^
 ||221.14.165.237^
+||221.14.185.105^
 ||221.14.47.162^
-||221.14.58.5^
+||221.14.47.189^
+||221.14.57.175^
 ||221.15.108.55^
+||221.15.112.103^
 ||221.15.125.190^
-||221.15.127.124^
-||221.15.147.220^
-||221.15.21.133^
-||221.15.212.123^
+||221.15.155.186^
+||221.15.190.2^
 ||221.15.234.159^
-||221.15.236.211^
 ||221.15.237.107^
 ||221.15.250.213^
 ||221.15.253.236^
@@ -2731,8 +2713,10 @@
 ||221.196.12.96^
 ||221.198.167.192^
 ||221.2.190.22^
+||221.202.232.230^
 ||221.214.130.147^
 ||221.214.224.184^
+||221.214.251.109^
 ||221.215.116.167^
 ||221.215.172.207^
 ||221.215.184.31^
@@ -2757,52 +2741,50 @@
 ||222.135.219.29^
 ||222.135.26.161^
 ||222.135.67.115^
-||222.136.49.252^
 ||222.136.53.227^
+||222.136.77.190^
 ||222.137.101.251^
 ||222.137.101.33^
 ||222.137.121.127^
 ||222.137.137.5^
 ||222.137.138.252^
 ||222.137.148.192^
-||222.137.160.202^
+||222.137.161.88^
 ||222.137.172.250^
 ||222.137.198.247^
+||222.137.220.215^
+||222.137.237.203^
 ||222.137.239.124^
 ||222.137.49.36^
-||222.137.5.150^
-||222.137.57.234^
+||222.137.53.193^
 ||222.137.72.146^
-||222.137.85.26^
 ||222.137.96.9^
+||222.138.118.192^
 ||222.138.143.84^
 ||222.138.151.100^
 ||222.138.189.138^
 ||222.138.201.241^
-||222.138.23.254^
+||222.138.213.235^
+||222.138.226.142^
 ||222.138.96.79^
-||222.139.16.229^
-||222.140.129.239^
+||222.139.106.55^
 ||222.140.162.140^
 ||222.140.163.112^
 ||222.140.17.245^
+||222.140.179.142^
+||222.140.208.18^
 ||222.140.209.222^
-||222.140.254.11^
 ||222.140.39.66^
+||222.141.101.39^
 ||222.141.120.26^
 ||222.141.13.77^
-||222.141.44.36^
-||222.141.73.249^
+||222.141.40.69^
+||222.141.46.119^
 ||222.141.9.0^
-||222.142.162.164^
 ||222.142.192.66^
 ||222.142.209.231^
-||222.142.209.7^
-||222.142.245.207^
 ||222.179.215.189^
 ||222.185.116.233^
-||222.186.20.19^
-||222.187.184.136^
 ||222.187.9.178^
 ||222.211.72.66^
 ||222.214.54.208^
@@ -2811,7 +2793,7 @@
 ||222.238.230.7^
 ||222.239.83.232^
 ||222.248.64.253^
-||222.83.150.240^
+||222.81.156.229^
 ||222.92.9.126^
 ||222.99.171.192^
 ||223.166.117.210^
@@ -2856,7 +2838,7 @@
 ||27.141.218.17^
 ||27.147.29.52^
 ||27.147.40.128^
-||27.153.207.1^
+||27.153.142.115^
 ||27.184.244.14^
 ||27.184.54.199^
 ||27.187.248.22^
@@ -2864,7 +2846,6 @@
 ||27.193.196.190^
 ||27.193.217.210^
 ||27.194.149.142^
-||27.194.158.229^
 ||27.194.192.66^
 ||27.194.210.20^
 ||27.197.17.88^
@@ -2890,13 +2871,11 @@
 ||27.203.165.138^
 ||27.203.175.203^
 ||27.203.185.42^
-||27.203.185.48^
 ||27.203.213.79^
 ||27.203.246.96^
 ||27.203.255.42^
 ||27.203.28.115^
 ||27.203.4.188^
-||27.203.54.217^
 ||27.203.68.144^
 ||27.203.87.75^
 ||27.203.94.134^
@@ -2920,11 +2899,10 @@
 ||27.208.164.18^
 ||27.208.166.13^
 ||27.208.201.212^
-||27.208.214.139^
 ||27.208.247.130^
 ||27.208.25.59^
 ||27.208.34.2^
-||27.208.46.167^
+||27.208.70.115^
 ||27.208.92.64^
 ||27.209.160.222^
 ||27.209.231.15^
@@ -2940,6 +2918,7 @@
 ||27.213.109.105^
 ||27.213.109.58^
 ||27.213.145.221^
+||27.213.166.50^
 ||27.213.167.175^
 ||27.213.175.208^
 ||27.213.220.5^
@@ -2952,6 +2931,7 @@
 ||27.215.212.209^
 ||27.215.212.80^
 ||27.215.253.149^
+||27.215.27.143^
 ||27.215.34.242^
 ||27.215.38.119^
 ||27.215.38.166^
@@ -2966,7 +2946,6 @@
 ||27.216.227.95^
 ||27.216.234.98^
 ||27.216.46.85^
-||27.216.58.120^
 ||27.216.95.56^
 ||27.217.120.226^
 ||27.217.133.53^
@@ -3001,23 +2980,30 @@
 ||27.35.154.13^
 ||27.35.212.124^
 ||27.35.58.5^
-||27.41.143.46^
+||27.41.159.28^
+||27.41.37.155^
+||27.41.9.105^
 ||27.41.9.44^
+||27.41.97.36^
+||27.43.108.78^
+||27.43.111.161^
+||27.43.117.66^
+||27.46.23.10^
 ||27.46.44.130^
-||27.46.44.161^
+||27.46.44.153^
+||27.46.45.86^
 ||27.46.46.100^
 ||27.46.46.252^
-||27.5.23.215^
-||27.5.34.254^
-||27.5.46.18^
-||27.6.195.65^
-||27.6.240.125^
-||27.6.242.65^
+||27.5.23.69^
+||27.5.47.16^
+||27.6.240.171^
+||27.6.38.96^
 ||31.0.98.131^
 ||31.11.51.57^
 ||31.13.23.180^
 ||31.154.234.3^
 ||31.163.191.11^
+||31.168.124.130^
 ||31.168.179.83^
 ||31.168.184.59^
 ||31.168.191.243^
@@ -3038,11 +3024,13 @@
 ||31.30.119.23^
 ||32.208.157.193^
 ||32.218.180.9^
+||32792.prolocksmithwinterpark.com^
 ||35.184.169.169^
 ||36.108.231.218^
 ||36.250.203.246^
 ||36.251.157.225^
 ||36.251.18.18^
+||36.251.18.63^
 ||36.251.19.88^
 ||36.251.51.244^
 ||36.255.90.219^
@@ -3050,10 +3038,13 @@
 ||36.33.160.167^
 ||36.34.150.236^
 ||36.36.243.67^
+||36.43.11.16^
 ||36.66.105.159^
 ||36.66.111.203^
 ||36.66.133.125^
 ||36.66.139.36^
+||36.67.152.161^
+||36.81.23.38^
 ||36.89.18.133^
 ||36.96.187.93^
 ||360.lcy2zzx.pw^
@@ -3108,9 +3099,11 @@
 ||39.77.150.203^
 ||39.77.197.81^
 ||39.77.209.209^
+||39.77.48.213^
 ||39.77.94.189^
 ||39.77.95.50^
 ||39.79.146.67^
+||39.79.163.188^
 ||39.79.166.31^
 ||39.79.218.46^
 ||39.79.62.43^
@@ -3122,6 +3115,7 @@
 ||39.80.205.255^
 ||39.80.24.54^
 ||39.80.36.151^
+||39.80.37.182^
 ||39.81.251.0^
 ||39.81.27.15^
 ||39.81.29.231^
@@ -3141,17 +3135,14 @@
 ||39.86.216.144^
 ||39.86.234.187^
 ||39.86.248.91^
-||39.86.60.98^
 ||39.86.66.24^
 ||39.86.73.100^
-||39.86.78.228^
 ||39.87.63.58^
 ||39.87.90.210^
 ||39.87.93.109^
 ||39.88.141.172^
 ||39.88.155.96^
 ||39.88.233.131^
-||39.88.41.73^
 ||39.88.67.238^
 ||39.88.72.9^
 ||39.89.146.198^
@@ -3166,66 +3157,84 @@
 ||41.219.185.171^
 ||41.230.31.58^
 ||41.72.203.82^
+||41.86.18.133^
 ||41.86.18.148^
-||41.86.18.200^
+||41.86.18.157^
+||41.86.18.164^
+||41.86.18.165^
 ||41.86.18.71^
-||41.86.21.23^
-||41.86.5.233^
-||41.86.5.236^
+||41.86.19.206^
+||41.86.19.80^
+||41.86.21.38^
+||41.86.21.44^
+||41.86.21.62^
+||41.86.5.142^
+||41.86.5.198^
+||41.86.5.206^
 ||42.176.112.72^
 ||42.177.164.171^
 ||42.179.162.208^
 ||42.179.163.177^
 ||42.202.101.147^
+||42.224.122.183^
 ||42.224.122.39^
-||42.224.169.111^
 ||42.224.171.104^
 ||42.224.172.125^
-||42.224.18.165^
+||42.224.188.223^
+||42.224.189.79^
 ||42.224.19.55^
 ||42.224.220.37^
 ||42.224.233.247^
 ||42.224.234.23^
 ||42.224.245.91^
 ||42.224.249.160^
+||42.224.249.188^
+||42.224.3.187^
 ||42.224.36.220^
-||42.224.56.81^
+||42.224.52.81^
+||42.224.68.72^
 ||42.224.69.11^
 ||42.224.70.213^
 ||42.225.120.122^
 ||42.225.205.191^
 ||42.225.241.5^
-||42.226.89.25^
 ||42.227.194.95^
 ||42.227.196.123^
 ||42.227.66.88^
-||42.228.39.232^
+||42.228.196.68^
 ||42.228.40.56^
 ||42.228.60.114^
 ||42.228.67.135^
 ||42.228.68.118^
 ||42.228.70.126^
 ||42.228.70.231^
-||42.228.84.206^
-||42.230.153.183^
-||42.230.219.175^
+||42.230.218.252^
 ||42.230.25.164^
+||42.230.46.55^
 ||42.230.48.162^
-||42.231.95.195^
+||42.231.95.247^
 ||42.232.102.163^
-||42.232.23.76^
+||42.232.46.169^
+||42.233.159.21^
 ||42.233.78.236^
-||42.233.90.183^
+||42.234.247.41^
 ||42.234.85.184^
 ||42.235.23.163^
-||42.235.3.187^
-||42.235.82.129^
-||42.235.86.211^
+||42.235.67.162^
+||42.235.82.112^
+||42.235.87.100^
 ||42.235.90.32^
 ||42.235.95.254^
 ||42.236.148.201^
+||42.237.142.157^
+||42.237.24.151^
 ||42.237.252.159^
+||42.237.60.73^
+||42.238.228.0^
+||42.239.155.147^
+||42.239.202.121^
 ||42.239.21.27^
+||42.239.218.137^
 ||42.239.98.70^
 ||42.242.200.90^
 ||42.56.15.227^
@@ -3234,6 +3243,7 @@
 ||42.87.29.162^
 ||43.230.156.44^
 ||43.241.106.183^
+||43.252.8.94^
 ||45.133.1.137^
 ||45.133.1.139^
 ||45.133.1.242^
@@ -3248,10 +3258,13 @@
 ||45.144.225.65^
 ||45.148.10.47^
 ||45.148.10.94^
+||45.165.215.19^
 ||45.176.108.116^
+||45.176.108.164^
 ||45.176.108.22^
 ||45.176.108.248^
 ||45.176.110.99^
+||45.176.111.119^
 ||45.176.111.154^
 ||45.176.111.16^
 ||45.176.111.202^
@@ -3267,10 +3280,10 @@
 ||45.81.235.31^
 ||45.9.148.37^
 ||46.151.155.218^
+||46.161.185.15^
 ||46.172.75.231^
 ||46.175.184.121^
 ||46.182.173.246^
-||46.182.173.247^
 ||46.20.63.218^
 ||46.21.153.231^
 ||46.214.27.4^
@@ -3292,7 +3305,6 @@
 ||49.142.87.36^
 ||49.143.32.36^
 ||49.143.43.93^
-||49.156.35.166^
 ||49.158.201.200^
 ||49.159.20.121^
 ||49.159.21.3^
@@ -3303,13 +3315,14 @@
 ||49.68.221.252^
 ||49.68.249.121^
 ||49.70.15.16^
+||49.70.95.181^
 ||5.146.202.18^
 ||5.181.135.114^
 ||5.2.70.50^
+||5.42.37.74^
 ||5.53.146.179^
 ||5.8.10.62^
 ||50.115.174.102^
-||50.115.174.106^
 ||50.121.91.255^
 ||50.252.47.29^
 ||51.171.146.13^
@@ -3317,6 +3330,7 @@
 ||54.36.114.136^
 ||54.36.180.122^
 ||58.114.246.26^
+||58.115.108.164^
 ||58.115.162.92^
 ||58.115.174.4^
 ||58.125.191.4^
@@ -3331,7 +3345,6 @@
 ||58.218.67.253^
 ||58.22.212.107^
 ||58.226.129.29^
-||58.229.194.122^
 ||58.23.245.24^
 ||58.230.89.42^
 ||58.238.42.192^
@@ -3340,92 +3353,57 @@
 ||58.241.78.55^
 ||58.243.126.133^
 ||58.248.112.254^
-||58.248.140.46^
+||58.248.117.238^
+||58.248.142.5^
 ||58.248.143.240^
-||58.248.144.122^
-||58.248.144.88^
-||58.248.147.235^
-||58.248.151.128^
+||58.248.144.229^
+||58.248.147.196^
+||58.248.151.33^
 ||58.248.153.224^
-||58.248.76.23^
+||58.248.74.240^
 ||58.248.77.38^
-||58.248.82.34^
 ||58.249.12.80^
 ||58.249.14.53^
 ||58.249.16.173^
 ||58.249.19.127^
-||58.249.23.58^
-||58.249.73.182^
-||58.249.74.197^
+||58.249.72.88^
+||58.249.74.243^
 ||58.249.74.245^
-||58.249.75.107^
-||58.249.75.158^
+||58.249.75.213^
 ||58.249.77.88^
-||58.249.79.62^
+||58.249.80.25^
 ||58.249.82.35^
-||58.249.86.11^
-||58.249.87.54^
-||58.249.88.218^
+||58.249.87.171^
+||58.249.89.158^
 ||58.252.176.71^
-||58.253.13.50^
+||58.255.133.161^
+||58.255.140.150^
 ||58.48.154.143^
 ||58.50.221.148^
 ||58.72.165.153^
 ||58.72.165.39^
 ||58.76.151.189^
+||58.76.151.51^
 ||58.97.206.33^
 ||59.0.211.161^
 ||59.102.168.189^
+||59.127.11.50^
 ||59.151.202.3^
 ||59.151.214.4^
+||59.151.246.125^
 ||59.29.133.229^
-||59.32.97.190^
-||59.42.62.0^
 ||59.45.235.176^
 ||59.58.104.244^
 ||59.58.117.226^
 ||59.7.124.148^
 ||59.8.35.22^
-||59.92.176.186^
-||59.92.18.43^
-||59.92.181.100^
-||59.92.182.21^
-||59.92.182.84^
-||59.92.218.209^
-||59.92.218.254^
-||59.93.17.66^
-||59.93.18.37^
-||59.93.22.45^
-||59.94.180.222^
-||59.94.181.124^
-||59.94.183.163^
-||59.95.174.230^
-||59.95.175.37^
-||59.96.38.154^
-||59.96.38.182^
-||59.97.168.127^
-||59.97.169.111^
-||59.97.169.173^
-||59.97.171.61^
-||59.97.172.0^
-||59.97.173.49^
-||59.97.174.151^
-||59.97.175.163^
-||59.99.136.22^
-||59.99.136.63^
-||59.99.138.83^
-||59.99.139.190^
-||59.99.141.237^
-||59.99.40.173^
-||59.99.40.27^
-||59.99.41.192^
-||59.99.44.136^
-||59.99.44.201^
-||59.99.44.5^
-||59.99.47.220^
-||59.99.47.96^
-||59.99.93.136^
-||59.99.94.181^
+||59.92.180.232^
+||59.92.217.35^
+||59.94.180.230^
+||59.96.37.181^
+||59.96.37.192^
+||59.96.39.222^
+||59.97.193.255^
 ||60.13.61.12^
 ||60.14.48.221^
 ||60.16.247.78^
@@ -3443,6 +3421,7 @@
 ||60.211.19.63^
 ||60.211.6.112^
 ||60.212.100.83^
+||60.212.111.39^
 ||60.212.162.152^
 ||60.212.202.218^
 ||60.212.206.246^
@@ -3453,6 +3432,8 @@
 ||60.213.162.59^
 ||60.213.58.188^
 ||60.213.83.55^
+||60.214.217.96^
+||60.214.32.17^
 ||60.214.73.6^
 ||60.214.93.166^
 ||60.215.165.64^
@@ -3466,15 +3447,15 @@
 ||60.25.115.48^
 ||60.25.76.224^
 ||60.253.15.104^
-||60.253.39.88^
+||60.253.4.72^
 ||60.253.42.72^
 ||60.253.51.127^
-||60.253.8.81^
 ||60.26.17.221^
 ||60.7.10.121^
 ||60.7.8.43^
 ||60.7.99.254^
 ||61.102.243.124^
+||61.130.195.121^
 ||61.162.169.210^
 ||61.162.55.42^
 ||61.163.142.96^
@@ -3482,52 +3463,49 @@
 ||61.179.171.60^
 ||61.179.91.194^
 ||61.179.91.230^
-||61.18.112.48^
 ||61.192.73.253^
 ||61.213.118.28^
 ||61.247.224.66^
 ||61.253.94.230^
-||61.3.124.126^
-||61.3.124.8^
-||61.3.127.102^
-||61.3.149.89^
+||61.3.124.125^
+||61.3.151.60^
 ||61.47.220.169^
 ||61.52.103.144^
+||61.52.103.217^
+||61.52.109.9^
 ||61.52.11.87^
 ||61.52.159.231^
+||61.52.167.66^
 ||61.52.195.226^
+||61.52.210.53^
+||61.52.211.61^
 ||61.52.212.191^
 ||61.52.214.11^
+||61.52.234.193^
 ||61.52.237.212^
 ||61.52.242.56^
+||61.52.30.172^
+||61.52.4.214^
+||61.52.42.174^
 ||61.52.48.40^
 ||61.52.76.72^
 ||61.52.9.166^
 ||61.52.9.62^
+||61.52.98.22^
 ||61.52.99.161^
-||61.53.100.87^
 ||61.53.102.137^
 ||61.53.117.115^
 ||61.53.119.161^
 ||61.53.122.161^
 ||61.53.123.162^
 ||61.53.192.49^
-||61.53.2.35^
 ||61.53.201.162^
-||61.53.54.255^
-||61.53.72.250^
-||61.53.81.18^
-||61.53.99.179^
 ||61.54.103.56^
 ||61.54.168.35^
 ||61.54.232.45^
 ||61.54.40.202^
-||61.54.58.190^
 ||61.54.58.20^
-||61.54.63.23^
 ||61.54.64.104^
-||61.54.76.122^
-||61.54.77.175^
 ||61.56.180.67^
 ||61.56.181.7^
 ||61.57.96.116^
@@ -3572,17 +3550,18 @@
 ||67.3.169.223^
 ||67.8.138.101^
 ||67.81.98.111^
-||67.82.242.243^
 ||67.83.49.234^
 ||67.84.138.165^
 ||68.151.244.128^
 ||68.174.182.226^
 ||68.175.107.153^
+||68.183.25.71^
 ||68.188.144.143^
 ||68.204.88.29^
 ||68.205.106.84^
 ||68.205.119.241^
 ||68.78.33.33^
+||68468438438.xyz^
 ||69.115.37.205^
 ||69.120.237.255^
 ||69.123.245.151^
@@ -3606,7 +3585,6 @@
 ||71.127.148.69^
 ||71.146.190.91^
 ||71.167.164.113^
-||71.19.150.93^
 ||71.204.63.239^
 ||71.29.48.164^
 ||71.34.191.213^
@@ -3624,16 +3602,17 @@
 ||72.214.69.226^
 ||72.229.230.118^
 ||72.229.35.40^
+||72.31.40.122^
 ||73.204.216.103^
 ||74.101.1.159^
 ||74.108.224.112^
+||74.116.216.141^
 ||74.194.117.165^
 ||74.195.115.176^
 ||74.199.84.77^
 ||74.64.139.223^
 ||74.75.165.81^
 ||75.127.141.52^
-||75.176.213.114^
 ||75.83.102.27^
 ||75.99.213.61^
 ||76.108.199.153^
@@ -3648,6 +3627,7 @@
 ||77.71.52.220^
 ||77.79.191.32^
 ||77.89.203.238^
+||77.94.89.20^
 ||78.186.155.18^
 ||78.187.141.144^
 ||78.187.240.125^
@@ -3700,7 +3680,6 @@
 ||82.80.154.214^
 ||82.80.187.109^
 ||82.81.100.54^
-||82.81.106.65^
 ||82.81.108.172^
 ||82.81.131.158^
 ||82.81.19.42^
@@ -3723,9 +3702,9 @@
 ||84.210.219.208^
 ||84.210.219.213^
 ||84.212.219.127^
-||84.224.162.170^
 ||84.228.50.118^
 ||84.228.95.204^
+||84.238.24.35^
 ||84.247.83.74^
 ||84.254.39.129^
 ||84.33.111.227^
@@ -3745,6 +3724,7 @@
 ||85.97.195.129^
 ||86.35.43.220^
 ||87.61.89.40^
+||87du.vip^
 ||88.119.171.253^
 ||88.2.208.71^
 ||88.2.219.179^
@@ -3758,7 +3738,6 @@
 ||88.250.254.90^
 ||89.122.183.130^
 ||89.29.213.33^
-||89.34.26.165^
 ||89.35.62.96^
 ||89.40.85.166^
 ||89.40.87.5^
@@ -3780,7 +3759,6 @@
 ||92.114.191.82^
 ||92.241.78.114^
 ||92.27.246.202^
-||92.54.237.143^
 ||92.54.237.237^
 ||92.83.62.139^
 ||92.85.18.138^
@@ -3803,6 +3781,7 @@
 ||95.153.241.63^
 ||95.154.20.231^
 ||95.158.19.130^
+||95.170.113.227^
 ||95.170.113.52^
 ||95.170.201.34^
 ||95.181.155.112^
@@ -3812,7 +3791,6 @@
 ||95.9.120.40^
 ||96.239.73.246^
 ||96.47.147.169^
-||97.103.64.196^
 ||97.68.140.254^
 ||97.96.199.75^
 ||98.0.210.218^
@@ -3826,7 +3804,6 @@
 ||98.30.24.54^
 ||99.150.245.203^
 ||99.33.195.164^
-||99centsdigitals.com^
 ||abcd.bg^
 ||abclicks.in^
 ||abissnet.net^
@@ -3834,6 +3811,7 @@
 ||absoftechworld.com^
 ||absupplies.co.uk^
 ||abyssos.eu^
+||academyshademani.com^
 ||acbick.com^
 ||accounts.thesmarttechhub.com^
 ||aceeprc.com.aceeprc.com^
@@ -3862,7 +3840,9 @@
 ||aiqtest.com^
 ||ajpharmaholding.com^
 ||ajstudiollc.com^
+||akauk09.top^
 ||akivj07.top^
+||akpgi08.top^
 ||al-wahd.com^
 ||alasdemariposas.org^
 ||alemelektronik.com^
@@ -3896,6 +3876,7 @@
 ||api.cstdevs.com^
 ||api.quocbao.biz^
 ||api.sampy.io^
+||aplicativoparasindicato.com.br^
 ||apoolcondo.com^
 ||app.adsensearticle.com^
 ||app.explicitsurveys.co.uk^
@@ -3903,7 +3884,6 @@
 ||apps.saintsoporte.com^
 ||aqv.news^
 ||areyoulivingwell.com^
-||arsapetrolab.com^
 ||artedibujoyarquitectura.com^
 ||ask-regard.call-save.biz^
 ||atfile.com^
@@ -3914,10 +3894,8 @@
 ||atteuqpotentialunlimited.com^
 ||augustair.com^
 ||aulist.com^
-||australiafashions.com^
 ||automaticrefreshments.com^
 ||avadhanagames.com^
-||avissrilanka.com^
 ||ayamallah.com^
 ||azmeasurement.com^
 ||azraktours.com^
@@ -3955,12 +3933,12 @@
 ||blog.oyinblogs.com^
 ||blog.takbelit.com^
 ||bmlifestyle.co.uk^
-||bnrbook.com^
 ||bnrnews.id^
 ||bodenstein.co.za^
 ||booksearch.com^
 ||bounces.mi-fs.com^
 ||bpo.correct.go.th^
+||bradleyinstitute.co.za^
 ||brandtrust.com.pk^
 ||brendanquine.com^
 ||brideofmessiah.com^
@@ -3971,8 +3949,6 @@
 ||browardinsurancemiami.solucioneslink.com^
 ||bt2.elin.co.za^
 ||btdapi.robotake.com^
-||bucrinsuranlceonlines.com^
-||buenavista.co^
 ||buigiaphat.com.vn^
 ||bullseyemedia.in^
 ||busandvanrentalmalaysia.com^
@@ -3997,6 +3973,7 @@
 ||ccauthority.net^
 ||cdaonline.com.ar^
 ||cec.asso.ac-amiens.fr^
+||cecra.cl^
 ||cellas.sk^
 ||cendekiabinaaksara.com^
 ||cespol-bote.com.mx^
@@ -4004,8 +3981,6 @@
 ||ch.rmu.ac.th^
 ||changematterscounselling.com^
 ||chardhamdodham.com^
-||cheacrilnsurances.com^
-||chealablilitycarinsurances.com^
 ||chezalice.co.za^
 ||childselect.com^
 ||chinhdropfile.myvnc.com^
@@ -4025,11 +4000,9 @@
 ||constructoralyon.com^
 ||consulateins.solucioneslink.com^
 ||contributeindustry.com^
-||controladoradeplagasmm.com^
 ||controleautomacao.com.br^
 ||copelandscapes.com^
 ||coulsongraphics.com^
-||coutler.newreadermedia.net^
 ||covid19.cyberschool.or.id^
 ||cr-sq.com^
 ||craftnesia.id^
@@ -4081,14 +4054,14 @@
 ||destinymc.co.za^
 ||detorre.es^
 ||dev-interestingtech.pantheonsite.io^
-||dev.sayse-tienda.com^
 ||dev.sebpo.net^
+||dezcom.com^
 ||dfcf.91756.cn^
-||dfsfcsfcdsfsdvcfsvcscv.com^
 ||diamantenegro.mi-fs.com^
 ||dienmayminhhung.com^
 ||digilib.dianhusada.ac.id^
 ||djking.f3322.net^
+||dl-link.link^
 ||dl.1003b.56a.com^
 ||dl.198424.com^
 ||dl.installcdn-aws.com^
@@ -4111,7 +4084,6 @@
 ||dovberger.com^
 ||down.flash-plays.com^
 ||down.pcclear.com^
-||down.udashi.com^
 ||down.webbora.com^
 ||down1.arpun.com^
 ||download.caihong.com^
@@ -4131,6 +4103,7 @@
 ||dsenterprize.co.za^
 ||dsspainting.com^
 ||du-wizards.com^
+||duckrambo.com^
 ||duque.guantanameratravel.com^
 ||dutapp.wisolve.co.za^
 ||duvalcharter.dekitout.com^
@@ -4141,7 +4114,6 @@
 ||ebruyatkin.com^
 ||econews.treegle.org^
 ||efficientegroup.com^
-||elliot.newreadermedia.net^
 ||en.baoend.com^
 ||enc-tech.com^
 ||endurotanzania.co.tz^
@@ -4157,7 +4129,6 @@
 ||exilum.com^
 ||exitoalfaomega.co^
 ||extrovertoffers.com^
-||f1sol.com^
 ||familydentist.site^
 ||farmaciasdrogaminas.com.br^
 ||fate3.xyz^
@@ -4168,6 +4139,7 @@
 ||files.martellexpress.us^
 ||final.makkahkmcc.com^
 ||fineartgallerym.com^
+||fixauto.illumetechnology.com^
 ||fkd.derpcity.ru^
 ||flintspin.com^
 ||flyingbuddhadesign.com^
@@ -4177,7 +4149,6 @@
 ||footweardirect.elin.co.za^
 ||forum.mdb.nu^
 ||fotoobjetivo.com^
-||foundationrepairhoustontx.net^
 ||foxeps.com.br^
 ||freecnetdownload.com^
 ||freedombookshop.tickme.lk^
@@ -4199,7 +4170,6 @@
 ||ghislain.dartois.pagesperso-orange.fr^
 ||giadungg7.com^
 ||giddos.ga^
-||gilliem.com^
 ||girotexuniformes.com^
 ||giteletropical.com^
 ||globaltask.ar^
@@ -4215,6 +4185,7 @@
 ||goldcupmortgage.com^
 ||golden-memories-funerals.yourpageserver.com^
 ||goldmen.in^
+||gracejukes.com^
 ||grupoinmare.com^
 ||gruposelt.000webhostapp.com^
 ||gs.monerorx.com^
@@ -4225,6 +4196,7 @@
 ||harshraval.in^
 ||hd11315.com^
 ||hdkamera2003.hu^
+||hdrest.fastlinktz.com^
 ||hds.sz4h.com^
 ||healthy20.net^
 ||heavymaq.cl^
@@ -4245,7 +4217,6 @@
 ||homefindersolutions.com^
 ||hongluosi.com^
 ||hookedupboatclub.com^
-||hostelkielce.com^
 ||hostzaa.com^
 ||houstonshutters.site^
 ||hr2019.vrcom7.com^
@@ -4264,7 +4235,6 @@
 ||iesanjosemonitos.edu.co^
 ||ikexpert.com^
 ||ilrafrica.com^
-||images.jermiau.com^
 ||imbueautoworx.co.za^
 ||incodimsa.com^
 ||incrediblepixels.com^
@@ -4282,8 +4252,10 @@
 ||intuitiveideas.com.my^
 ||inversiones.arrayanfinanciero.cl^
 ||invest.xpcorporative.com.br^
+||investinae.com^
 ||ipmes.ma^
 ||iremart.es^
+||iris101.co.uk^
 ||isaac.mikhailmotoringschool.com^
 ||iscamenabe.com^
 ||ismf.com.ng^
@@ -4294,7 +4266,6 @@
 ||it123.ru^
 ||itc-demo.softgig.co.ke^
 ||itconsultus.com.co^
-||jamesjorgensen.newreadermedia.net^
 ||jamiekaylive.com^
 ||jamshed.pk^
 ||jansen-heesch.nl^
@@ -4302,7 +4273,6 @@
 ||jay.diamondrelationscrm.us^
 ||jebs.net.au^
 ||jeffdahlke.com^
-||jewsjuice.com^
 ||jhayesconsulting.com^
 ||jiaoyuzixun.cn^
 ||jing-da.com.tw^
@@ -4317,14 +4287,11 @@
 ||jpwoodfordco.com^
 ||jumpmanualjacobhiller.com^
 ||jupiter.toxsl.in^
-||jurgensen.newreadermedia.net^
 ||justinscott.com.au^
-||kaizenjanitorial.com^
 ||kalawatihomes.com^
 ||kalpataru-elitus-mulund.thakkers.in^
 ||karer.by^
 ||katanvetov.co.il^
-||kbdom.com^
 ||kensingtondriving.com^
 ||kevinjewelry.com.co^
 ||keywatch.yourpageserver.com^
@@ -4362,7 +4329,6 @@
 ||lifebeam.elin.co.za^
 ||lindnerelektroanlagen.de^
 ||linkintec.cn^
-||litroxlitro.com^
 ||livetrack.in^
 ||lloydsindian.co.uk^
 ||lm.stagingarea.co.za^
@@ -4376,11 +4342,8 @@
 ||logotypfabriken.se^
 ||lotix.de^
 ||lotusanddragonfly.com^
-||lp.carrduci.com^
 ||lp.definerisco.com^
 ||lp.difusodesign.com^
-||lp.juancamilogarciareyes.com^
-||lp.tecnimasdecolombia.com.co^
 ||ltc.typoten.com^
 ||luckybrownie.com^
 ||luminouspneuma.com^
@@ -4410,6 +4373,7 @@
 ||materialescantu.com^
 ||matruchhaya.co.in^
 ||mattysplayground.com^
+||maxiquim.cl^
 ||maxtox.com.pk^
 ||mbgrm.com^
 ||mbsolutions.ge^
@@ -4419,6 +4383,7 @@
 ||mediamaster.co.za^
 ||medianews.ge^
 ||medistaffconsulting.com^
+||meditreat.itwebservice.in^
 ||meeweb.com^
 ||megamart.afnan-amc.com^
 ||merbay.ru^
@@ -4489,7 +4454,6 @@
 ||nikanpolimer.ir^
 ||nilehouse.co.ug^
 ||nilinkeji.com^
-||nisacooks.com^
 ||njtiledesigncenter.com^
 ||nobius.org^
 ||nocalnoodle.elin.co.za^
@@ -4504,7 +4468,6 @@
 ||nyeh2o.com.au^
 ||oakleyandfriends.co.uk^
 ||obseques-conseils.com^
-||ocean.tecnasulstore.com.br^
 ||ohe.ie^
 ||ohsewgorgeous.co.uk^
 ||oknoplastik.sk^
@@ -4555,7 +4518,6 @@
 ||payments.atifsiddiqui.me^
 ||pcsoori.com^
 ||pd.oceaniarp.net^
-||perpus.onlineman7-jombang.sch.id^
 ||perpustekim.untirta.ac.id^
 ||petercollie.com^
 ||ph4s.ru^
@@ -4576,6 +4538,7 @@
 ||poulman.panagiotopoulos-tours.gr^
 ||ppdb.smk-ciptaskill.sch.id^
 ||pptvideotemplates.com^
+||prestasicash.com.ar^
 ||prestigehomeautomation.net^
 ||prishaartcreations.com^
 ||production.sparshims.com^
@@ -4589,7 +4552,6 @@
 ||prosyarmakassar.com^
 ||provence.elin.co.za^
 ||prueba.danielluza.com^
-||ptpmeccatronica.eu^
 ||pujashoppe.in^
 ||punchdialogues.com^
 ||punjabdevelopersassociation.com.pk^
@@ -4641,7 +4603,6 @@
 ||rsgym.net^
 ||rubazar.pro^
 ||rubycityvietnam.com^
-||ruch.newreadermedia.net^
 ||ruisgood.ru^
 ||ruwadalkuwait.com^
 ||rydchile.cl^
@@ -4675,6 +4636,7 @@
 ||serendibsourcing.com^
 ||servicemhkd.myvnc.com^
 ||servicemhkd80.myvnc.com^
+||serviciovirtual.com.ar^
 ||seyranikenger.com.tr^
 ||sgessy.com.br^
 ||shaheentbfoundation.com^
@@ -4689,7 +4651,6 @@
 ||shopsofe.com^
 ||shrushtiinfotech.com^
 ||sibernetix.fr^
-||siddharthpanditpautra.com^
 ||sige.brisainformatica.com.br^
 ||signatureads.co.in^
 ||siili.net^
@@ -4740,7 +4701,8 @@
 ||statsres.com^
 ||statssound.com^
 ||statsspot.com^
-||stattilion.bar^
+||statsvilla.com^
+||stemschool.net^
 ||stiepancasetia.ac.id^
 ||stott-thompson.co.uk^
 ||stratexec.co.za^
@@ -4752,13 +4714,13 @@
 ||supermercadostia.com^
 ||support-4-free.com^
 ||support.clz.kr^
+||supportit.online^
 ||sw.yourpageserver.com^
 ||sweaty.dk^
 ||sweet-diet.com^
 ||swentsai.com^
 ||swiftlogisticseg.com^
 ||swwbia.com^
-||syedpro.dezinetimes.com^
 ||syracusecoffee.com^
 ||sys.pbmadu.co.id^
 ||sytraders.co^
@@ -4772,6 +4734,7 @@
 ||tapalkoedacoffee.com^
 ||tarravalleyfoods.com.au^
 ||taurus.ug^
+||tavo.cl^
 ||taxicabsrilanka.com^
 ||taxpos.com^
 ||tc.snpsresidential.com^
@@ -4792,6 +4755,7 @@
 ||test.letraele.es^
 ||test.typoten.com^
 ||test.wanepghana.org^
+||test1.asistencia247.com^
 ||test1.milenial.id^
 ||test1.tenplusone.my^
 ||test2.basis-web.com^
@@ -4858,7 +4822,7 @@
 ||unisoftcc.com^
 ||unyazitelecom.com^
 ||upcbpta.com^
-||urbane.dezinetimes.com^
+||urbantrapfest.cl^
 ||useformoney.000webhostapp.com^
 ||usmadetshirts.com^
 ||uss.ac.th^
@@ -4867,7 +4831,6 @@
 ||vcah.co.uk^
 ||vegadelcasero.cl^
 ||vendas.lidiacarmeli.com.br^
-||verify.aicosoft.com^
 ||vfocus.net^
 ||vidmattic.com^
 ||vienen.gblix.srv.br^
@@ -4885,6 +4848,7 @@
 ||vokasi.ub.ac.id^
 ||vologroup.com.br^
 ||voteyouramerica.dekitout.com^
+||vpinversiones.cl^
 ||vstsample.com^
 ||vtube.fadlymotivator.com^
 ||vvsskmodinationalschool.com^
@@ -4939,6 +4903,5 @@
 ||yskadvisors.com^
 ||yummyyogaudaipur.com^
 ||yzkzixun.com^
-||zakra.tecnasulstore.com.br^
 ||zytrox.tk^
 ||zz.690tx.com^
diff --git a/urlhaus-filter-agh.txt b/urlhaus-filter-agh.txt
index 3e812a42..2ab91aeb 100644
--- a/urlhaus-filter-agh.txt
+++ b/urlhaus-filter-agh.txt
@@ -1,5 +1,5 @@
 ! Title: Malicious URL Blocklist (AdGuard Home)
-! Updated: Sat, 27 Mar 2021 12:12:22 UTC
+! Updated: Sun, 28 Mar 2021 00:12:34 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1866,6 +1866,7 @@
 ||101.108.142.60^
 ||101.108.142.75^
 ||101.108.142.82^
+||101.108.142.9^
 ||101.108.143.105^
 ||101.108.143.110^
 ||101.108.143.137^
@@ -2392,6 +2393,7 @@
 ||101.66.80.23^
 ||101.66.80.72^
 ||101.66.81.166^
+||101.66.81.70^
 ||101.67.176.237^
 ||101.67.180.154^
 ||101.67.198.121^
@@ -2971,6 +2973,7 @@
 ||103.126.100.31^
 ||103.126.100.9^
 ||103.126.217.58^
+||103.126.35.40^
 ||103.127.104.165^
 ||103.127.104.16^
 ||103.127.104.184^
@@ -4274,6 +4277,7 @@
 ||103.245.48.197^
 ||103.245.49.135^
 ||103.245.49.147^
+||103.245.49.180^
 ||103.245.49.183^
 ||103.245.49.204^
 ||103.245.49.24^
@@ -8721,6 +8725,7 @@
 ||107.173.160.139^
 ||107.173.160.14^
 ||107.173.171.123^
+||107.173.171.143^
 ||107.173.171.168^
 ||107.173.175.135^
 ||107.173.176.100^
@@ -12357,6 +12362,7 @@
 ||112.122.63.240^
 ||112.122.63.54^
 ||112.122.63.6^
+||112.122.63.70^
 ||112.122.63.9^
 ||112.122.90.208^
 ||112.122.99.186^
@@ -14452,6 +14458,7 @@
 ||112.235.188.86^
 ||112.235.194.43^
 ||112.235.210.15^
+||112.235.210.251^
 ||112.235.217.106^
 ||112.235.217.213^
 ||112.235.219.224^
@@ -16831,6 +16838,7 @@
 ||112.242.96.25^
 ||112.242.96.4^
 ||112.242.96.56^
+||112.242.97.131^
 ||112.242.97.165^
 ||112.242.97.195^
 ||112.242.98.194^
@@ -16885,6 +16893,7 @@
 ||112.245.177.136^
 ||112.245.177.145^
 ||112.245.177.215^
+||112.245.178.153^
 ||112.245.179.96^
 ||112.245.182.56^
 ||112.245.182.9^
@@ -17213,6 +17222,7 @@
 ||112.247.156.74^
 ||112.247.158.19^
 ||112.247.16.190^
+||112.247.16.222^
 ||112.247.161.45^
 ||112.247.161.83^
 ||112.247.163.177^
@@ -17280,6 +17290,7 @@
 ||112.247.248.76^
 ||112.247.249.198^
 ||112.247.249.82^
+||112.247.25.42^
 ||112.247.250.193^
 ||112.247.250.96^
 ||112.247.251.11^
@@ -18712,6 +18723,7 @@
 ||112.254.125.2^
 ||112.254.127.63^
 ||112.254.128.119^
+||112.254.128.160^
 ||112.254.128.224^
 ||112.254.129.79^
 ||112.254.129.95^
@@ -18815,6 +18827,7 @@
 ||112.254.188.12^
 ||112.254.188.137^
 ||112.254.188.19^
+||112.254.188.228^
 ||112.254.188.35^
 ||112.254.189.137^
 ||112.254.189.16^
@@ -21505,6 +21518,7 @@
 ||113.116.177.248^
 ||113.116.177.29^
 ||113.116.177.81^
+||113.116.177.90^
 ||113.116.178.100^
 ||113.116.178.133^
 ||113.116.178.138^
@@ -22344,6 +22358,7 @@
 ||113.116.89.29^
 ||113.116.89.2^
 ||113.116.89.40^
+||113.116.89.41^
 ||113.116.89.45^
 ||113.116.89.55^
 ||113.116.89.82^
@@ -22698,6 +22713,7 @@
 ||113.118.159.142^
 ||113.118.159.144^
 ||113.118.159.153^
+||113.118.159.178^
 ||113.118.159.215^
 ||113.118.159.22^
 ||113.118.159.232^
@@ -23151,6 +23167,7 @@
 ||113.118.87.88^
 ||113.118.87.8^
 ||113.119.36.91^
+||113.119.37.141^
 ||113.119.85.16^
 ||113.122.238.68^
 ||113.122.32.245^
@@ -26884,6 +26901,7 @@
 ||113.88.39.103^
 ||113.88.39.104^
 ||113.88.39.194^
+||113.88.39.21^
 ||113.88.39.2^
 ||113.88.39.35^
 ||113.88.39.37^
@@ -27593,6 +27611,7 @@
 ||113.90.26.54^
 ||113.90.26.6^
 ||113.90.27.178^
+||113.90.27.218^
 ||113.90.92.191^
 ||113.90.93.98^
 ||113.90.94.120^
@@ -27720,6 +27739,7 @@
 ||113.92.196.102^
 ||113.92.196.116^
 ||113.92.196.145^
+||113.92.196.173^
 ||113.92.196.192^
 ||113.92.196.227^
 ||113.92.196.235^
@@ -30186,6 +30206,7 @@
 ||115.205.14.76^
 ||115.205.15.79^
 ||115.205.171.34^
+||115.205.197.221^
 ||115.205.235.30^
 ||115.205.66.30^
 ||115.205.70.49^
@@ -32675,6 +32696,7 @@
 ||115.48.201.222^
 ||115.48.201.244^
 ||115.48.201.255^
+||115.48.201.26^
 ||115.48.201.31^
 ||115.48.201.37^
 ||115.48.201.40^
@@ -33512,6 +33534,7 @@
 ||115.48.40.227^
 ||115.48.40.3^
 ||115.48.40.63^
+||115.48.41.101^
 ||115.48.41.141^
 ||115.48.41.156^
 ||115.48.41.184^
@@ -34452,6 +34475,7 @@
 ||115.49.24.52^
 ||115.49.24.58^
 ||115.49.24.60^
+||115.49.24.63^
 ||115.49.240.125^
 ||115.49.240.147^
 ||115.49.240.14^
@@ -36542,6 +36566,7 @@
 ||115.50.168.145^
 ||115.50.168.153^
 ||115.50.168.159^
+||115.50.168.160^
 ||115.50.168.168^
 ||115.50.168.183^
 ||115.50.168.197^
@@ -36684,6 +36709,7 @@
 ||115.50.171.172^
 ||115.50.171.184^
 ||115.50.171.188^
+||115.50.171.192^
 ||115.50.171.196^
 ||115.50.171.248^
 ||115.50.171.250^
@@ -37469,6 +37495,7 @@
 ||115.50.211.56^
 ||115.50.211.62^
 ||115.50.211.65^
+||115.50.211.74^
 ||115.50.211.80^
 ||115.50.211.8^
 ||115.50.212.107^
@@ -38652,6 +38679,7 @@
 ||115.50.242.244^
 ||115.50.242.246^
 ||115.50.242.43^
+||115.50.242.7^
 ||115.50.242.81^
 ||115.50.242.89^
 ||115.50.243.105^
@@ -38769,6 +38797,7 @@
 ||115.50.247.245^
 ||115.50.247.33^
 ||115.50.247.40^
+||115.50.247.46^
 ||115.50.247.47^
 ||115.50.247.56^
 ||115.50.247.80^
@@ -40641,6 +40670,7 @@
 ||115.50.79.23^
 ||115.50.79.50^
 ||115.50.79.73^
+||115.50.79.78^
 ||115.50.79.7^
 ||115.50.79.95^
 ||115.50.8.131^
@@ -41822,6 +41852,7 @@
 ||115.51.58.162^
 ||115.51.61.137^
 ||115.51.7.177^
+||115.51.7.254^
 ||115.51.78.11^
 ||115.51.88.101^
 ||115.51.88.117^
@@ -42457,6 +42488,7 @@
 ||115.52.172.58^
 ||115.52.172.63^
 ||115.52.172.64^
+||115.52.172.72^
 ||115.52.172.74^
 ||115.52.172.91^
 ||115.52.172.93^
@@ -43808,6 +43840,7 @@
 ||115.53.56.72^
 ||115.53.57.189^
 ||115.53.58.162^
+||115.53.58.228^
 ||115.53.58.24^
 ||115.53.59.170^
 ||115.53.59.68^
@@ -43923,6 +43956,7 @@
 ||115.54.112.3^
 ||115.54.113.101^
 ||115.54.113.128^
+||115.54.113.49^
 ||115.54.114.20^
 ||115.54.114.211^
 ||115.54.115.198^
@@ -44111,6 +44145,7 @@
 ||115.54.158.176^
 ||115.54.158.17^
 ||115.54.158.210^
+||115.54.158.251^
 ||115.54.158.255^
 ||115.54.158.67^
 ||115.54.159.101^
@@ -45800,6 +45835,7 @@
 ||115.55.126.58^
 ||115.55.126.59^
 ||115.55.126.88^
+||115.55.127.0^
 ||115.55.127.101^
 ||115.55.127.126^
 ||115.55.127.146^
@@ -48040,6 +48076,7 @@
 ||115.55.197.78^
 ||115.55.197.99^
 ||115.55.198.103^
+||115.55.198.105^
 ||115.55.198.117^
 ||115.55.198.127^
 ||115.55.198.143^
@@ -48842,6 +48879,7 @@
 ||115.55.52.113^
 ||115.55.52.125^
 ||115.55.52.136^
+||115.55.52.17^
 ||115.55.52.200^
 ||115.55.52.206^
 ||115.55.52.208^
@@ -49747,6 +49785,7 @@
 ||115.56.131.13^
 ||115.56.131.144^
 ||115.56.131.148^
+||115.56.131.150^
 ||115.56.131.166^
 ||115.56.131.170^
 ||115.56.131.186^
@@ -49996,6 +50035,7 @@
 ||115.56.135.237^
 ||115.56.135.247^
 ||115.56.135.250^
+||115.56.135.255^
 ||115.56.135.28^
 ||115.56.135.33^
 ||115.56.135.36^
@@ -50415,6 +50455,7 @@
 ||115.56.142.31^
 ||115.56.142.39^
 ||115.56.142.44^
+||115.56.142.45^
 ||115.56.142.49^
 ||115.56.142.4^
 ||115.56.142.5^
@@ -50742,6 +50783,7 @@
 ||115.56.150.128^
 ||115.56.150.130^
 ||115.56.150.139^
+||115.56.150.149^
 ||115.56.150.14^
 ||115.56.150.150^
 ||115.56.150.152^
@@ -50992,6 +51034,7 @@
 ||115.56.155.38^
 ||115.56.155.42^
 ||115.56.155.43^
+||115.56.155.50^
 ||115.56.155.51^
 ||115.56.155.54^
 ||115.56.155.64^
@@ -52593,6 +52636,7 @@
 ||115.56.27.88^
 ||115.56.3.209^
 ||115.56.31.10^
+||115.56.31.11^
 ||115.56.31.156^
 ||115.56.31.170^
 ||115.56.31.176^
@@ -54741,6 +54785,7 @@
 ||115.58.91.225^
 ||115.58.91.240^
 ||115.58.91.52^
+||115.58.91.65^
 ||115.58.91.74^
 ||115.58.91.86^
 ||115.58.91.9^
@@ -57991,6 +58036,7 @@
 ||115.61.112.13^
 ||115.61.112.140^
 ||115.61.112.14^
+||115.61.112.159^
 ||115.61.112.161^
 ||115.61.112.168^
 ||115.61.112.185^
@@ -58628,6 +58674,7 @@
 ||115.61.158.55^
 ||115.61.158.90^
 ||115.61.158.93^
+||115.61.158.98^
 ||115.61.159.102^
 ||115.61.159.115^
 ||115.61.159.118^
@@ -60152,6 +60199,7 @@
 ||115.62.170.41^
 ||115.62.170.82^
 ||115.62.170.91^
+||115.62.171.143^
 ||115.62.171.177^
 ||115.62.171.71^
 ||115.62.171.81^
@@ -60546,6 +60594,7 @@
 ||115.63.131.168^
 ||115.63.131.169^
 ||115.63.131.170^
+||115.63.131.173^
 ||115.63.131.176^
 ||115.63.131.229^
 ||115.63.131.230^
@@ -60777,6 +60826,7 @@
 ||115.63.139.178^
 ||115.63.139.183^
 ||115.63.139.186^
+||115.63.139.187^
 ||115.63.139.229^
 ||115.63.139.246^
 ||115.63.139.25^
@@ -68426,6 +68476,7 @@
 ||115.97.139.252^
 ||115.97.139.254^
 ||115.97.139.28^
+||115.97.139.32^
 ||115.97.139.35^
 ||115.97.139.3^
 ||115.97.139.43^
@@ -92778,6 +92829,7 @@
 ||116.68.98.15^
 ||116.68.98.160^
 ||116.68.98.163^
+||116.68.98.173^
 ||116.68.98.178^
 ||116.68.98.17^
 ||116.68.98.182^
@@ -94889,6 +94941,7 @@
 ||116.72.28.187^
 ||116.72.28.204^
 ||116.72.28.226^
+||116.72.28.239^
 ||116.72.28.48^
 ||116.72.28.49^
 ||116.72.28.76^
@@ -96505,6 +96558,7 @@
 ||116.73.52.121^
 ||116.73.52.122^
 ||116.73.52.124^
+||116.73.52.125^
 ||116.73.52.127^
 ||116.73.52.132^
 ||116.73.52.133^
@@ -98337,6 +98391,7 @@
 ||116.73.99.95^
 ||116.73.99.97^
 ||116.74.101.118^
+||116.74.101.150^
 ||116.74.101.161^
 ||116.74.101.177^
 ||116.74.101.210^
@@ -100253,6 +100308,7 @@
 ||116.74.23.37^
 ||116.74.23.44^
 ||116.74.23.45^
+||116.74.23.46^
 ||116.74.23.48^
 ||116.74.23.51^
 ||116.74.23.52^
@@ -100348,6 +100404,7 @@
 ||116.74.24.84^
 ||116.74.24.85^
 ||116.74.24.86^
+||116.74.24.8^
 ||116.74.24.92^
 ||116.74.24.96^
 ||116.74.24.99^
@@ -111714,6 +111771,7 @@
 ||116.88.65.131^
 ||116.9.145.199^
 ||116.9.43.106^
+||116.9.43.220^
 ||116.9.43.235^
 ||116.90.238.142^
 ||116.91.202.79^
@@ -112815,6 +112873,7 @@
 ||117.194.148.188^
 ||117.194.148.189^
 ||117.194.148.190^
+||117.194.148.198^
 ||117.194.148.202^
 ||117.194.148.205^
 ||117.194.148.207^
@@ -113096,6 +113155,7 @@
 ||117.194.151.176^
 ||117.194.151.178^
 ||117.194.151.180^
+||117.194.151.184^
 ||117.194.151.192^
 ||117.194.151.196^
 ||117.194.151.198^
@@ -114129,6 +114189,7 @@
 ||117.194.165.197^
 ||117.194.165.199^
 ||117.194.165.19^
+||117.194.165.1^
 ||117.194.165.200^
 ||117.194.165.202^
 ||117.194.165.203^
@@ -114739,6 +114800,7 @@
 ||117.196.48.178^
 ||117.196.48.179^
 ||117.196.48.180^
+||117.196.48.181^
 ||117.196.48.183^
 ||117.196.48.184^
 ||117.196.48.185^
@@ -115027,6 +115089,7 @@
 ||117.196.50.146^
 ||117.196.50.147^
 ||117.196.50.150^
+||117.196.50.154^
 ||117.196.50.158^
 ||117.196.50.15^
 ||117.196.50.161^
@@ -115070,6 +115133,7 @@
 ||117.196.50.229^
 ||117.196.50.230^
 ||117.196.50.236^
+||117.196.50.239^
 ||117.196.50.23^
 ||117.196.50.240^
 ||117.196.50.241^
@@ -115115,6 +115179,7 @@
 ||117.196.50.69^
 ||117.196.50.71^
 ||117.196.50.72^
+||117.196.50.76^
 ||117.196.50.77^
 ||117.196.50.78^
 ||117.196.50.79^
@@ -115993,6 +116058,7 @@
 ||117.202.66.40^
 ||117.202.66.41^
 ||117.202.66.42^
+||117.202.66.44^
 ||117.202.66.45^
 ||117.202.66.46^
 ||117.202.66.47^
@@ -117615,6 +117681,7 @@
 ||117.208.132.103^
 ||117.208.132.105^
 ||117.208.132.109^
+||117.208.132.10^
 ||117.208.132.110^
 ||117.208.132.111^
 ||117.208.132.113^
@@ -117882,6 +117949,7 @@
 ||117.208.133.85^
 ||117.208.133.86^
 ||117.208.133.87^
+||117.208.133.91^
 ||117.208.133.92^
 ||117.208.133.97^
 ||117.208.133.9^
@@ -119331,6 +119399,7 @@
 ||117.213.41.87^
 ||117.213.41.88^
 ||117.213.41.89^
+||117.213.41.8^
 ||117.213.41.91^
 ||117.213.41.92^
 ||117.213.41.93^
@@ -120265,6 +120334,7 @@
 ||117.213.47.134^
 ||117.213.47.136^
 ||117.213.47.138^
+||117.213.47.139^
 ||117.213.47.13^
 ||117.213.47.140^
 ||117.213.47.142^
@@ -120526,6 +120596,7 @@
 ||117.215.210.230^
 ||117.215.210.243^
 ||117.215.210.245^
+||117.215.210.249^
 ||117.215.210.250^
 ||117.215.210.251^
 ||117.215.210.25^
@@ -120586,6 +120657,7 @@
 ||117.215.212.153^
 ||117.215.212.166^
 ||117.215.212.168^
+||117.215.212.174^
 ||117.215.212.176^
 ||117.215.212.180^
 ||117.215.212.182^
@@ -120728,6 +120800,7 @@
 ||117.215.248.158^
 ||117.215.248.17^
 ||117.215.248.181^
+||117.215.248.198^
 ||117.215.248.201^
 ||117.215.248.205^
 ||117.215.248.208^
@@ -121570,6 +121643,7 @@
 ||117.222.162.70^
 ||117.222.162.71^
 ||117.222.162.72^
+||117.222.162.73^
 ||117.222.162.74^
 ||117.222.162.75^
 ||117.222.162.76^
@@ -122343,6 +122417,7 @@
 ||117.222.166.28^
 ||117.222.166.2^
 ||117.222.166.30^
+||117.222.166.36^
 ||117.222.166.38^
 ||117.222.166.39^
 ||117.222.166.3^
@@ -122820,6 +122895,7 @@
 ||117.222.170.217^
 ||117.222.170.223^
 ||117.222.170.224^
+||117.222.170.234^
 ||117.222.170.237^
 ||117.222.170.238^
 ||117.222.170.239^
@@ -124466,6 +124542,7 @@
 ||117.242.210.238^
 ||117.242.210.239^
 ||117.242.210.23^
+||117.242.210.240^
 ||117.242.210.241^
 ||117.242.210.244^
 ||117.242.210.246^
@@ -124748,6 +124825,7 @@
 ||117.242.48.212^
 ||117.242.48.232^
 ||117.242.48.57^
+||117.242.49.157^
 ||117.242.49.166^
 ||117.242.49.185^
 ||117.242.49.21^
@@ -126493,6 +126571,7 @@
 ||117.248.63.61^
 ||117.248.63.62^
 ||117.248.63.67^
+||117.248.63.70^
 ||117.248.63.73^
 ||117.248.63.74^
 ||117.248.63.75^
@@ -127590,6 +127669,7 @@
 ||117.251.63.214^
 ||117.251.63.216^
 ||117.251.63.217^
+||117.251.63.21^
 ||117.251.63.221^
 ||117.251.63.224^
 ||117.251.63.229^
@@ -128460,6 +128540,7 @@
 ||118.113.244.200^
 ||118.113.245.110^
 ||118.114.216.131^
+||118.114.84.237^
 ||118.116.192.103^
 ||118.116.192.53^
 ||118.117.167.48^
@@ -128779,6 +128860,7 @@
 ||118.172.224.136^
 ||118.172.224.179^
 ||118.172.224.205^
+||118.172.224.37^
 ||118.172.231.79^
 ||118.172.232.164^
 ||118.172.234.157^
@@ -130315,6 +130397,7 @@
 ||118.79.91.203^
 ||118.79.92.29^
 ||118.79.93.194^
+||118.79.96.11^
 ||118.79.96.249^
 ||118.79.96.9^
 ||118.79.97.100^
@@ -130631,6 +130714,7 @@
 ||119.118.128.127^
 ||119.118.139.228^
 ||119.118.143.250^
+||119.118.150.84^
 ||119.118.161.115^
 ||119.118.167.179^
 ||119.118.172.168^
@@ -131011,6 +131095,7 @@
 ||119.123.173.46^
 ||119.123.173.73^
 ||119.123.173.91^
+||119.123.173.95^
 ||119.123.173.96^
 ||119.123.174.102^
 ||119.123.174.11^
@@ -131055,6 +131140,7 @@
 ||119.123.175.174^
 ||119.123.175.175^
 ||119.123.175.185^
+||119.123.175.210^
 ||119.123.175.215^
 ||119.123.175.222^
 ||119.123.175.228^
@@ -131273,6 +131359,7 @@
 ||119.123.219.194^
 ||119.123.219.204^
 ||119.123.219.230^
+||119.123.219.232^
 ||119.123.219.234^
 ||119.123.219.240^
 ||119.123.219.247^
@@ -131316,6 +131403,7 @@
 ||119.123.221.5^
 ||119.123.221.6^
 ||119.123.221.74^
+||119.123.221.94^
 ||119.123.222.0^
 ||119.123.222.112^
 ||119.123.222.128^
@@ -131456,6 +131544,7 @@
 ||119.123.239.109^
 ||119.123.239.117^
 ||119.123.239.122^
+||119.123.239.131^
 ||119.123.239.142^
 ||119.123.239.153^
 ||119.123.239.180^
@@ -137596,6 +137685,7 @@
 ||120.57.214.1^
 ||120.57.214.200^
 ||120.57.214.223^
+||120.57.214.228^
 ||120.57.214.251^
 ||120.57.214.38^
 ||120.57.214.44^
@@ -139448,6 +139538,7 @@
 ||120.6.233.250^
 ||120.6.239.231^
 ||120.6.240.130^
+||120.6.241.130^
 ||120.6.242.41^
 ||120.6.248.88^
 ||120.6.4.156^
@@ -140460,6 +140551,7 @@
 ||120.85.196.17^
 ||120.85.196.196^
 ||120.85.196.205^
+||120.85.196.211^
 ||120.85.196.217^
 ||120.85.196.220^
 ||120.85.196.231^
@@ -140559,6 +140651,7 @@
 ||120.85.199.91^
 ||120.85.199.97^
 ||120.85.208.103^
+||120.85.208.107^
 ||120.85.208.111^
 ||120.85.208.114^
 ||120.85.208.121^
@@ -140737,6 +140830,7 @@
 ||120.85.238.0^
 ||120.85.238.107^
 ||120.85.238.10^
+||120.85.238.129^
 ||120.85.238.137^
 ||120.85.238.139^
 ||120.85.238.13^
@@ -140752,6 +140846,7 @@
 ||120.85.238.218^
 ||120.85.238.219^
 ||120.85.238.233^
+||120.85.238.238^
 ||120.85.238.240^
 ||120.85.238.244^
 ||120.85.238.252^
@@ -145410,6 +145505,7 @@
 ||123.11.125.70^
 ||123.11.125.93^
 ||123.11.126.117^
+||123.11.126.225^
 ||123.11.126.241^
 ||123.11.126.2^
 ||123.11.126.62^
@@ -146828,6 +146924,7 @@
 ||123.11.62.73^
 ||123.11.62.76^
 ||123.11.63.112^
+||123.11.63.113^
 ||123.11.63.133^
 ||123.11.63.170^
 ||123.11.63.180^
@@ -147452,6 +147549,7 @@
 ||123.12.185.95^
 ||123.12.186.64^
 ||123.12.187.224^
+||123.12.189.247^
 ||123.12.189.252^
 ||123.12.189.93^
 ||123.12.19.142^
@@ -147563,6 +147661,7 @@
 ||123.12.225.250^
 ||123.12.225.254^
 ||123.12.225.62^
+||123.12.225.70^
 ||123.12.225.90^
 ||123.12.225.94^
 ||123.12.226.119^
@@ -147903,6 +148002,7 @@
 ||123.12.243.76^
 ||123.12.243.82^
 ||123.12.243.83^
+||123.12.243.85^
 ||123.12.243.89^
 ||123.12.243.95^
 ||123.12.243.99^
@@ -149461,6 +149561,7 @@
 ||123.130.254.2^
 ||123.130.26.116^
 ||123.130.27.172^
+||123.130.27.19^
 ||123.130.28.103^
 ||123.130.28.105^
 ||123.130.28.213^
@@ -150426,6 +150527,7 @@
 ||123.14.127.174^
 ||123.14.127.209^
 ||123.14.127.219^
+||123.14.127.238^
 ||123.14.127.243^
 ||123.14.127.250^
 ||123.14.127.33^
@@ -150768,6 +150870,7 @@
 ||123.14.173.130^
 ||123.14.173.154^
 ||123.14.173.159^
+||123.14.173.199^
 ||123.14.173.202^
 ||123.14.173.218^
 ||123.14.174.128^
@@ -151256,6 +151359,7 @@
 ||123.14.249.253^
 ||123.14.249.25^
 ||123.14.249.30^
+||123.14.249.33^
 ||123.14.249.34^
 ||123.14.249.38^
 ||123.14.249.46^
@@ -151508,6 +151612,7 @@
 ||123.14.34.184^
 ||123.14.34.200^
 ||123.14.34.222^
+||123.14.34.240^
 ||123.14.34.246^
 ||123.14.34.36^
 ||123.14.34.42^
@@ -151563,6 +151668,7 @@
 ||123.14.37.215^
 ||123.14.37.228^
 ||123.14.37.231^
+||123.14.37.32^
 ||123.14.37.81^
 ||123.14.38.0^
 ||123.14.38.112^
@@ -151710,6 +151816,7 @@
 ||123.14.50.184^
 ||123.14.50.185^
 ||123.14.50.207^
+||123.14.50.214^
 ||123.14.50.221^
 ||123.14.50.251^
 ||123.14.50.3^
@@ -152490,6 +152597,7 @@
 ||123.153.59.88^
 ||123.153.80.178^
 ||123.153.88.252^
+||123.154.116.116^
 ||123.154.116.130^
 ||123.154.116.155^
 ||123.154.116.19^
@@ -154349,6 +154457,7 @@
 ||123.4.194.109^
 ||123.4.194.144^
 ||123.4.194.147^
+||123.4.194.152^
 ||123.4.194.15^
 ||123.4.194.167^
 ||123.4.194.173^
@@ -154562,6 +154671,7 @@
 ||123.4.213.128^
 ||123.4.213.152^
 ||123.4.213.169^
+||123.4.213.239^
 ||123.4.213.74^
 ||123.4.213.83^
 ||123.4.214.10^
@@ -155114,6 +155224,7 @@
 ||123.4.45.112^
 ||123.4.45.192^
 ||123.4.45.221^
+||123.4.45.31^
 ||123.4.45.4^
 ||123.4.45.7^
 ||123.4.46.136^
@@ -159752,6 +159863,7 @@
 ||123.8.71.235^
 ||123.8.71.243^
 ||123.8.71.246^
+||123.8.71.27^
 ||123.8.71.32^
 ||123.8.71.7^
 ||123.8.71.82^
@@ -161024,6 +161136,7 @@
 ||123.9.239.80^
 ||123.9.240.102^
 ||123.9.240.103^
+||123.9.240.115^
 ||123.9.240.138^
 ||123.9.240.146^
 ||123.9.240.166^
@@ -162383,6 +162496,7 @@
 ||124.131.136.92^
 ||124.131.137.113^
 ||124.131.137.137^
+||124.131.137.147^
 ||124.131.137.183^
 ||124.131.137.190^
 ||124.131.137.192^
@@ -162743,6 +162857,7 @@
 ||124.131.23.131^
 ||124.131.23.177^
 ||124.131.239.254^
+||124.131.24.185^
 ||124.131.24.187^
 ||124.131.24.219^
 ||124.131.24.229^
@@ -164133,6 +164248,7 @@
 ||124.92.133.100^
 ||124.92.135.150^
 ||124.92.135.30^
+||124.92.135.37^
 ||124.92.137.146^
 ||124.92.137.71^
 ||124.92.139.198^
@@ -164376,6 +164492,7 @@
 ||125.106.44.171^
 ||125.106.45.123^
 ||125.106.45.200^
+||125.106.46.225^
 ||125.106.47.217^
 ||125.106.48.237^
 ||125.106.48.250^
@@ -167516,6 +167633,7 @@
 ||125.41.164.49^
 ||125.41.164.56^
 ||125.41.164.59^
+||125.41.164.60^
 ||125.41.164.69^
 ||125.41.164.6^
 ||125.41.164.92^
@@ -167712,6 +167830,7 @@
 ||125.41.184.230^
 ||125.41.184.251^
 ||125.41.185.110^
+||125.41.185.186^
 ||125.41.185.237^
 ||125.41.185.252^
 ||125.41.185.65^
@@ -167870,6 +167989,7 @@
 ||125.41.191.88^
 ||125.41.191.8^
 ||125.41.196.104^
+||125.41.196.114^
 ||125.41.196.119^
 ||125.41.196.128^
 ||125.41.196.132^
@@ -169757,6 +169877,7 @@
 ||125.41.97.226^
 ||125.41.97.228^
 ||125.41.97.22^
+||125.41.97.231^
 ||125.41.97.234^
 ||125.41.97.237^
 ||125.41.97.238^
@@ -173144,6 +173265,7 @@
 ||125.43.6.111^
 ||125.43.6.114^
 ||125.43.6.138^
+||125.43.6.186^
 ||125.43.6.191^
 ||125.43.6.204^
 ||125.43.6.216^
@@ -173238,6 +173360,7 @@
 ||125.43.63.252^
 ||125.43.63.39^
 ||125.43.63.46^
+||125.43.63.47^
 ||125.43.63.49^
 ||125.43.63.50^
 ||125.43.63.55^
@@ -174991,6 +175114,7 @@
 ||125.44.207.72^
 ||125.44.207.91^
 ||125.44.207.97^
+||125.44.208.152^
 ||125.44.208.153^
 ||125.44.208.164^
 ||125.44.208.165^
@@ -175469,6 +175593,7 @@
 ||125.44.227.242^
 ||125.44.227.248^
 ||125.44.227.4^
+||125.44.227.51^
 ||125.44.227.65^
 ||125.44.227.69^
 ||125.44.228.124^
@@ -176412,6 +176537,7 @@
 ||125.44.70.28^
 ||125.44.70.31^
 ||125.44.70.5^
+||125.44.70.64^
 ||125.44.70.68^
 ||125.44.70.87^
 ||125.44.71.101^
@@ -177124,6 +177250,7 @@
 ||125.45.43.190^
 ||125.45.43.19^
 ||125.45.43.209^
+||125.45.43.63^
 ||125.45.43.78^
 ||125.45.48.101^
 ||125.45.48.154^
@@ -178191,6 +178318,7 @@
 ||125.46.165.8^
 ||125.46.166.101^
 ||125.46.166.10^
+||125.46.166.112^
 ||125.46.166.121^
 ||125.46.166.123^
 ||125.46.166.125^
@@ -179423,6 +179551,7 @@
 ||125.47.124.60^
 ||125.47.124.62^
 ||125.47.125.129^
+||125.47.125.16^
 ||125.47.126.230^
 ||125.47.126.53^
 ||125.47.126.63^
@@ -180392,6 +180521,7 @@
 ||125.47.248.117^
 ||125.47.248.119^
 ||125.47.248.124^
+||125.47.248.131^
 ||125.47.248.135^
 ||125.47.248.141^
 ||125.47.248.142^
@@ -180898,9 +181028,11 @@
 ||125.47.37.56^
 ||125.47.37.68^
 ||125.47.38.10^
+||125.47.38.114^
 ||125.47.38.119^
 ||125.47.38.124^
 ||125.47.38.132^
+||125.47.38.142^
 ||125.47.38.152^
 ||125.47.38.168^
 ||125.47.38.17^
@@ -181000,6 +181132,7 @@
 ||125.47.47.198^
 ||125.47.47.19^
 ||125.47.47.209^
+||125.47.47.212^
 ||125.47.47.217^
 ||125.47.47.21^
 ||125.47.47.220^
@@ -182998,6 +183131,7 @@
 ||125.99.220.216^
 ||125.99.222.152^
 ||125.99.222.245^
+||125.99.222.2^
 ||125.99.222.76^
 ||125.99.223.227^
 ||125.99.223.26^
@@ -185547,6 +185681,7 @@
 ||139.213.7.128^
 ||139.213.7.230^
 ||139.213.96.26^
+||139.213.97.191^
 ||139.213.97.23^
 ||139.214.62.66^
 ||139.214.62.96^
@@ -185775,6 +185910,7 @@
 ||14.109.109.129^
 ||14.109.111.219^
 ||14.109.112.100^
+||14.109.126.96^
 ||14.113.12.153^
 ||14.113.13.184^
 ||14.113.14.145^
@@ -186794,6 +186930,7 @@
 ||140.237.28.148^
 ||140.237.29.28^
 ||140.237.30.113^
+||140.237.30.172^
 ||140.237.30.179^
 ||140.237.30.188^
 ||140.237.31.197^
@@ -187597,6 +187734,7 @@
 ||149.255.15.112^
 ||149.255.15.121^
 ||149.255.15.134^
+||149.255.15.172^
 ||149.255.15.180^
 ||149.255.15.182^
 ||149.255.15.184^
@@ -190281,6 +190419,7 @@
 ||163.125.2.36^
 ||163.125.2.67^
 ||163.125.200.107^
+||163.125.200.118^
 ||163.125.200.126^
 ||163.125.200.129^
 ||163.125.200.133^
@@ -190302,6 +190441,7 @@
 ||163.125.200.230^
 ||163.125.200.233^
 ||163.125.200.238^
+||163.125.200.242^
 ||163.125.200.247^
 ||163.125.200.37^
 ||163.125.200.40^
@@ -190390,12 +190530,14 @@
 ||163.125.202.235^
 ||163.125.202.245^
 ||163.125.202.246^
+||163.125.202.255^
 ||163.125.202.27^
 ||163.125.202.4^
 ||163.125.202.57^
 ||163.125.202.72^
 ||163.125.202.74^
 ||163.125.202.83^
+||163.125.202.87^
 ||163.125.202.8^
 ||163.125.202.9^
 ||163.125.203.10^
@@ -190413,6 +190555,7 @@
 ||163.125.203.209^
 ||163.125.203.213^
 ||163.125.203.214^
+||163.125.203.236^
 ||163.125.203.23^
 ||163.125.203.32^
 ||163.125.203.33^
@@ -190474,6 +190617,7 @@
 ||163.125.206.151^
 ||163.125.206.162^
 ||163.125.206.164^
+||163.125.206.16^
 ||163.125.206.187^
 ||163.125.206.199^
 ||163.125.206.20^
@@ -190799,6 +190943,7 @@
 ||163.204.21.75^
 ||163.204.210.243^
 ||163.204.210.34^
+||163.204.211.136^
 ||163.204.211.205^
 ||163.204.211.228^
 ||163.204.211.47^
@@ -191886,6 +192031,7 @@
 ||168.187.202.184^
 ||168.187.234.86^
 ||168.194.110.39^
+||168.194.146.145^
 ||168.194.176.180^
 ||168.194.214.107^
 ||168.194.214.113^
@@ -192885,6 +193031,7 @@
 ||171.125.122.33^
 ||171.125.122.54^
 ||171.125.122.90^
+||171.125.122.91^
 ||171.125.123.88^
 ||171.125.124.133^
 ||171.125.124.58^
@@ -193148,6 +193295,7 @@
 ||171.125.65.193^
 ||171.125.65.202^
 ||171.125.65.22^
+||171.125.65.89^
 ||171.125.66.6^
 ||171.125.68.45^
 ||171.125.7.181^
@@ -198100,6 +198248,7 @@
 ||175.164.59.67^
 ||175.164.6.45^
 ||175.164.61.169^
+||175.164.61.215^
 ||175.164.63.75^
 ||175.164.63.94^
 ||175.164.66.17^
@@ -198242,6 +198391,7 @@
 ||175.169.118.51^
 ||175.169.127.142^
 ||175.169.127.205^
+||175.169.13.182^
 ||175.169.15.220^
 ||175.169.160.119^
 ||175.169.163.231^
@@ -201145,6 +201295,7 @@
 ||178.141.41.122^
 ||178.141.41.125^
 ||178.141.41.239^
+||178.141.44.152^
 ||178.141.44.159^
 ||178.141.44.184^
 ||178.141.44.219^
@@ -201412,9 +201563,11 @@
 ||178.175.1.162^
 ||178.175.1.164^
 ||178.175.1.165^
+||178.175.1.16^
 ||178.175.1.172^
 ||178.175.1.174^
 ||178.175.1.175^
+||178.175.1.176^
 ||178.175.1.178^
 ||178.175.1.179^
 ||178.175.1.182^
@@ -201450,6 +201603,7 @@
 ||178.175.1.33^
 ||178.175.1.34^
 ||178.175.1.43^
+||178.175.1.44^
 ||178.175.1.46^
 ||178.175.1.48^
 ||178.175.1.50^
@@ -201478,6 +201632,7 @@
 ||178.175.10.108^
 ||178.175.10.10^
 ||178.175.10.113^
+||178.175.10.121^
 ||178.175.10.124^
 ||178.175.10.125^
 ||178.175.10.12^
@@ -201498,6 +201653,7 @@
 ||178.175.10.173^
 ||178.175.10.175^
 ||178.175.10.177^
+||178.175.10.178^
 ||178.175.10.182^
 ||178.175.10.184^
 ||178.175.10.186^
@@ -201576,6 +201732,7 @@
 ||178.175.100.185^
 ||178.175.100.187^
 ||178.175.100.190^
+||178.175.100.191^
 ||178.175.100.193^
 ||178.175.100.201^
 ||178.175.100.203^
@@ -201613,6 +201770,7 @@
 ||178.175.100.48^
 ||178.175.100.49^
 ||178.175.100.4^
+||178.175.100.52^
 ||178.175.100.54^
 ||178.175.100.58^
 ||178.175.100.5^
@@ -201663,11 +201821,13 @@
 ||178.175.101.168^
 ||178.175.101.170^
 ||178.175.101.171^
+||178.175.101.173^
 ||178.175.101.174^
 ||178.175.101.177^
 ||178.175.101.186^
 ||178.175.101.187^
 ||178.175.101.189^
+||178.175.101.191^
 ||178.175.101.194^
 ||178.175.101.196^
 ||178.175.101.199^
@@ -201880,6 +202040,8 @@
 ||178.175.103.239^
 ||178.175.103.242^
 ||178.175.103.245^
+||178.175.103.246^
+||178.175.103.24^
 ||178.175.103.253^
 ||178.175.103.26^
 ||178.175.103.27^
@@ -201944,6 +202106,7 @@
 ||178.175.104.145^
 ||178.175.104.148^
 ||178.175.104.14^
+||178.175.104.151^
 ||178.175.104.152^
 ||178.175.104.153^
 ||178.175.104.154^
@@ -201952,6 +202115,7 @@
 ||178.175.104.15^
 ||178.175.104.161^
 ||178.175.104.163^
+||178.175.104.166^
 ||178.175.104.167^
 ||178.175.104.169^
 ||178.175.104.16^
@@ -201972,6 +202136,7 @@
 ||178.175.104.195^
 ||178.175.104.196^
 ||178.175.104.198^
+||178.175.104.199^
 ||178.175.104.1^
 ||178.175.104.200^
 ||178.175.104.202^
@@ -201985,6 +202150,7 @@
 ||178.175.104.230^
 ||178.175.104.234^
 ||178.175.104.235^
+||178.175.104.239^
 ||178.175.104.23^
 ||178.175.104.241^
 ||178.175.104.243^
@@ -201994,6 +202160,7 @@
 ||178.175.104.252^
 ||178.175.104.253^
 ||178.175.104.255^
+||178.175.104.26^
 ||178.175.104.27^
 ||178.175.104.29^
 ||178.175.104.34^
@@ -202070,6 +202237,7 @@
 ||178.175.105.206^
 ||178.175.105.208^
 ||178.175.105.213^
+||178.175.105.214^
 ||178.175.105.215^
 ||178.175.105.217^
 ||178.175.105.21^
@@ -202079,6 +202247,7 @@
 ||178.175.105.235^
 ||178.175.105.237^
 ||178.175.105.238^
+||178.175.105.240^
 ||178.175.105.245^
 ||178.175.105.247^
 ||178.175.105.248^
@@ -202120,6 +202289,7 @@
 ||178.175.105.93^
 ||178.175.105.94^
 ||178.175.105.96^
+||178.175.105.99^
 ||178.175.106.100^
 ||178.175.106.102^
 ||178.175.106.103^
@@ -202139,6 +202309,7 @@
 ||178.175.106.13^
 ||178.175.106.144^
 ||178.175.106.146^
+||178.175.106.149^
 ||178.175.106.154^
 ||178.175.106.156^
 ||178.175.106.157^
@@ -202200,6 +202371,7 @@
 ||178.175.106.28^
 ||178.175.106.31^
 ||178.175.106.32^
+||178.175.106.36^
 ||178.175.106.37^
 ||178.175.106.42^
 ||178.175.106.44^
@@ -202218,6 +202390,7 @@
 ||178.175.106.77^
 ||178.175.106.78^
 ||178.175.106.79^
+||178.175.106.83^
 ||178.175.106.84^
 ||178.175.106.87^
 ||178.175.106.8^
@@ -202570,6 +202743,7 @@
 ||178.175.11.149^
 ||178.175.11.150^
 ||178.175.11.154^
+||178.175.11.155^
 ||178.175.11.156^
 ||178.175.11.157^
 ||178.175.11.158^
@@ -202602,6 +202776,7 @@
 ||178.175.11.230^
 ||178.175.11.235^
 ||178.175.11.23^
+||178.175.11.241^
 ||178.175.11.243^
 ||178.175.11.244^
 ||178.175.11.246^
@@ -202687,6 +202862,7 @@
 ||178.175.110.190^
 ||178.175.110.191^
 ||178.175.110.192^
+||178.175.110.194^
 ||178.175.110.195^
 ||178.175.110.197^
 ||178.175.110.198^
@@ -202837,6 +203013,7 @@
 ||178.175.112.103^
 ||178.175.112.106^
 ||178.175.112.109^
+||178.175.112.110^
 ||178.175.112.113^
 ||178.175.112.114^
 ||178.175.112.117^
@@ -203066,6 +203243,7 @@
 ||178.175.114.123^
 ||178.175.114.124^
 ||178.175.114.125^
+||178.175.114.127^
 ||178.175.114.129^
 ||178.175.114.135^
 ||178.175.114.136^
@@ -203274,6 +203452,7 @@
 ||178.175.115.97^
 ||178.175.115.99^
 ||178.175.116.100^
+||178.175.116.101^
 ||178.175.116.103^
 ||178.175.116.104^
 ||178.175.116.106^
@@ -203301,6 +203480,7 @@
 ||178.175.116.15^
 ||178.175.116.165^
 ||178.175.116.169^
+||178.175.116.170^
 ||178.175.116.171^
 ||178.175.116.174^
 ||178.175.116.175^
@@ -203782,6 +203962,7 @@
 ||178.175.12.78^
 ||178.175.12.79^
 ||178.175.12.91^
+||178.175.12.93^
 ||178.175.12.97^
 ||178.175.120.100^
 ||178.175.120.101^
@@ -203866,6 +204047,7 @@
 ||178.175.120.52^
 ||178.175.120.57^
 ||178.175.120.58^
+||178.175.120.5^
 ||178.175.120.60^
 ||178.175.120.66^
 ||178.175.120.76^
@@ -203914,6 +204096,8 @@
 ||178.175.121.172^
 ||178.175.121.180^
 ||178.175.121.190^
+||178.175.121.192^
+||178.175.121.193^
 ||178.175.121.19^
 ||178.175.121.202^
 ||178.175.121.204^
@@ -204155,6 +204339,7 @@
 ||178.175.123.249^
 ||178.175.123.24^
 ||178.175.123.255^
+||178.175.123.26^
 ||178.175.123.27^
 ||178.175.123.29^
 ||178.175.123.2^
@@ -204575,6 +204760,7 @@
 ||178.175.127.214^
 ||178.175.127.216^
 ||178.175.127.217^
+||178.175.127.219^
 ||178.175.127.225^
 ||178.175.127.228^
 ||178.175.127.230^
@@ -204598,6 +204784,7 @@
 ||178.175.127.35^
 ||178.175.127.36^
 ||178.175.127.38^
+||178.175.127.43^
 ||178.175.127.45^
 ||178.175.127.46^
 ||178.175.127.53^
@@ -204620,6 +204807,7 @@
 ||178.175.127.91^
 ||178.175.127.92^
 ||178.175.127.95^
+||178.175.127.97^
 ||178.175.127.9^
 ||178.175.13.0^
 ||178.175.13.101^
@@ -204714,6 +204902,7 @@
 ||178.175.14.126^
 ||178.175.14.12^
 ||178.175.14.130^
+||178.175.14.131^
 ||178.175.14.13^
 ||178.175.14.141^
 ||178.175.14.144^
@@ -205042,6 +205231,7 @@
 ||178.175.17.62^
 ||178.175.17.63^
 ||178.175.17.64^
+||178.175.17.66^
 ||178.175.17.70^
 ||178.175.17.74^
 ||178.175.17.77^
@@ -205253,6 +205443,7 @@
 ||178.175.2.177^
 ||178.175.2.181^
 ||178.175.2.184^
+||178.175.2.186^
 ||178.175.2.187^
 ||178.175.2.188^
 ||178.175.2.189^
@@ -205408,6 +205599,7 @@
 ||178.175.20.8^
 ||178.175.20.93^
 ||178.175.20.96^
+||178.175.20.97^
 ||178.175.21.110^
 ||178.175.21.115^
 ||178.175.21.116^
@@ -205607,6 +205799,7 @@
 ||178.175.23.187^
 ||178.175.23.198^
 ||178.175.23.199^
+||178.175.23.19^
 ||178.175.23.201^
 ||178.175.23.204^
 ||178.175.23.205^
@@ -205696,6 +205889,7 @@
 ||178.175.24.189^
 ||178.175.24.190^
 ||178.175.24.191^
+||178.175.24.198^
 ||178.175.24.199^
 ||178.175.24.1^
 ||178.175.24.200^
@@ -205969,6 +206163,7 @@
 ||178.175.27.122^
 ||178.175.27.124^
 ||178.175.27.125^
+||178.175.27.137^
 ||178.175.27.138^
 ||178.175.27.143^
 ||178.175.27.146^
@@ -206021,6 +206216,7 @@
 ||178.175.27.237^
 ||178.175.27.239^
 ||178.175.27.241^
+||178.175.27.244^
 ||178.175.27.245^
 ||178.175.27.246^
 ||178.175.27.247^
@@ -206109,6 +206305,7 @@
 ||178.175.28.197^
 ||178.175.28.198^
 ||178.175.28.199^
+||178.175.28.200^
 ||178.175.28.202^
 ||178.175.28.205^
 ||178.175.28.206^
@@ -206134,6 +206331,7 @@
 ||178.175.28.38^
 ||178.175.28.4^
 ||178.175.28.50^
+||178.175.28.51^
 ||178.175.28.55^
 ||178.175.28.59^
 ||178.175.28.5^
@@ -206141,6 +206339,7 @@
 ||178.175.28.64^
 ||178.175.28.65^
 ||178.175.28.66^
+||178.175.28.69^
 ||178.175.28.6^
 ||178.175.28.72^
 ||178.175.28.74^
@@ -206190,6 +206389,7 @@
 ||178.175.29.204^
 ||178.175.29.205^
 ||178.175.29.207^
+||178.175.29.208^
 ||178.175.29.209^
 ||178.175.29.219^
 ||178.175.29.220^
@@ -206231,6 +206431,7 @@
 ||178.175.29.73^
 ||178.175.29.77^
 ||178.175.29.78^
+||178.175.29.7^
 ||178.175.29.85^
 ||178.175.29.86^
 ||178.175.29.8^
@@ -206302,6 +206503,7 @@
 ||178.175.3.27^
 ||178.175.3.28^
 ||178.175.3.31^
+||178.175.3.32^
 ||178.175.3.33^
 ||178.175.3.34^
 ||178.175.3.3^
@@ -206314,6 +206516,7 @@
 ||178.175.3.58^
 ||178.175.3.5^
 ||178.175.3.62^
+||178.175.3.66^
 ||178.175.3.68^
 ||178.175.3.69^
 ||178.175.3.6^
@@ -206324,6 +206527,7 @@
 ||178.175.3.80^
 ||178.175.3.81^
 ||178.175.3.85^
+||178.175.3.87^
 ||178.175.3.94^
 ||178.175.3.98^
 ||178.175.30.0^
@@ -206482,6 +206686,7 @@
 ||178.175.31.247^
 ||178.175.31.249^
 ||178.175.31.251^
+||178.175.31.252^
 ||178.175.31.253^
 ||178.175.31.29^
 ||178.175.31.32^
@@ -206512,6 +206717,7 @@
 ||178.175.31.94^
 ||178.175.31.97^
 ||178.175.31.98^
+||178.175.31.99^
 ||178.175.31.9^
 ||178.175.32.0^
 ||178.175.32.100^
@@ -206537,6 +206743,7 @@
 ||178.175.32.143^
 ||178.175.32.146^
 ||178.175.32.149^
+||178.175.32.14^
 ||178.175.32.152^
 ||178.175.32.154^
 ||178.175.32.157^
@@ -206579,6 +206786,7 @@
 ||178.175.32.23^
 ||178.175.32.241^
 ||178.175.32.243^
+||178.175.32.244^
 ||178.175.32.246^
 ||178.175.32.248^
 ||178.175.32.249^
@@ -206651,6 +206859,7 @@
 ||178.175.33.18^
 ||178.175.33.192^
 ||178.175.33.193^
+||178.175.33.196^
 ||178.175.33.198^
 ||178.175.33.1^
 ||178.175.33.202^
@@ -206675,6 +206884,7 @@
 ||178.175.33.241^
 ||178.175.33.242^
 ||178.175.33.244^
+||178.175.33.245^
 ||178.175.33.246^
 ||178.175.33.24^
 ||178.175.33.255^
@@ -206895,6 +207105,7 @@
 ||178.175.35.86^
 ||178.175.35.89^
 ||178.175.35.8^
+||178.175.35.91^
 ||178.175.35.92^
 ||178.175.35.93^
 ||178.175.35.96^
@@ -206980,6 +207191,7 @@
 ||178.175.36.51^
 ||178.175.36.52^
 ||178.175.36.56^
+||178.175.36.5^
 ||178.175.36.60^
 ||178.175.36.67^
 ||178.175.36.6^
@@ -207095,6 +207307,7 @@
 ||178.175.37.68^
 ||178.175.37.6^
 ||178.175.37.70^
+||178.175.37.71^
 ||178.175.37.74^
 ||178.175.37.75^
 ||178.175.37.76^
@@ -207213,6 +207426,7 @@
 ||178.175.39.105^
 ||178.175.39.106^
 ||178.175.39.107^
+||178.175.39.110^
 ||178.175.39.112^
 ||178.175.39.113^
 ||178.175.39.11^
@@ -207284,6 +207498,7 @@
 ||178.175.39.57^
 ||178.175.39.58^
 ||178.175.39.61^
+||178.175.39.63^
 ||178.175.39.71^
 ||178.175.39.74^
 ||178.175.39.76^
@@ -207531,6 +207746,7 @@
 ||178.175.41.217^
 ||178.175.41.221^
 ||178.175.41.223^
+||178.175.41.224^
 ||178.175.41.225^
 ||178.175.41.229^
 ||178.175.41.231^
@@ -207619,12 +207835,14 @@
 ||178.175.42.228^
 ||178.175.42.234^
 ||178.175.42.235^
+||178.175.42.240^
 ||178.175.42.243^
 ||178.175.42.245^
 ||178.175.42.247^
 ||178.175.42.253^
 ||178.175.42.254^
 ||178.175.42.255^
+||178.175.42.25^
 ||178.175.42.27^
 ||178.175.42.29^
 ||178.175.42.31^
@@ -207799,6 +208017,7 @@
 ||178.175.44.178^
 ||178.175.44.179^
 ||178.175.44.186^
+||178.175.44.188^
 ||178.175.44.191^
 ||178.175.44.194^
 ||178.175.44.197^
@@ -207930,6 +208149,7 @@
 ||178.175.45.252^
 ||178.175.45.253^
 ||178.175.45.254^
+||178.175.45.25^
 ||178.175.45.2^
 ||178.175.45.31^
 ||178.175.45.33^
@@ -208285,6 +208505,7 @@
 ||178.175.49.163^
 ||178.175.49.166^
 ||178.175.49.169^
+||178.175.49.177^
 ||178.175.49.180^
 ||178.175.49.185^
 ||178.175.49.188^
@@ -208297,6 +208518,7 @@
 ||178.175.49.208^
 ||178.175.49.20^
 ||178.175.49.213^
+||178.175.49.214^
 ||178.175.49.215^
 ||178.175.49.219^
 ||178.175.49.21^
@@ -208315,6 +208537,7 @@
 ||178.175.49.247^
 ||178.175.49.248^
 ||178.175.49.251^
+||178.175.49.252^
 ||178.175.49.253^
 ||178.175.49.31^
 ||178.175.49.39^
@@ -208424,6 +208647,7 @@
 ||178.175.5.68^
 ||178.175.5.70^
 ||178.175.5.71^
+||178.175.5.79^
 ||178.175.5.84^
 ||178.175.5.85^
 ||178.175.5.88^
@@ -208455,6 +208679,7 @@
 ||178.175.50.151^
 ||178.175.50.152^
 ||178.175.50.165^
+||178.175.50.168^
 ||178.175.50.169^
 ||178.175.50.173^
 ||178.175.50.174^
@@ -208491,6 +208716,7 @@
 ||178.175.50.27^
 ||178.175.50.28^
 ||178.175.50.2^
+||178.175.50.32^
 ||178.175.50.33^
 ||178.175.50.38^
 ||178.175.50.3^
@@ -208635,6 +208861,7 @@
 ||178.175.52.140^
 ||178.175.52.141^
 ||178.175.52.142^
+||178.175.52.146^
 ||178.175.52.149^
 ||178.175.52.14^
 ||178.175.52.153^
@@ -208659,6 +208886,7 @@
 ||178.175.52.211^
 ||178.175.52.212^
 ||178.175.52.216^
+||178.175.52.21^
 ||178.175.52.220^
 ||178.175.52.224^
 ||178.175.52.226^
@@ -208830,9 +209058,11 @@
 ||178.175.54.151^
 ||178.175.54.154^
 ||178.175.54.158^
+||178.175.54.15^
 ||178.175.54.162^
 ||178.175.54.163^
 ||178.175.54.165^
+||178.175.54.167^
 ||178.175.54.172^
 ||178.175.54.173^
 ||178.175.54.178^
@@ -209064,6 +209294,7 @@
 ||178.175.56.44^
 ||178.175.56.48^
 ||178.175.56.50^
+||178.175.56.52^
 ||178.175.56.54^
 ||178.175.56.55^
 ||178.175.56.57^
@@ -209098,6 +209329,7 @@
 ||178.175.57.119^
 ||178.175.57.11^
 ||178.175.57.121^
+||178.175.57.124^
 ||178.175.57.126^
 ||178.175.57.127^
 ||178.175.57.129^
@@ -209183,6 +209415,7 @@
 ||178.175.57.94^
 ||178.175.57.95^
 ||178.175.57.96^
+||178.175.57.99^
 ||178.175.58.100^
 ||178.175.58.101^
 ||178.175.58.105^
@@ -209324,6 +209557,7 @@
 ||178.175.59.238^
 ||178.175.59.239^
 ||178.175.59.23^
+||178.175.59.241^
 ||178.175.59.243^
 ||178.175.59.244^
 ||178.175.59.245^
@@ -209531,6 +209765,7 @@
 ||178.175.60.67^
 ||178.175.60.70^
 ||178.175.60.75^
+||178.175.60.76^
 ||178.175.60.79^
 ||178.175.60.7^
 ||178.175.60.80^
@@ -209621,6 +209856,7 @@
 ||178.175.61.86^
 ||178.175.61.90^
 ||178.175.61.91^
+||178.175.61.95^
 ||178.175.61.96^
 ||178.175.61.97^
 ||178.175.61.9^
@@ -209636,6 +209872,7 @@
 ||178.175.62.122^
 ||178.175.62.123^
 ||178.175.62.128^
+||178.175.62.141^
 ||178.175.62.143^
 ||178.175.62.150^
 ||178.175.62.151^
@@ -209775,6 +210012,7 @@
 ||178.175.63.227^
 ||178.175.63.228^
 ||178.175.63.229^
+||178.175.63.230^
 ||178.175.63.231^
 ||178.175.63.235^
 ||178.175.63.239^
@@ -209800,6 +210038,7 @@
 ||178.175.63.75^
 ||178.175.63.76^
 ||178.175.63.77^
+||178.175.63.78^
 ||178.175.63.80^
 ||178.175.63.87^
 ||178.175.63.88^
@@ -209833,6 +210072,7 @@
 ||178.175.64.149^
 ||178.175.64.151^
 ||178.175.64.154^
+||178.175.64.155^
 ||178.175.64.156^
 ||178.175.64.158^
 ||178.175.64.163^
@@ -209957,6 +210197,7 @@
 ||178.175.65.193^
 ||178.175.65.194^
 ||178.175.65.196^
+||178.175.65.19^
 ||178.175.65.202^
 ||178.175.65.214^
 ||178.175.65.215^
@@ -210197,6 +210438,7 @@
 ||178.175.67.48^
 ||178.175.67.51^
 ||178.175.67.54^
+||178.175.67.55^
 ||178.175.67.59^
 ||178.175.67.60^
 ||178.175.67.63^
@@ -210232,6 +210474,7 @@
 ||178.175.68.113^
 ||178.175.68.114^
 ||178.175.68.115^
+||178.175.68.116^
 ||178.175.68.121^
 ||178.175.68.124^
 ||178.175.68.125^
@@ -210906,6 +211149,7 @@
 ||178.175.73.72^
 ||178.175.73.76^
 ||178.175.73.77^
+||178.175.73.78^
 ||178.175.73.7^
 ||178.175.73.86^
 ||178.175.73.88^
@@ -210964,6 +211208,7 @@
 ||178.175.74.201^
 ||178.175.74.203^
 ||178.175.74.204^
+||178.175.74.205^
 ||178.175.74.206^
 ||178.175.74.207^
 ||178.175.74.20^
@@ -210982,6 +211227,7 @@
 ||178.175.74.237^
 ||178.175.74.238^
 ||178.175.74.241^
+||178.175.74.247^
 ||178.175.74.251^
 ||178.175.74.253^
 ||178.175.74.2^
@@ -211175,6 +211421,7 @@
 ||178.175.76.240^
 ||178.175.76.241^
 ||178.175.76.244^
+||178.175.76.246^
 ||178.175.76.248^
 ||178.175.76.24^
 ||178.175.76.27^
@@ -211255,6 +211502,7 @@
 ||178.175.77.242^
 ||178.175.77.244^
 ||178.175.77.246^
+||178.175.77.248^
 ||178.175.77.250^
 ||178.175.77.251^
 ||178.175.77.252^
@@ -211262,6 +211510,7 @@
 ||178.175.77.31^
 ||178.175.77.32^
 ||178.175.77.33^
+||178.175.77.34^
 ||178.175.77.37^
 ||178.175.77.38^
 ||178.175.77.40^
@@ -211362,6 +211611,7 @@
 ||178.175.78.48^
 ||178.175.78.50^
 ||178.175.78.51^
+||178.175.78.57^
 ||178.175.78.58^
 ||178.175.78.60^
 ||178.175.78.64^
@@ -211513,6 +211763,7 @@
 ||178.175.8.217^
 ||178.175.8.223^
 ||178.175.8.225^
+||178.175.8.227^
 ||178.175.8.233^
 ||178.175.8.238^
 ||178.175.8.241^
@@ -211530,6 +211781,7 @@
 ||178.175.8.60^
 ||178.175.8.61^
 ||178.175.8.63^
+||178.175.8.64^
 ||178.175.8.67^
 ||178.175.8.69^
 ||178.175.8.72^
@@ -211644,6 +211896,7 @@
 ||178.175.80.82^
 ||178.175.80.86^
 ||178.175.80.87^
+||178.175.80.89^
 ||178.175.80.8^
 ||178.175.80.90^
 ||178.175.80.91^
@@ -211699,6 +211952,7 @@
 ||178.175.81.194^
 ||178.175.81.197^
 ||178.175.81.198^
+||178.175.81.19^
 ||178.175.81.1^
 ||178.175.81.200^
 ||178.175.81.202^
@@ -211815,6 +212069,7 @@
 ||178.175.82.235^
 ||178.175.82.236^
 ||178.175.82.239^
+||178.175.82.23^
 ||178.175.82.242^
 ||178.175.82.245^
 ||178.175.82.246^
@@ -211871,11 +212126,13 @@
 ||178.175.83.125^
 ||178.175.83.130^
 ||178.175.83.133^
+||178.175.83.136^
 ||178.175.83.137^
 ||178.175.83.138^
 ||178.175.83.139^
 ||178.175.83.141^
 ||178.175.83.143^
+||178.175.83.144^
 ||178.175.83.145^
 ||178.175.83.147^
 ||178.175.83.151^
@@ -211993,6 +212250,7 @@
 ||178.175.84.16^
 ||178.175.84.170^
 ||178.175.84.178^
+||178.175.84.17^
 ||178.175.84.180^
 ||178.175.84.181^
 ||178.175.84.182^
@@ -212449,6 +212707,8 @@
 ||178.175.88.242^
 ||178.175.88.243^
 ||178.175.88.246^
+||178.175.88.248^
+||178.175.88.24^
 ||178.175.88.251^
 ||178.175.88.253^
 ||178.175.88.254^
@@ -212549,6 +212809,7 @@
 ||178.175.89.253^
 ||178.175.89.25^
 ||178.175.89.28^
+||178.175.89.30^
 ||178.175.89.31^
 ||178.175.89.33^
 ||178.175.89.37^
@@ -212686,6 +212947,7 @@
 ||178.175.90.177^
 ||178.175.90.178^
 ||178.175.90.179^
+||178.175.90.185^
 ||178.175.90.186^
 ||178.175.90.187^
 ||178.175.90.188^
@@ -212739,6 +213001,7 @@
 ||178.175.90.75^
 ||178.175.90.79^
 ||178.175.90.80^
+||178.175.90.81^
 ||178.175.90.85^
 ||178.175.90.89^
 ||178.175.90.8^
@@ -212931,6 +213194,7 @@
 ||178.175.92.42^
 ||178.175.92.43^
 ||178.175.92.45^
+||178.175.92.48^
 ||178.175.92.4^
 ||178.175.92.51^
 ||178.175.92.54^
@@ -212991,6 +213255,7 @@
 ||178.175.93.196^
 ||178.175.93.197^
 ||178.175.93.198^
+||178.175.93.199^
 ||178.175.93.1^
 ||178.175.93.200^
 ||178.175.93.202^
@@ -213183,6 +213448,7 @@
 ||178.175.95.154^
 ||178.175.95.156^
 ||178.175.95.158^
+||178.175.95.163^
 ||178.175.95.164^
 ||178.175.95.165^
 ||178.175.95.166^
@@ -213284,6 +213550,7 @@
 ||178.175.96.16^
 ||178.175.96.180^
 ||178.175.96.181^
+||178.175.96.187^
 ||178.175.96.189^
 ||178.175.96.192^
 ||178.175.96.195^
@@ -213334,6 +213601,7 @@
 ||178.175.96.6^
 ||178.175.96.70^
 ||178.175.96.75^
+||178.175.96.81^
 ||178.175.96.82^
 ||178.175.96.88^
 ||178.175.96.8^
@@ -213403,6 +213671,7 @@
 ||178.175.97.219^
 ||178.175.97.220^
 ||178.175.97.224^
+||178.175.97.225^
 ||178.175.97.230^
 ||178.175.97.231^
 ||178.175.97.238^
@@ -213467,6 +213736,7 @@
 ||178.175.98.206^
 ||178.175.98.207^
 ||178.175.98.20^
+||178.175.98.216^
 ||178.175.98.217^
 ||178.175.98.221^
 ||178.175.98.224^
@@ -214137,6 +214407,7 @@
 ||178.95.195.240^
 ||178.95.197.16^
 ||178.95.197.55^
+||178.95.197.91^
 ||178.95.198.146^
 ||178.95.199.144^
 ||178.95.199.175^
@@ -214458,6 +214729,7 @@
 ||179.42.107.127^
 ||179.42.107.128^
 ||179.42.107.137^
+||179.42.107.139^
 ||179.42.107.141^
 ||179.42.107.144^
 ||179.42.107.149^
@@ -215823,6 +216095,7 @@
 ||180.188.224.104^
 ||180.188.236.174^
 ||180.188.236.247^
+||180.188.236.32^
 ||180.188.236.9^
 ||180.188.241.111^
 ||180.188.241.115^
@@ -216007,6 +216280,7 @@
 ||180.253.17.128^
 ||180.253.191.125^
 ||180.253.27.248^
+||180.253.99.109^
 ||180.254.167.231^
 ||180.254.241.245^
 ||180.254.53.113^
@@ -217185,6 +217459,7 @@
 ||182.112.28.108^
 ||182.112.28.10^
 ||182.112.28.116^
+||182.112.28.118^
 ||182.112.28.122^
 ||182.112.28.123^
 ||182.112.28.130^
@@ -217419,6 +217694,7 @@
 ||182.112.34.187^
 ||182.112.34.202^
 ||182.112.34.20^
+||182.112.34.220^
 ||182.112.34.233^
 ||182.112.34.25^
 ||182.112.34.34^
@@ -219672,6 +219948,7 @@
 ||182.113.238.135^
 ||182.113.238.136^
 ||182.113.238.165^
+||182.113.238.197^
 ||182.113.238.199^
 ||182.113.238.20^
 ||182.113.238.28^
@@ -219866,6 +220143,7 @@
 ||182.113.29.230^
 ||182.113.29.241^
 ||182.113.29.245^
+||182.113.29.28^
 ||182.113.29.44^
 ||182.113.29.46^
 ||182.113.29.54^
@@ -221877,6 +222155,7 @@
 ||182.114.76.254^
 ||182.114.76.39^
 ||182.114.76.41^
+||182.114.76.42^
 ||182.114.76.50^
 ||182.114.76.67^
 ||182.114.76.81^
@@ -223927,6 +224206,7 @@
 ||182.116.116.61^
 ||182.116.116.64^
 ||182.116.116.68^
+||182.116.116.70^
 ||182.116.116.73^
 ||182.116.116.75^
 ||182.116.116.76^
@@ -224103,6 +224383,7 @@
 ||182.116.119.53^
 ||182.116.119.56^
 ||182.116.119.59^
+||182.116.119.66^
 ||182.116.119.68^
 ||182.116.119.74^
 ||182.116.119.77^
@@ -224289,6 +224570,7 @@
 ||182.116.36.149^
 ||182.116.36.15^
 ||182.116.36.174^
+||182.116.36.175^
 ||182.116.36.180^
 ||182.116.36.195^
 ||182.116.36.199^
@@ -226599,6 +226881,7 @@
 ||182.117.13.21^
 ||182.117.13.32^
 ||182.117.13.4^
+||182.117.13.57^
 ||182.117.13.71^
 ||182.117.13.73^
 ||182.117.13.75^
@@ -229967,6 +230250,7 @@
 ||182.118.164.227^
 ||182.118.164.248^
 ||182.118.165.190^
+||182.118.166.128^
 ||182.118.166.153^
 ||182.118.166.36^
 ||182.118.166.82^
@@ -230710,6 +230994,7 @@
 ||182.119.15.63^
 ||182.119.15.68^
 ||182.119.15.70^
+||182.119.15.78^
 ||182.119.15.81^
 ||182.119.15.86^
 ||182.119.15.91^
@@ -230970,6 +231255,7 @@
 ||182.119.166.4^
 ||182.119.166.64^
 ||182.119.166.72^
+||182.119.166.76^
 ||182.119.166.84^
 ||182.119.166.94^
 ||182.119.166.98^
@@ -231135,6 +231421,7 @@
 ||182.119.179.130^
 ||182.119.179.169^
 ||182.119.179.17^
+||182.119.179.193^
 ||182.119.179.199^
 ||182.119.179.202^
 ||182.119.179.230^
@@ -231513,6 +231800,7 @@
 ||182.119.196.160^
 ||182.119.196.182^
 ||182.119.196.190^
+||182.119.197.123^
 ||182.119.199.158^
 ||182.119.199.85^
 ||182.119.2.110^
@@ -231613,6 +231901,7 @@
 ||182.119.202.159^
 ||182.119.202.170^
 ||182.119.202.179^
+||182.119.202.180^
 ||182.119.202.189^
 ||182.119.202.201^
 ||182.119.202.205^
@@ -231813,6 +232102,7 @@
 ||182.119.21.39^
 ||182.119.21.46^
 ||182.119.21.54^
+||182.119.21.68^
 ||182.119.21.76^
 ||182.119.21.79^
 ||182.119.21.81^
@@ -233456,6 +233746,7 @@
 ||182.119.88.4^
 ||182.119.88.54^
 ||182.119.88.88^
+||182.119.89.107^
 ||182.119.89.11^
 ||182.119.89.123^
 ||182.119.89.126^
@@ -236306,6 +236597,7 @@
 ||182.121.15.1^
 ||182.121.15.203^
 ||182.121.15.219^
+||182.121.15.223^
 ||182.121.15.227^
 ||182.121.15.237^
 ||182.121.15.252^
@@ -238186,6 +238478,7 @@
 ||182.121.254.117^
 ||182.121.254.127^
 ||182.121.254.132^
+||182.121.254.147^
 ||182.121.254.152^
 ||182.121.254.15^
 ||182.121.254.198^
@@ -239232,6 +239525,7 @@
 ||182.121.54.81^
 ||182.121.54.8^
 ||182.121.54.95^
+||182.121.55.106^
 ||182.121.55.109^
 ||182.121.55.112^
 ||182.121.55.122^
@@ -241952,6 +242246,7 @@
 ||182.123.241.130^
 ||182.123.241.172^
 ||182.123.241.173^
+||182.123.241.195^
 ||182.123.241.200^
 ||182.123.241.214^
 ||182.123.241.23^
@@ -242762,6 +243057,7 @@
 ||182.124.200.94^
 ||182.124.201.176^
 ||182.124.201.186^
+||182.124.201.207^
 ||182.124.201.222^
 ||182.124.202.211^
 ||182.124.202.241^
@@ -244286,6 +244582,7 @@
 ||182.126.123.191^
 ||182.126.123.193^
 ||182.126.123.199^
+||182.126.123.19^
 ||182.126.123.201^
 ||182.126.123.209^
 ||182.126.123.211^
@@ -246544,6 +246841,7 @@
 ||182.127.106.176^
 ||182.127.106.216^
 ||182.127.106.217^
+||182.127.106.43^
 ||182.127.106.53^
 ||182.127.106.57^
 ||182.127.106.5^
@@ -249990,6 +250288,7 @@
 ||182.127.93.229^
 ||182.127.93.230^
 ||182.127.93.35^
+||182.127.93.38^
 ||182.127.93.39^
 ||182.127.93.42^
 ||182.127.93.44^
@@ -250437,6 +250736,7 @@
 ||182.245.26.13^
 ||182.245.26.171^
 ||182.245.27.165^
+||182.245.28.162^
 ||182.245.28.80^
 ||182.245.34.249^
 ||182.245.34.32^
@@ -251102,6 +251402,7 @@
 ||182.56.192.77^
 ||182.56.193.147^
 ||182.56.193.161^
+||182.56.193.251^
 ||182.56.193.26^
 ||182.56.193.39^
 ||182.56.193.46^
@@ -255720,6 +256021,7 @@
 ||182.59.222.42^
 ||182.59.222.60^
 ||182.59.222.96^
+||182.59.223.113^
 ||182.59.223.124^
 ||182.59.223.127^
 ||182.59.223.131^
@@ -255911,6 +256213,7 @@
 ||182.59.235.107^
 ||182.59.235.10^
 ||182.59.235.121^
+||182.59.235.150^
 ||182.59.235.151^
 ||182.59.235.157^
 ||182.59.235.164^
@@ -258269,6 +258572,7 @@
 ||183.185.113.113^
 ||183.185.115.92^
 ||183.185.125.227^
+||183.185.162.225^
 ||183.185.168.107^
 ||183.185.168.165^
 ||183.185.169.102^
@@ -258663,6 +258967,7 @@
 ||183.188.90.55^
 ||183.188.91.12^
 ||183.188.92.208^
+||183.188.93.116^
 ||183.188.93.21^
 ||183.188.94.13^
 ||183.188.94.195^
@@ -262172,6 +262477,7 @@
 ||186.33.112.209^
 ||186.33.112.20^
 ||186.33.112.210^
+||186.33.112.211^
 ||186.33.112.214^
 ||186.33.112.216^
 ||186.33.112.218^
@@ -262259,6 +262565,7 @@
 ||186.33.112.96^
 ||186.33.112.97^
 ||186.33.112.9^
+||186.33.113.137^
 ||186.33.113.241^
 ||186.33.113.2^
 ||186.33.113.54^
@@ -263541,6 +263848,7 @@
 ||188.116.36.88^
 ||188.119.112.125^
 ||188.119.120.135^
+||188.119.45.194^
 ||188.119.45.205^
 ||188.119.49.1^
 ||188.119.58.176^
@@ -265885,6 +266193,7 @@
 ||190.72.32.132^
 ||190.72.62.232^
 ||190.73.101.231^
+||190.73.12.149^
 ||190.73.71.174^
 ||190.74.22.100^
 ||190.75.113.109^
@@ -267081,6 +267390,7 @@
 ||193.38.55.126^
 ||193.38.55.59^
 ||193.38.55.73^
+||193.38.55.9^
 ||193.39.185.202^
 ||193.39.185.207^
 ||193.39.185.214^
@@ -269226,6 +269536,7 @@
 ||2.68.190.234^
 ||2.68.192.214^
 ||2.68.234.169^
+||2.68.59.23^
 ||2.68.78.147^
 ||2.82.200.218^
 ||2.82.28.27^
@@ -270499,6 +270810,7 @@
 ||202.164.139.120^
 ||202.164.139.121^
 ||202.164.139.123^
+||202.164.139.124^
 ||202.164.139.125^
 ||202.164.139.127^
 ||202.164.139.128^
@@ -270591,6 +270903,7 @@
 ||202.164.139.243^
 ||202.164.139.246^
 ||202.164.139.247^
+||202.164.139.248^
 ||202.164.139.249^
 ||202.164.139.24^
 ||202.164.139.252^
@@ -274936,6 +275249,7 @@
 ||209.133.223.130^
 ||209.14.30.109^
 ||209.14.30.121^
+||209.14.30.132^
 ||209.14.30.135^
 ||209.14.30.136^
 ||209.14.30.156^
@@ -274947,6 +275261,7 @@
 ||209.14.30.205^
 ||209.14.30.30^
 ||209.14.30.54^
+||209.14.31.111^
 ||209.14.31.125^
 ||209.14.31.162^
 ||209.14.31.163^
@@ -277663,6 +277978,7 @@
 ||218.32.118.185^
 ||218.32.118.1^
 ||218.32.124.170^
+||218.32.96.158^
 ||218.32.98.172^
 ||218.35.198.109^
 ||218.35.205.235^
@@ -277761,6 +278077,7 @@
 ||218.57.107.48^
 ||218.57.109.101^
 ||218.57.109.155^
+||218.57.109.48^
 ||218.57.109.58^
 ||218.57.115.102^
 ||218.57.115.124^
@@ -279307,6 +279624,7 @@
 ||219.154.116.154^
 ||219.154.116.156^
 ||219.154.116.166^
+||219.154.116.168^
 ||219.154.116.171^
 ||219.154.116.17^
 ||219.154.116.185^
@@ -279960,6 +280278,7 @@
 ||219.154.142.196^
 ||219.154.142.210^
 ||219.154.142.239^
+||219.154.142.35^
 ||219.154.142.41^
 ||219.154.142.43^
 ||219.154.142.4^
@@ -280095,6 +280414,7 @@
 ||219.154.176.189^
 ||219.154.176.24^
 ||219.154.177.205^
+||219.154.178.138^
 ||219.154.178.175^
 ||219.154.178.69^
 ||219.154.178.72^
@@ -280303,6 +280623,7 @@
 ||219.154.41.137^
 ||219.154.41.183^
 ||219.154.41.31^
+||219.154.41.36^
 ||219.154.41.51^
 ||219.154.42.109^
 ||219.154.42.121^
@@ -280612,6 +280933,7 @@
 ||219.155.11.212^
 ||219.155.11.220^
 ||219.155.11.240^
+||219.155.11.252^
 ||219.155.11.28^
 ||219.155.11.36^
 ||219.155.11.41^
@@ -281249,6 +281571,7 @@
 ||219.155.209.219^
 ||219.155.209.230^
 ||219.155.209.232^
+||219.155.209.253^
 ||219.155.209.25^
 ||219.155.209.35^
 ||219.155.209.54^
@@ -282622,6 +282945,7 @@
 ||219.155.86.128^
 ||219.155.86.136^
 ||219.155.86.145^
+||219.155.86.156^
 ||219.155.86.17^
 ||219.155.86.182^
 ||219.155.86.191^
@@ -283452,6 +283776,7 @@
 ||219.156.175.190^
 ||219.156.175.225^
 ||219.156.176.129^
+||219.156.176.153^
 ||219.156.176.184^
 ||219.156.176.20^
 ||219.156.176.64^
@@ -283462,6 +283787,7 @@
 ||219.156.177.212^
 ||219.156.177.232^
 ||219.156.177.71^
+||219.156.178.130^
 ||219.156.178.133^
 ||219.156.178.137^
 ||219.156.178.179^
@@ -284112,6 +284438,7 @@
 ||219.156.65.250^
 ||219.156.65.251^
 ||219.156.65.27^
+||219.156.65.47^
 ||219.156.65.48^
 ||219.156.65.70^
 ||219.156.65.71^
@@ -285776,6 +286103,7 @@
 ||219.157.214.216^
 ||219.157.214.221^
 ||219.157.214.22^
+||219.157.214.235^
 ||219.157.214.236^
 ||219.157.214.24^
 ||219.157.214.31^
@@ -289583,6 +289911,7 @@
 ||221.13.191.75^
 ||221.13.191.91^
 ||221.13.208.118^
+||221.13.208.159^
 ||221.13.208.8^
 ||221.13.210.251^
 ||221.13.211.121^
@@ -290332,6 +290661,7 @@
 ||221.14.184.24^
 ||221.14.184.32^
 ||221.14.184.76^
+||221.14.185.105^
 ||221.14.185.112^
 ||221.14.185.157^
 ||221.14.185.4^
@@ -290453,6 +290783,7 @@
 ||221.14.46.48^
 ||221.14.47.162^
 ||221.14.47.182^
+||221.14.47.189^
 ||221.14.47.46^
 ||221.14.47.77^
 ||221.14.47.82^
@@ -290461,6 +290792,7 @@
 ||221.14.56.169^
 ||221.14.56.252^
 ||221.14.56.67^
+||221.14.57.175^
 ||221.14.57.62^
 ||221.14.58.27^
 ||221.14.58.5^
@@ -290612,6 +290944,7 @@
 ||221.15.111.49^
 ||221.15.111.82^
 ||221.15.111.96^
+||221.15.112.103^
 ||221.15.112.186^
 ||221.15.112.203^
 ||221.15.112.220^
@@ -291253,6 +291586,7 @@
 ||221.15.155.179^
 ||221.15.155.180^
 ||221.15.155.184^
+||221.15.155.186^
 ||221.15.155.194^
 ||221.15.155.197^
 ||221.15.155.199^
@@ -291991,6 +292325,7 @@
 ||221.15.190.232^
 ||221.15.190.234^
 ||221.15.190.247^
+||221.15.190.2^
 ||221.15.190.40^
 ||221.15.190.98^
 ||221.15.191.114^
@@ -294267,6 +294602,7 @@
 ||221.201.54.42^
 ||221.201.54.97^
 ||221.202.232.175^
+||221.202.232.230^
 ||221.202.232.5^
 ||221.202.234.170^
 ||221.202.235.198^
@@ -294561,6 +294897,7 @@
 ||221.214.249.112^
 ||221.214.249.181^
 ||221.214.249.199^
+||221.214.251.109^
 ||221.214.251.162^
 ||221.214.251.91^
 ||221.214.254.15^
@@ -296320,6 +296657,7 @@
 ||222.136.76.154^
 ||222.136.76.84^
 ||222.136.77.141^
+||222.136.77.190^
 ||222.136.77.3^
 ||222.136.77.91^
 ||222.136.78.29^
@@ -297706,6 +298044,7 @@
 ||222.137.161.46^
 ||222.137.161.73^
 ||222.137.161.85^
+||222.137.161.88^
 ||222.137.161.8^
 ||222.137.161.91^
 ||222.137.161.95^
@@ -298883,6 +299222,7 @@
 ||222.137.220.204^
 ||222.137.220.207^
 ||222.137.220.212^
+||222.137.220.215^
 ||222.137.220.219^
 ||222.137.220.226^
 ||222.137.220.244^
@@ -299092,6 +299432,7 @@
 ||222.137.237.181^
 ||222.137.237.187^
 ||222.137.237.190^
+||222.137.237.203^
 ||222.137.237.208^
 ||222.137.237.212^
 ||222.137.237.217^
@@ -299574,6 +299915,7 @@
 ||222.137.53.125^
 ||222.137.53.191^
 ||222.137.53.192^
+||222.137.53.193^
 ||222.137.53.229^
 ||222.137.53.242^
 ||222.137.53.255^
@@ -300486,6 +300828,7 @@
 ||222.138.118.186^
 ||222.138.118.190^
 ||222.138.118.191^
+||222.138.118.192^
 ||222.138.118.195^
 ||222.138.118.196^
 ||222.138.118.201^
@@ -301348,6 +301691,7 @@
 ||222.138.183.111^
 ||222.138.183.116^
 ||222.138.183.117^
+||222.138.183.120^
 ||222.138.183.123^
 ||222.138.183.126^
 ||222.138.183.129^
@@ -301740,6 +302084,7 @@
 ||222.138.213.192^
 ||222.138.213.202^
 ||222.138.213.219^
+||222.138.213.235^
 ||222.138.213.239^
 ||222.138.213.245^
 ||222.138.213.31^
@@ -302369,6 +302714,7 @@
 ||222.138.50.32^
 ||222.138.50.50^
 ||222.138.50.75^
+||222.138.51.203^
 ||222.138.51.69^
 ||222.138.52.108^
 ||222.138.52.200^
@@ -302619,6 +302965,7 @@
 ||222.139.106.121^
 ||222.139.106.154^
 ||222.139.106.230^
+||222.139.106.55^
 ||222.139.107.10^
 ||222.139.107.113^
 ||222.139.107.137^
@@ -304144,6 +304491,7 @@
 ||222.140.179.102^
 ||222.140.179.11^
 ||222.140.179.120^
+||222.140.179.142^
 ||222.140.179.14^
 ||222.140.179.168^
 ||222.140.179.16^
@@ -304384,6 +304732,7 @@
 ||222.140.207.76^
 ||222.140.207.85^
 ||222.140.208.132^
+||222.140.208.18^
 ||222.140.208.205^
 ||222.140.208.219^
 ||222.140.208.45^
@@ -304704,6 +305053,7 @@
 ||222.141.101.240^
 ||222.141.101.251^
 ||222.141.101.254^
+||222.141.101.39^
 ||222.141.101.55^
 ||222.141.101.87^
 ||222.141.101.92^
@@ -305727,6 +306077,7 @@
 ||222.141.40.47^
 ||222.141.40.58^
 ||222.141.40.65^
+||222.141.40.69^
 ||222.141.40.73^
 ||222.141.40.75^
 ||222.141.40.7^
@@ -308015,6 +308366,7 @@
 ||222.81.155.83^
 ||222.81.155.88^
 ||222.81.156.100^
+||222.81.156.229^
 ||222.81.157.146^
 ||222.81.157.148^
 ||222.81.157.177^
@@ -309506,6 +309858,7 @@
 ||27.153.140.109^
 ||27.153.141.43^
 ||27.153.141.80^
+||27.153.142.115^
 ||27.153.142.228^
 ||27.153.142.44^
 ||27.153.143.113^
@@ -313503,6 +313856,7 @@
 ||27.208.200.128^
 ||27.208.200.67^
 ||27.208.201.212^
+||27.208.202.165^
 ||27.208.202.25^
 ||27.208.203.172^
 ||27.208.205.119^
@@ -313553,6 +313907,7 @@
 ||27.208.55.230^
 ||27.208.55.65^
 ||27.208.63.93^
+||27.208.70.115^
 ||27.208.70.207^
 ||27.208.72.67^
 ||27.208.76.142^
@@ -314608,6 +314963,7 @@
 ||27.213.165.198^
 ||27.213.166.136^
 ||27.213.166.174^
+||27.213.166.50^
 ||27.213.167.154^
 ||27.213.167.175^
 ||27.213.167.180^
@@ -315332,6 +315688,7 @@
 ||27.215.253.149^
 ||27.215.254.134^
 ||27.215.255.209^
+||27.215.27.143^
 ||27.215.28.105^
 ||27.215.28.45^
 ||27.215.3.168^
@@ -319710,6 +320067,7 @@
 ||27.41.159.205^
 ||27.41.159.216^
 ||27.41.159.26^
+||27.41.159.28^
 ||27.41.159.33^
 ||27.41.159.58^
 ||27.41.159.76^
@@ -320459,6 +320817,7 @@
 ||27.41.37.128^
 ||27.41.37.131^
 ||27.41.37.133^
+||27.41.37.155^
 ||27.41.37.171^
 ||27.41.37.180^
 ||27.41.37.187^
@@ -320607,6 +320966,7 @@
 ||27.41.89.195^
 ||27.41.89.50^
 ||27.41.89.89^
+||27.41.9.105^
 ||27.41.9.113^
 ||27.41.9.130^
 ||27.41.9.135^
@@ -320659,6 +321019,7 @@
 ||27.41.97.172^
 ||27.41.97.191^
 ||27.41.97.2^
+||27.41.97.36^
 ||27.41.97.40^
 ||27.41.97.6^
 ||27.41.97.94^
@@ -320693,10 +321054,12 @@
 ||27.43.105.64^
 ||27.43.106.242^
 ||27.43.107.181^
+||27.43.108.78^
 ||27.43.109.21^
 ||27.43.110.101^
 ||27.43.110.185^
 ||27.43.110.198^
+||27.43.111.161^
 ||27.43.111.217^
 ||27.43.111.46^
 ||27.43.115.108^
@@ -320708,6 +321071,7 @@
 ||27.43.116.96^
 ||27.43.116.9^
 ||27.43.117.15^
+||27.43.117.66^
 ||27.43.117.89^
 ||27.43.118.111^
 ||27.43.118.150^
@@ -320839,6 +321203,7 @@
 ||27.46.22.67^
 ||27.46.22.83^
 ||27.46.22.9^
+||27.46.23.10^
 ||27.46.23.123^
 ||27.46.23.181^
 ||27.46.23.188^
@@ -320883,6 +321248,7 @@
 ||27.46.44.233^
 ||27.46.44.235^
 ||27.46.44.237^
+||27.46.44.239^
 ||27.46.44.23^
 ||27.46.44.246^
 ||27.46.44.254^
@@ -320943,6 +321309,7 @@
 ||27.46.45.7^
 ||27.46.45.82^
 ||27.46.45.85^
+||27.46.45.86^
 ||27.46.45.88^
 ||27.46.45.89^
 ||27.46.45.90^
@@ -322363,6 +322730,7 @@
 ||27.5.30.70^
 ||27.5.30.71^
 ||27.5.30.72^
+||27.5.30.79^
 ||27.5.30.81^
 ||27.5.30.82^
 ||27.5.30.87^
@@ -322822,6 +323190,7 @@
 ||27.5.36.221^
 ||27.5.36.222^
 ||27.5.36.230^
+||27.5.36.232^
 ||27.5.36.233^
 ||27.5.36.234^
 ||27.5.36.238^
@@ -323336,6 +323705,7 @@
 ||27.5.41.143^
 ||27.5.41.144^
 ||27.5.41.145^
+||27.5.41.146^
 ||27.5.41.148^
 ||27.5.41.149^
 ||27.5.41.155^
@@ -325850,6 +326220,7 @@
 ||27.6.122.18^
 ||27.6.122.192^
 ||27.6.122.193^
+||27.6.122.194^
 ||27.6.122.197^
 ||27.6.122.19^
 ||27.6.122.1^
@@ -331353,6 +331724,7 @@
 ||27.6.240.15^
 ||27.6.240.161^
 ||27.6.240.169^
+||27.6.240.171^
 ||27.6.240.175^
 ||27.6.240.181^
 ||27.6.240.183^
@@ -331573,6 +331945,7 @@
 ||27.6.243.112^
 ||27.6.243.113^
 ||27.6.243.117^
+||27.6.243.122^
 ||27.6.243.126^
 ||27.6.243.127^
 ||27.6.243.128^
@@ -332264,6 +332637,7 @@
 ||27.6.34.217^
 ||27.6.34.60^
 ||27.6.38.222^
+||27.6.38.96^
 ||27.6.4.101^
 ||27.6.4.102^
 ||27.6.4.106^
@@ -344722,6 +345096,7 @@
 ||36.251.18.2^
 ||36.251.18.40^
 ||36.251.18.44^
+||36.251.18.63^
 ||36.251.19.213^
 ||36.251.19.231^
 ||36.251.19.249^
@@ -345326,6 +345701,7 @@
 ||36.42.107.77^
 ||36.42.107.99^
 ||36.43.10.121^
+||36.43.11.16^
 ||36.43.11.211^
 ||36.43.12.163^
 ||36.43.64.100^
@@ -345463,6 +345839,7 @@
 ||36.81.158.24^
 ||36.81.187.39^
 ||36.81.209.186^
+||36.81.23.38^
 ||36.81.230.140^
 ||36.81.31.124^
 ||36.82.179.161^
@@ -348934,6 +349311,7 @@
 ||39.77.44.29^
 ||39.77.44.32^
 ||39.77.46.7^
+||39.77.48.213^
 ||39.77.49.13^
 ||39.77.5.113^
 ||39.77.5.214^
@@ -349363,6 +349741,7 @@
 ||39.79.162.176^
 ||39.79.163.104^
 ||39.79.163.173^
+||39.79.163.188^
 ||39.79.163.252^
 ||39.79.163.96^
 ||39.79.164.165^
@@ -349827,6 +350206,7 @@
 ||39.80.35.201^
 ||39.80.36.151^
 ||39.80.36.64^
+||39.80.37.182^
 ||39.80.38.117^
 ||39.80.38.27^
 ||39.80.39.207^
@@ -353511,6 +353891,7 @@
 ||42.224.122.174^
 ||42.224.122.176^
 ||42.224.122.182^
+||42.224.122.183^
 ||42.224.122.186^
 ||42.224.122.191^
 ||42.224.122.193^
@@ -355133,6 +355514,7 @@
 ||42.224.188.115^
 ||42.224.188.137^
 ||42.224.188.176^
+||42.224.188.223^
 ||42.224.188.241^
 ||42.224.188.250^
 ||42.224.188.85^
@@ -355140,6 +355522,7 @@
 ||42.224.189.121^
 ||42.224.189.153^
 ||42.224.189.208^
+||42.224.189.79^
 ||42.224.189.88^
 ||42.224.189.89^
 ||42.224.189.90^
@@ -356182,6 +356565,7 @@
 ||42.224.249.177^
 ||42.224.249.178^
 ||42.224.249.182^
+||42.224.249.188^
 ||42.224.249.18^
 ||42.224.249.190^
 ||42.224.249.195^
@@ -356629,6 +357013,7 @@
 ||42.224.3.179^
 ||42.224.3.17^
 ||42.224.3.180^
+||42.224.3.187^
 ||42.224.3.192^
 ||42.224.3.205^
 ||42.224.3.206^
@@ -357344,6 +357729,7 @@
 ||42.224.52.52^
 ||42.224.52.56^
 ||42.224.52.58^
+||42.224.52.81^
 ||42.224.52.8^
 ||42.224.52.97^
 ||42.224.53.120^
@@ -357486,6 +357872,7 @@
 ||42.224.59.245^
 ||42.224.59.247^
 ||42.224.59.249^
+||42.224.59.251^
 ||42.224.59.68^
 ||42.224.59.73^
 ||42.224.59.74^
@@ -357865,6 +358252,7 @@
 ||42.224.68.67^
 ||42.224.68.69^
 ||42.224.68.70^
+||42.224.68.72^
 ||42.224.68.74^
 ||42.224.68.78^
 ||42.224.68.79^
@@ -361727,6 +362115,7 @@
 ||42.228.196.177^
 ||42.228.196.193^
 ||42.228.196.218^
+||42.228.196.68^
 ||42.228.196.89^
 ||42.228.197.136^
 ||42.228.197.142^
@@ -366571,6 +366960,7 @@
 ||42.230.46.198^
 ||42.230.46.231^
 ||42.230.46.246^
+||42.230.46.55^
 ||42.230.46.70^
 ||42.230.46.93^
 ||42.230.46.95^
@@ -368996,6 +369386,7 @@
 ||42.231.95.195^
 ||42.231.95.210^
 ||42.231.95.230^
+||42.231.95.247^
 ||42.231.95.99^
 ||42.231.96.105^
 ||42.231.96.176^
@@ -369931,6 +370322,7 @@
 ||42.232.45.68^
 ||42.232.45.85^
 ||42.232.46.129^
+||42.232.46.169^
 ||42.232.46.1^
 ||42.232.46.73^
 ||42.232.46.86^
@@ -370628,6 +371020,7 @@
 ||42.233.159.141^
 ||42.233.159.168^
 ||42.233.159.19^
+||42.233.159.21^
 ||42.233.159.223^
 ||42.233.159.228^
 ||42.233.159.230^
@@ -372150,6 +372543,7 @@
 ||42.234.246.76^
 ||42.234.246.77^
 ||42.234.247.171^
+||42.234.247.41^
 ||42.234.247.44^
 ||42.234.247.4^
 ||42.234.247.55^
@@ -375439,6 +375833,7 @@
 ||42.235.81.8^
 ||42.235.82.0^
 ||42.235.82.108^
+||42.235.82.112^
 ||42.235.82.118^
 ||42.235.82.129^
 ||42.235.82.141^
@@ -375469,6 +375864,7 @@
 ||42.235.82.44^
 ||42.235.82.45^
 ||42.235.82.46^
+||42.235.82.52^
 ||42.235.82.53^
 ||42.235.82.54^
 ||42.235.82.60^
@@ -375658,6 +376054,7 @@
 ||42.235.86.87^
 ||42.235.86.8^
 ||42.235.86.95^
+||42.235.87.100^
 ||42.235.87.102^
 ||42.235.87.103^
 ||42.235.87.121^
@@ -376844,6 +377241,7 @@
 ||42.237.14.202^
 ||42.237.14.74^
 ||42.237.14.8^
+||42.237.142.157^
 ||42.237.15.110^
 ||42.237.15.142^
 ||42.237.15.153^
@@ -376953,6 +377351,7 @@
 ||42.237.24.108^
 ||42.237.24.129^
 ||42.237.24.14^
+||42.237.24.151^
 ||42.237.24.166^
 ||42.237.24.220^
 ||42.237.24.232^
@@ -377205,6 +377604,7 @@
 ||42.237.60.219^
 ||42.237.60.254^
 ||42.237.60.42^
+||42.237.60.73^
 ||42.237.61.107^
 ||42.237.61.152^
 ||42.237.61.246^
@@ -377834,6 +378234,7 @@
 ||42.238.227.72^
 ||42.238.227.86^
 ||42.238.227.95^
+||42.238.228.0^
 ||42.238.228.122^
 ||42.238.228.132^
 ||42.238.228.220^
@@ -378022,6 +378423,7 @@
 ||42.238.250.202^
 ||42.238.250.246^
 ||42.238.250.248^
+||42.238.250.56^
 ||42.238.251.226^
 ||42.238.251.47^
 ||42.238.251.61^
@@ -378538,6 +378940,7 @@
 ||42.239.154.85^
 ||42.239.155.124^
 ||42.239.155.143^
+||42.239.155.147^
 ||42.239.155.158^
 ||42.239.155.159^
 ||42.239.155.165^
@@ -378806,6 +379209,7 @@
 ||42.239.201.20^
 ||42.239.201.86^
 ||42.239.202.100^
+||42.239.202.121^
 ||42.239.202.145^
 ||42.239.202.227^
 ||42.239.202.229^
@@ -378900,6 +379304,7 @@
 ||42.239.217.21^
 ||42.239.217.228^
 ||42.239.217.56^
+||42.239.218.137^
 ||42.239.218.141^
 ||42.239.218.157^
 ||42.239.218.63^
@@ -381157,6 +381562,7 @@
 ||45.176.108.154^
 ||45.176.108.157^
 ||45.176.108.161^
+||45.176.108.164^
 ||45.176.108.168^
 ||45.176.108.170^
 ||45.176.108.186^
@@ -386293,6 +386699,7 @@
 ||5.39.218.162^
 ||5.39.219.130^
 ||5.39.223.68^
+||5.42.37.74^
 ||5.42.48.223^
 ||5.42.82.17^
 ||5.42.92.195^
@@ -387046,6 +387453,7 @@
 ||58.11.78.109^
 ||58.114.245.23^
 ||58.114.246.26^
+||58.115.108.164^
 ||58.115.160.50^
 ||58.115.162.92^
 ||58.115.166.148^
@@ -387716,6 +388124,7 @@
 ||58.248.116.199^
 ||58.248.116.210^
 ||58.248.116.216^
+||58.248.116.21^
 ||58.248.116.222^
 ||58.248.116.234^
 ||58.248.116.2^
@@ -387745,6 +388154,7 @@
 ||58.248.117.21^
 ||58.248.117.226^
 ||58.248.117.233^
+||58.248.117.238^
 ||58.248.117.244^
 ||58.248.117.253^
 ||58.248.117.41^
@@ -387900,6 +388310,7 @@
 ||58.248.142.111^
 ||58.248.142.116^
 ||58.248.142.11^
+||58.248.142.132^
 ||58.248.142.137^
 ||58.248.142.138^
 ||58.248.142.148^
@@ -387927,6 +388338,7 @@
 ||58.248.142.24^
 ||58.248.142.4^
 ||58.248.142.53^
+||58.248.142.5^
 ||58.248.142.64^
 ||58.248.142.67^
 ||58.248.142.76^
@@ -388058,6 +388470,7 @@
 ||58.248.147.159^
 ||58.248.147.179^
 ||58.248.147.182^
+||58.248.147.196^
 ||58.248.147.208^
 ||58.248.147.224^
 ||58.248.147.226^
@@ -388160,6 +388573,7 @@
 ||58.248.151.248^
 ||58.248.151.25^
 ||58.248.151.2^
+||58.248.151.33^
 ||58.248.151.48^
 ||58.248.151.4^
 ||58.248.151.65^
@@ -388251,6 +388665,7 @@
 ||58.248.74.230^
 ||58.248.74.236^
 ||58.248.74.23^
+||58.248.74.240^
 ||58.248.74.241^
 ||58.248.74.246^
 ||58.248.74.24^
@@ -388932,6 +389347,7 @@
 ||58.249.72.49^
 ||58.249.72.67^
 ||58.249.72.69^
+||58.249.72.88^
 ||58.249.72.95^
 ||58.249.72.98^
 ||58.249.73.102^
@@ -388988,6 +389404,7 @@
 ||58.249.74.222^
 ||58.249.74.227^
 ||58.249.74.235^
+||58.249.74.243^
 ||58.249.74.245^
 ||58.249.74.248^
 ||58.249.74.35^
@@ -389013,6 +389430,7 @@
 ||58.249.75.19^
 ||58.249.75.209^
 ||58.249.75.20^
+||58.249.75.213^
 ||58.249.75.214^
 ||58.249.75.218^
 ||58.249.75.233^
@@ -389185,6 +389603,7 @@
 ||58.249.80.242^
 ||58.249.80.245^
 ||58.249.80.246^
+||58.249.80.25^
 ||58.249.80.37^
 ||58.249.80.38^
 ||58.249.80.46^
@@ -389469,6 +389888,7 @@
 ||58.249.89.134^
 ||58.249.89.143^
 ||58.249.89.157^
+||58.249.89.158^
 ||58.249.89.15^
 ||58.249.89.160^
 ||58.249.89.162^
@@ -389878,6 +390298,7 @@
 ||58.255.140.125^
 ||58.255.140.146^
 ||58.255.140.149^
+||58.255.140.150^
 ||58.255.140.156^
 ||58.255.140.190^
 ||58.255.140.21^
@@ -390453,6 +390874,7 @@
 ||59.127.10.103^
 ||59.127.108.38^
 ||59.127.109.11^
+||59.127.11.50^
 ||59.127.124.161^
 ||59.127.125.164^
 ||59.127.130.170^
@@ -395289,6 +395711,7 @@
 ||59.92.176.202^
 ||59.92.176.209^
 ||59.92.176.218^
+||59.92.176.21^
 ||59.92.176.221^
 ||59.92.176.222^
 ||59.92.176.224^
@@ -395300,6 +395723,7 @@
 ||59.92.176.243^
 ||59.92.176.244^
 ||59.92.176.245^
+||59.92.176.24^
 ||59.92.176.251^
 ||59.92.176.253^
 ||59.92.176.255^
@@ -395312,6 +395736,7 @@
 ||59.92.176.40^
 ||59.92.176.41^
 ||59.92.176.44^
+||59.92.176.45^
 ||59.92.176.47^
 ||59.92.176.55^
 ||59.92.176.56^
@@ -395520,7 +395945,9 @@
 ||59.92.179.119^
 ||59.92.179.11^
 ||59.92.179.123^
+||59.92.179.124^
 ||59.92.179.125^
+||59.92.179.12^
 ||59.92.179.13^
 ||59.92.179.141^
 ||59.92.179.143^
@@ -395592,6 +396019,7 @@
 ||59.92.18.145^
 ||59.92.18.152^
 ||59.92.18.155^
+||59.92.18.156^
 ||59.92.18.159^
 ||59.92.18.161^
 ||59.92.18.170^
@@ -395914,6 +396342,7 @@
 ||59.92.181.221^
 ||59.92.181.222^
 ||59.92.181.223^
+||59.92.181.224^
 ||59.92.181.225^
 ||59.92.181.226^
 ||59.92.181.227^
@@ -396036,6 +396465,7 @@
 ||59.92.182.138^
 ||59.92.182.13^
 ||59.92.182.140^
+||59.92.182.141^
 ||59.92.182.144^
 ||59.92.182.145^
 ||59.92.182.147^
@@ -396400,6 +396830,7 @@
 ||59.92.19.211^
 ||59.92.19.212^
 ||59.92.19.229^
+||59.92.19.230^
 ||59.92.19.235^
 ||59.92.19.244^
 ||59.92.19.246^
@@ -397728,6 +398159,7 @@
 ||59.93.19.98^
 ||59.93.19.99^
 ||59.93.20.0^
+||59.93.20.104^
 ||59.93.20.106^
 ||59.93.20.107^
 ||59.93.20.110^
@@ -397804,6 +398236,7 @@
 ||59.93.21.111^
 ||59.93.21.115^
 ||59.93.21.117^
+||59.93.21.119^
 ||59.93.21.121^
 ||59.93.21.126^
 ||59.93.21.127^
@@ -400770,6 +401203,7 @@
 ||59.96.37.179^
 ||59.96.37.17^
 ||59.96.37.180^
+||59.96.37.181^
 ||59.96.37.182^
 ||59.96.37.183^
 ||59.96.37.185^
@@ -400847,6 +401281,7 @@
 ||59.96.37.34^
 ||59.96.37.35^
 ||59.96.37.37^
+||59.96.37.38^
 ||59.96.37.39^
 ||59.96.37.40^
 ||59.96.37.43^
@@ -401232,6 +401667,7 @@
 ||59.96.39.241^
 ||59.96.39.242^
 ||59.96.39.243^
+||59.96.39.244^
 ||59.96.39.246^
 ||59.96.39.247^
 ||59.96.39.248^
@@ -403664,6 +404100,7 @@
 ||59.99.139.195^
 ||59.99.139.196^
 ||59.99.139.197^
+||59.99.139.19^
 ||59.99.139.200^
 ||59.99.139.203^
 ||59.99.139.205^
@@ -403712,6 +404149,7 @@
 ||59.99.139.64^
 ||59.99.139.66^
 ||59.99.139.68^
+||59.99.139.71^
 ||59.99.139.73^
 ||59.99.139.76^
 ||59.99.139.78^
@@ -404004,6 +404442,7 @@
 ||59.99.142.157^
 ||59.99.142.158^
 ||59.99.142.159^
+||59.99.142.163^
 ||59.99.142.164^
 ||59.99.142.165^
 ||59.99.142.167^
@@ -404105,6 +404544,7 @@
 ||59.99.143.112^
 ||59.99.143.113^
 ||59.99.143.114^
+||59.99.143.115^
 ||59.99.143.117^
 ||59.99.143.119^
 ||59.99.143.11^
@@ -404403,6 +404843,7 @@
 ||59.99.190.179^
 ||59.99.190.182^
 ||59.99.190.187^
+||59.99.190.189^
 ||59.99.190.18^
 ||59.99.190.190^
 ||59.99.190.191^
@@ -405236,6 +405677,7 @@
 ||59.99.44.123^
 ||59.99.44.124^
 ||59.99.44.125^
+||59.99.44.126^
 ||59.99.44.129^
 ||59.99.44.131^
 ||59.99.44.132^
@@ -405429,6 +405871,7 @@
 ||59.99.45.153^
 ||59.99.45.154^
 ||59.99.45.155^
+||59.99.45.156^
 ||59.99.45.158^
 ||59.99.45.15^
 ||59.99.45.160^
@@ -405605,12 +406048,14 @@
 ||59.99.46.167^
 ||59.99.46.168^
 ||59.99.46.16^
+||59.99.46.170^
 ||59.99.46.171^
 ||59.99.46.172^
 ||59.99.46.174^
 ||59.99.46.175^
 ||59.99.46.176^
 ||59.99.46.177^
+||59.99.46.180^
 ||59.99.46.181^
 ||59.99.46.182^
 ||59.99.46.183^
@@ -406563,6 +407008,7 @@
 ||59.99.95.161^
 ||59.99.95.162^
 ||59.99.95.164^
+||59.99.95.166^
 ||59.99.95.167^
 ||59.99.95.168^
 ||59.99.95.169^
@@ -407889,6 +408335,7 @@
 ||60.212.11.156^
 ||60.212.110.19^
 ||60.212.110.3^
+||60.212.111.39^
 ||60.212.117.125^
 ||60.212.117.206^
 ||60.212.117.51^
@@ -408255,6 +408702,7 @@
 ||60.214.217.79^
 ||60.214.217.82^
 ||60.214.217.85^
+||60.214.217.96^
 ||60.214.218.136^
 ||60.214.218.192^
 ||60.214.218.196^
@@ -408347,6 +408795,7 @@
 ||60.214.32.138^
 ||60.214.32.150^
 ||60.214.32.151^
+||60.214.32.17^
 ||60.214.32.236^
 ||60.214.32.243^
 ||60.214.32.244^
@@ -418530,6 +418979,7 @@
 ||61.128.83.148^
 ||61.128.88.38^
 ||61.129.101.57^
+||61.130.195.121^
 ||61.130.195.172^
 ||61.130.198.170^
 ||61.130.224.119^
@@ -421040,6 +421490,7 @@
 ||61.3.151.37^
 ||61.3.151.38^
 ||61.3.151.56^
+||61.3.151.60^
 ||61.3.151.66^
 ||61.3.151.70^
 ||61.3.151.84^
@@ -421315,6 +421766,7 @@
 ||61.52.103.192^
 ||61.52.103.193^
 ||61.52.103.20^
+||61.52.103.217^
 ||61.52.103.21^
 ||61.52.103.220^
 ||61.52.103.228^
@@ -421355,6 +421807,7 @@
 ||61.52.103.91^
 ||61.52.103.93^
 ||61.52.103.99^
+||61.52.109.9^
 ||61.52.11.12^
 ||61.52.11.15^
 ||61.52.11.23^
@@ -421706,6 +422159,7 @@
 ||61.52.166.218^
 ||61.52.167.246^
 ||61.52.167.249^
+||61.52.167.66^
 ||61.52.167.89^
 ||61.52.168.106^
 ||61.52.168.121^
@@ -422545,6 +422999,7 @@
 ||61.52.211.31^
 ||61.52.211.38^
 ||61.52.211.59^
+||61.52.211.61^
 ||61.52.211.75^
 ||61.52.211.76^
 ||61.52.211.77^
@@ -423195,6 +423650,7 @@
 ||61.52.30.159^
 ||61.52.30.160^
 ||61.52.30.161^
+||61.52.30.172^
 ||61.52.30.174^
 ||61.52.30.176^
 ||61.52.30.178^
@@ -423441,6 +423897,7 @@
 ||61.52.4.127^
 ||61.52.4.138^
 ||61.52.4.151^
+||61.52.4.214^
 ||61.52.4.220^
 ||61.52.4.59^
 ||61.52.4.81^
@@ -423494,6 +423951,7 @@
 ||61.52.42.112^
 ||61.52.42.134^
 ||61.52.42.138^
+||61.52.42.174^
 ||61.52.42.192^
 ||61.52.42.196^
 ||61.52.42.206^
@@ -424969,6 +425427,7 @@
 ||61.52.98.214^
 ||61.52.98.215^
 ||61.52.98.220^
+||61.52.98.22^
 ||61.52.98.231^
 ||61.52.98.244^
 ||61.52.98.246^
@@ -429535,6 +429994,7 @@
 ||62.76.5.154^
 ||62.77.210.124^
 ||62.78.131.240^
+||62.78.82.93^
 ||62.80.167.71^
 ||62.80.231.196^
 ||62.80.235.224^
@@ -430369,6 +430829,7 @@
 ||68.183.24.160^
 ||68.183.24.34^
 ||68.183.25.231^
+||68.183.25.71^
 ||68.183.26.100^
 ||68.183.26.166^
 ||68.183.26.74^
@@ -430500,6 +430961,7 @@
 ||68.99.179.195^
 ||68.99.179.89^
 ||68.99.180.30^
+||68468438438.xyz^
 ||68h7.com^
 ||69.10.193.239^
 ||69.10.35.44^
@@ -431555,6 +432017,7 @@
 ||77.43.248.83^
 ||77.43.250.181^
 ||77.43.250.205^
+||77.43.250.246^
 ||77.43.251.170^
 ||77.43.251.196^
 ||77.43.251.77^
@@ -431656,6 +432119,7 @@
 ||77.49.200.235^
 ||77.51.189.86^
 ||77.52.180.138^
+||77.53.144.46^
 ||77.53.145.33^
 ||77.53.2.182^
 ||77.53.246.179^
@@ -437959,6 +438423,7 @@
 ||999.buzz^
 ||999.co.id^
 ||999.rajaojek.com^
+||999080321newfolder1002002131-service1002.space^
 ||999102com.cn^
 ||99bkx.com^
 ||99centsdigitals.com^
@@ -439457,6 +439922,7 @@
 ||adventureexplorer.in^
 ||adventurehr.com^
 ||adventureitdate.com^
+||adventureits.com^
 ||adventuremania.com^
 ||adventurersafaris.com^
 ||adventuresofarchibald.com^
@@ -440485,6 +440951,7 @@
 ||akatanomastos.net^
 ||akatlot.com^
 ||akatsolution.net^
+||akauk09.top^
 ||akaunting.redocom.com^
 ||akawork.io^
 ||akbaara.com^
@@ -440568,6 +441035,7 @@
 ||akowa.projet-test.com^
 ||akowalska.ecrm.pl^
 ||akpeugono.com^
+||akpgi08.top^
 ||akpp-service.top^
 ||akppservis30.ru^
 ||akprokonaija.com^
@@ -452520,6 +452988,7 @@
 ||camelmorocco.com^
 ||camelotbrasil.com^
 ||camelotorganics.com^
+||cameltrektours.com^
 ||camenisch-software.ch^
 ||camera.risami.net^
 ||camera88.vn^
@@ -462541,6 +463010,7 @@
 ||dl-675423.store-downloads.com^
 ||dl-80076342.md-downloads.com^
 ||dl-97674424.md-downloads.com^
+||dl-link.link^
 ||dl-link.live^
 ||dl-link.network^
 ||dl-rw.com^
@@ -464212,6 +464682,7 @@
 ||duckhouse.org^
 ||duckiesplumbing.com.au^
 ||duckpvp.xyz^
+||duckrambo.com^
 ||ducks.org.tw^
 ||ducontcl.esy.es^
 ||ducro.nl^
@@ -471406,6 +471877,7 @@
 ||freedomsec.com.br^
 ||freedomsolutionsuk.co.uk^
 ||freedomtoshine.co^
+||freedomwellnesstherapy.com^
 ||freedownloadbravebrowser.com^
 ||freeeeweb-com.umbler.net^
 ||freeezguru.com^
@@ -479361,6 +479833,7 @@
 ||iappco.ir^
 ||iar.webprojemiz.com^
 ||iarpp.ro^
+||iasdcentralbucaramanga.com^
 ||iasgoogle.com^
 ||iashelpdesk.in^
 ||iasira.dm.files.1drv.com^
@@ -481665,6 +482138,7 @@
 ||investigadoresforenses-abcjuris.com^
 ||investigatorsnorthwest.co.uk^
 ||investime.info^
+||investinae.com^
 ||investingbazar.com^
 ||investingpivot.co.uk^
 ||investinscs.com^
@@ -483888,6 +484362,7 @@
 ||joeundrosky.com^
 ||joezer-online.com^
 ||jofox.nl^
+||jofre.eu^
 ||jogaae.jfoaigh.com^
 ||joghataisalam.ir^
 ||joghatay.ir^
@@ -488332,7 +488807,6 @@
 ||laparoscopysales.com^
 ||lapartenza-khl.com^
 ||lapc.com.pk^
-||lapcare.com^
 ||lapcentervn.xyz^
 ||lapchallenge.co.uk^
 ||lapelimmortelle.com.au^
@@ -489398,7 +489872,6 @@
 ||lglab.co.uk^
 ||lgmi.org.uk^
 ||lgonlinecenter.com^
-||lgpass.com^
 ||lgrp35.vatelstudents.fr^
 ||lgs.ec^
 ||lgservis.net^
@@ -496756,7 +497229,6 @@
 ||mojang.com.br^
 ||mojehaftom.com^
 ||mojewnetrza.pl^
-||mojno--vse.ru^
 ||mojo-studios.co.uk^
 ||mojorockstar.com^
 ||mojstudent.net^
@@ -497283,7 +497755,6 @@
 ||motzadministraties.nl^
 ||mouas.xyz^
 ||mouaysha.com^
-||moufed.com^
 ||moulin-de-la-hunelle.be^
 ||mouni11.xyz^
 ||mounicmadiraju.com^
@@ -498591,6 +499062,7 @@
 ||mytemplate.ro^
 ||mytempucheck.com^
 ||mytest.alessioatzeni.com^
+||mytestingserver.ml^
 ||mytestwp.cf^
 ||mytex.pe^
 ||mythelxis.gr^
@@ -500783,6 +501255,7 @@
 ||no1angelsescort.com^
 ||no1spinningfields.90degrees.digital^
 ||no1websitedesigner.com^
+||no2politics.com^
 ||no70.fun^
 ||noabuseshere.top^
 ||noach.nl^
@@ -502206,6 +502679,7 @@
 ||ol.cognitiononline.in^
 ||olacabattachment.com^
 ||oladi.sulinet.hu^
+||olafyoutrue.xyz^
 ||olahnyomda.hu^
 ||olairdryport.com^
 ||olalekan419.000webhostapp.com^
@@ -503336,6 +503810,7 @@
 ||ostappnp.myjino.ru^
 ||ostaz.ml^
 ||osteklenie-balkonov.tomsk.ru^
+||ostemeda.lt^
 ||osteoliv.com^
 ||osteopatasitgesblog.es^
 ||osteopathin-husum.de^
@@ -505735,6 +506210,7 @@
 ||physicianmedical-legalconsulting.com^
 ||physicscafe.com.sg^
 ||physio-bo.de^
+||physio-svdh.ch^
 ||physio-veda.de^
 ||physionize.com^
 ||physiotherapeutinnen.at^
@@ -509836,6 +510312,7 @@
 ||radiolajee.com^
 ||radioland.eu^
 ||radiolavariada.net^
+||radiolevi.ro^
 ||radiomaismg.com.br^
 ||radiomaxima.cl^
 ||radiomega-hit.com^
@@ -513098,6 +513575,7 @@
 ||s-vrach.com.ua^
 ||s-zone.uz^
 ||s.51shijuan.com^
+||s.lletlee.com^
 ||s.oooooooooo.ga^
 ||s.put.re^
 ||s.thechinesemuslim.com^
@@ -515241,6 +515719,7 @@
 ||seioodsoi.club^
 ||seis.me^
 ||seismophonic.com^
+||seitaiken.net^
 ||seitenstreifen.ch^
 ||seivenco.com^
 ||seiz-ib.de^
@@ -529701,7 +530180,6 @@
 ||url-validation-clients.com^
 ||url.246546.com^
 ||url.57569.fr.snd52.ch^
-||url.sg^
 ||url3.mailanyone.net^
 ||url5459.41southbar.com^
 ||url675.textilmallorca.com^
diff --git a/urlhaus-filter-bind-online.conf b/urlhaus-filter-bind-online.conf
index 6fbfaed4..76ab2b7e 100644
--- a/urlhaus-filter-bind-online.conf
+++ b/urlhaus-filter-bind-online.conf
@@ -1,5 +1,5 @@
 # Title: Online Malicious Domains BIND Blocklist
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -13,11 +13,13 @@ zone "1am.co.nz" { type master; notify no; file "null.zone.file"; };
 zone "20.dbstrony.pl" { type master; notify no; file "null.zone.file"; };
 zone "21robo.com" { type master; notify no; file "null.zone.file"; };
 zone "24.dbstrony.pl" { type master; notify no; file "null.zone.file"; };
+zone "32792.prolocksmithwinterpark.com" { type master; notify no; file "null.zone.file"; };
 zone "360.lcy2zzx.pw" { type master; notify no; file "null.zone.file"; };
 zone "360down7.miiyun.cn" { type master; notify no; file "null.zone.file"; };
+zone "68468438438.xyz" { type master; notify no; file "null.zone.file"; };
 zone "8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com" { type master; notify no; file "null.zone.file"; };
+zone "87du.vip" { type master; notify no; file "null.zone.file"; };
 zone "8poieq.bn.files.1drv.com" { type master; notify no; file "null.zone.file"; };
-zone "99centsdigitals.com" { type master; notify no; file "null.zone.file"; };
 zone "abcd.bg" { type master; notify no; file "null.zone.file"; };
 zone "abclicks.in" { type master; notify no; file "null.zone.file"; };
 zone "abissnet.net" { type master; notify no; file "null.zone.file"; };
@@ -25,6 +27,7 @@ zone "aboveandbelow.com.au" { type master; notify no; file "null.zone.file"; };
 zone "absoftechworld.com" { type master; notify no; file "null.zone.file"; };
 zone "absupplies.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "abyssos.eu" { type master; notify no; file "null.zone.file"; };
+zone "academyshademani.com" { type master; notify no; file "null.zone.file"; };
 zone "acbick.com" { type master; notify no; file "null.zone.file"; };
 zone "accounts.thesmarttechhub.com" { type master; notify no; file "null.zone.file"; };
 zone "aceeprc.com.aceeprc.com" { type master; notify no; file "null.zone.file"; };
@@ -53,7 +56,9 @@ zone "agmcarpetcare.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "aiqtest.com" { type master; notify no; file "null.zone.file"; };
 zone "ajpharmaholding.com" { type master; notify no; file "null.zone.file"; };
 zone "ajstudiollc.com" { type master; notify no; file "null.zone.file"; };
+zone "akauk09.top" { type master; notify no; file "null.zone.file"; };
 zone "akivj07.top" { type master; notify no; file "null.zone.file"; };
+zone "akpgi08.top" { type master; notify no; file "null.zone.file"; };
 zone "al-wahd.com" { type master; notify no; file "null.zone.file"; };
 zone "alasdemariposas.org" { type master; notify no; file "null.zone.file"; };
 zone "alemelektronik.com" { type master; notify no; file "null.zone.file"; };
@@ -87,6 +92,7 @@ zone "api-ms.cobainaja.id" { type master; notify no; file "null.zone.file"; };
 zone "api.cstdevs.com" { type master; notify no; file "null.zone.file"; };
 zone "api.quocbao.biz" { type master; notify no; file "null.zone.file"; };
 zone "api.sampy.io" { type master; notify no; file "null.zone.file"; };
+zone "aplicativoparasindicato.com.br" { type master; notify no; file "null.zone.file"; };
 zone "apoolcondo.com" { type master; notify no; file "null.zone.file"; };
 zone "app.adsensearticle.com" { type master; notify no; file "null.zone.file"; };
 zone "app.explicitsurveys.co.uk" { type master; notify no; file "null.zone.file"; };
@@ -94,7 +100,6 @@ zone "app.prerana.info" { type master; notify no; file "null.zone.file"; };
 zone "apps.saintsoporte.com" { type master; notify no; file "null.zone.file"; };
 zone "aqv.news" { type master; notify no; file "null.zone.file"; };
 zone "areyoulivingwell.com" { type master; notify no; file "null.zone.file"; };
-zone "arsapetrolab.com" { type master; notify no; file "null.zone.file"; };
 zone "artedibujoyarquitectura.com" { type master; notify no; file "null.zone.file"; };
 zone "ask-regard.call-save.biz" { type master; notify no; file "null.zone.file"; };
 zone "atfile.com" { type master; notify no; file "null.zone.file"; };
@@ -105,10 +110,8 @@ zone "attach.66rpg.com" { type master; notify no; file "null.zone.file"; };
 zone "atteuqpotentialunlimited.com" { type master; notify no; file "null.zone.file"; };
 zone "augustair.com" { type master; notify no; file "null.zone.file"; };
 zone "aulist.com" { type master; notify no; file "null.zone.file"; };
-zone "australiafashions.com" { type master; notify no; file "null.zone.file"; };
 zone "automaticrefreshments.com" { type master; notify no; file "null.zone.file"; };
 zone "avadhanagames.com" { type master; notify no; file "null.zone.file"; };
-zone "avissrilanka.com" { type master; notify no; file "null.zone.file"; };
 zone "ayamallah.com" { type master; notify no; file "null.zone.file"; };
 zone "azmeasurement.com" { type master; notify no; file "null.zone.file"; };
 zone "azraktours.com" { type master; notify no; file "null.zone.file"; };
@@ -146,12 +149,12 @@ zone "blog.callensaxen.com" { type master; notify no; file "null.zone.file"; };
 zone "blog.oyinblogs.com" { type master; notify no; file "null.zone.file"; };
 zone "blog.takbelit.com" { type master; notify no; file "null.zone.file"; };
 zone "bmlifestyle.co.uk" { type master; notify no; file "null.zone.file"; };
-zone "bnrbook.com" { type master; notify no; file "null.zone.file"; };
 zone "bnrnews.id" { type master; notify no; file "null.zone.file"; };
 zone "bodenstein.co.za" { type master; notify no; file "null.zone.file"; };
 zone "booksearch.com" { type master; notify no; file "null.zone.file"; };
 zone "bounces.mi-fs.com" { type master; notify no; file "null.zone.file"; };
 zone "bpo.correct.go.th" { type master; notify no; file "null.zone.file"; };
+zone "bradleyinstitute.co.za" { type master; notify no; file "null.zone.file"; };
 zone "brandtrust.com.pk" { type master; notify no; file "null.zone.file"; };
 zone "brendanquine.com" { type master; notify no; file "null.zone.file"; };
 zone "brideofmessiah.com" { type master; notify no; file "null.zone.file"; };
@@ -162,8 +165,6 @@ zone "brightstarshop.com" { type master; notify no; file "null.zone.file"; };
 zone "browardinsurancemiami.solucioneslink.com" { type master; notify no; file "null.zone.file"; };
 zone "bt2.elin.co.za" { type master; notify no; file "null.zone.file"; };
 zone "btdapi.robotake.com" { type master; notify no; file "null.zone.file"; };
-zone "bucrinsuranlceonlines.com" { type master; notify no; file "null.zone.file"; };
-zone "buenavista.co" { type master; notify no; file "null.zone.file"; };
 zone "buigiaphat.com.vn" { type master; notify no; file "null.zone.file"; };
 zone "bullseyemedia.in" { type master; notify no; file "null.zone.file"; };
 zone "busandvanrentalmalaysia.com" { type master; notify no; file "null.zone.file"; };
@@ -188,6 +189,7 @@ zone "cazyacustomfurniture.com" { type master; notify no; file "null.zone.file";
 zone "ccauthority.net" { type master; notify no; file "null.zone.file"; };
 zone "cdaonline.com.ar" { type master; notify no; file "null.zone.file"; };
 zone "cec.asso.ac-amiens.fr" { type master; notify no; file "null.zone.file"; };
+zone "cecra.cl" { type master; notify no; file "null.zone.file"; };
 zone "cellas.sk" { type master; notify no; file "null.zone.file"; };
 zone "cendekiabinaaksara.com" { type master; notify no; file "null.zone.file"; };
 zone "cespol-bote.com.mx" { type master; notify no; file "null.zone.file"; };
@@ -195,8 +197,6 @@ zone "cfs5.tistory.com" { type master; notify no; file "null.zone.file"; };
 zone "ch.rmu.ac.th" { type master; notify no; file "null.zone.file"; };
 zone "changematterscounselling.com" { type master; notify no; file "null.zone.file"; };
 zone "chardhamdodham.com" { type master; notify no; file "null.zone.file"; };
-zone "cheacrilnsurances.com" { type master; notify no; file "null.zone.file"; };
-zone "chealablilitycarinsurances.com" { type master; notify no; file "null.zone.file"; };
 zone "chezalice.co.za" { type master; notify no; file "null.zone.file"; };
 zone "childselect.com" { type master; notify no; file "null.zone.file"; };
 zone "chinhdropfile.myvnc.com" { type master; notify no; file "null.zone.file"; };
@@ -216,11 +216,9 @@ zone "config.cqhbkjzx.com" { type master; notify no; file "null.zone.file"; };
 zone "constructoralyon.com" { type master; notify no; file "null.zone.file"; };
 zone "consulateins.solucioneslink.com" { type master; notify no; file "null.zone.file"; };
 zone "contributeindustry.com" { type master; notify no; file "null.zone.file"; };
-zone "controladoradeplagasmm.com" { type master; notify no; file "null.zone.file"; };
 zone "controleautomacao.com.br" { type master; notify no; file "null.zone.file"; };
 zone "copelandscapes.com" { type master; notify no; file "null.zone.file"; };
 zone "coulsongraphics.com" { type master; notify no; file "null.zone.file"; };
-zone "coutler.newreadermedia.net" { type master; notify no; file "null.zone.file"; };
 zone "covid19.cyberschool.or.id" { type master; notify no; file "null.zone.file"; };
 zone "cr-sq.com" { type master; notify no; file "null.zone.file"; };
 zone "craftnesia.id" { type master; notify no; file "null.zone.file"; };
@@ -272,14 +270,14 @@ zone "despertaresi.com.br" { type master; notify no; file "null.zone.file"; };
 zone "destinymc.co.za" { type master; notify no; file "null.zone.file"; };
 zone "detorre.es" { type master; notify no; file "null.zone.file"; };
 zone "dev-interestingtech.pantheonsite.io" { type master; notify no; file "null.zone.file"; };
-zone "dev.sayse-tienda.com" { type master; notify no; file "null.zone.file"; };
 zone "dev.sebpo.net" { type master; notify no; file "null.zone.file"; };
+zone "dezcom.com" { type master; notify no; file "null.zone.file"; };
 zone "dfcf.91756.cn" { type master; notify no; file "null.zone.file"; };
-zone "dfsfcsfcdsfsdvcfsvcscv.com" { type master; notify no; file "null.zone.file"; };
 zone "diamantenegro.mi-fs.com" { type master; notify no; file "null.zone.file"; };
 zone "dienmayminhhung.com" { type master; notify no; file "null.zone.file"; };
 zone "digilib.dianhusada.ac.id" { type master; notify no; file "null.zone.file"; };
 zone "djking.f3322.net" { type master; notify no; file "null.zone.file"; };
+zone "dl-link.link" { type master; notify no; file "null.zone.file"; };
 zone "dl.1003b.56a.com" { type master; notify no; file "null.zone.file"; };
 zone "dl.198424.com" { type master; notify no; file "null.zone.file"; };
 zone "dl.installcdn-aws.com" { type master; notify no; file "null.zone.file"; };
@@ -302,7 +300,6 @@ zone "dosman.pl" { type master; notify no; file "null.zone.file"; };
 zone "dovberger.com" { type master; notify no; file "null.zone.file"; };
 zone "down.flash-plays.com" { type master; notify no; file "null.zone.file"; };
 zone "down.pcclear.com" { type master; notify no; file "null.zone.file"; };
-zone "down.udashi.com" { type master; notify no; file "null.zone.file"; };
 zone "down.webbora.com" { type master; notify no; file "null.zone.file"; };
 zone "down1.arpun.com" { type master; notify no; file "null.zone.file"; };
 zone "download.caihong.com" { type master; notify no; file "null.zone.file"; };
@@ -322,6 +319,7 @@ zone "drsha.innovativesolutions.mobi" { type master; notify no; file "null.zone.
 zone "dsenterprize.co.za" { type master; notify no; file "null.zone.file"; };
 zone "dsspainting.com" { type master; notify no; file "null.zone.file"; };
 zone "du-wizards.com" { type master; notify no; file "null.zone.file"; };
+zone "duckrambo.com" { type master; notify no; file "null.zone.file"; };
 zone "duque.guantanameratravel.com" { type master; notify no; file "null.zone.file"; };
 zone "dutapp.wisolve.co.za" { type master; notify no; file "null.zone.file"; };
 zone "duvalcharter.dekitout.com" { type master; notify no; file "null.zone.file"; };
@@ -332,7 +330,6 @@ zone "e.sldov.ru" { type master; notify no; file "null.zone.file"; };
 zone "ebruyatkin.com" { type master; notify no; file "null.zone.file"; };
 zone "econews.treegle.org" { type master; notify no; file "null.zone.file"; };
 zone "efficientegroup.com" { type master; notify no; file "null.zone.file"; };
-zone "elliot.newreadermedia.net" { type master; notify no; file "null.zone.file"; };
 zone "en.baoend.com" { type master; notify no; file "null.zone.file"; };
 zone "enc-tech.com" { type master; notify no; file "null.zone.file"; };
 zone "endurotanzania.co.tz" { type master; notify no; file "null.zone.file"; };
@@ -348,7 +345,6 @@ zone "evidencemarketing.ca" { type master; notify no; file "null.zone.file"; };
 zone "exilum.com" { type master; notify no; file "null.zone.file"; };
 zone "exitoalfaomega.co" { type master; notify no; file "null.zone.file"; };
 zone "extrovertoffers.com" { type master; notify no; file "null.zone.file"; };
-zone "f1sol.com" { type master; notify no; file "null.zone.file"; };
 zone "familydentist.site" { type master; notify no; file "null.zone.file"; };
 zone "farmaciasdrogaminas.com.br" { type master; notify no; file "null.zone.file"; };
 zone "fate3.xyz" { type master; notify no; file "null.zone.file"; };
@@ -359,6 +355,7 @@ zone "fi.bonitastores.com" { type master; notify no; file "null.zone.file"; };
 zone "files.martellexpress.us" { type master; notify no; file "null.zone.file"; };
 zone "final.makkahkmcc.com" { type master; notify no; file "null.zone.file"; };
 zone "fineartgallerym.com" { type master; notify no; file "null.zone.file"; };
+zone "fixauto.illumetechnology.com" { type master; notify no; file "null.zone.file"; };
 zone "fkd.derpcity.ru" { type master; notify no; file "null.zone.file"; };
 zone "flintspin.com" { type master; notify no; file "null.zone.file"; };
 zone "flyingbuddhadesign.com" { type master; notify no; file "null.zone.file"; };
@@ -368,7 +365,6 @@ zone "foothills.com.br" { type master; notify no; file "null.zone.file"; };
 zone "footweardirect.elin.co.za" { type master; notify no; file "null.zone.file"; };
 zone "forum.mdb.nu" { type master; notify no; file "null.zone.file"; };
 zone "fotoobjetivo.com" { type master; notify no; file "null.zone.file"; };
-zone "foundationrepairhoustontx.net" { type master; notify no; file "null.zone.file"; };
 zone "foxeps.com.br" { type master; notify no; file "null.zone.file"; };
 zone "freecnetdownload.com" { type master; notify no; file "null.zone.file"; };
 zone "freedombookshop.tickme.lk" { type master; notify no; file "null.zone.file"; };
@@ -390,7 +386,6 @@ zone "ghettohub.co.za" { type master; notify no; file "null.zone.file"; };
 zone "ghislain.dartois.pagesperso-orange.fr" { type master; notify no; file "null.zone.file"; };
 zone "giadungg7.com" { type master; notify no; file "null.zone.file"; };
 zone "giddos.ga" { type master; notify no; file "null.zone.file"; };
-zone "gilliem.com" { type master; notify no; file "null.zone.file"; };
 zone "girotexuniformes.com" { type master; notify no; file "null.zone.file"; };
 zone "giteletropical.com" { type master; notify no; file "null.zone.file"; };
 zone "globaltask.ar" { type master; notify no; file "null.zone.file"; };
@@ -406,6 +401,7 @@ zone "goldcoastoffice365.com.au" { type master; notify no; file "null.zone.file"
 zone "goldcupmortgage.com" { type master; notify no; file "null.zone.file"; };
 zone "golden-memories-funerals.yourpageserver.com" { type master; notify no; file "null.zone.file"; };
 zone "goldmen.in" { type master; notify no; file "null.zone.file"; };
+zone "gracejukes.com" { type master; notify no; file "null.zone.file"; };
 zone "grupoinmare.com" { type master; notify no; file "null.zone.file"; };
 zone "gruposelt.000webhostapp.com" { type master; notify no; file "null.zone.file"; };
 zone "gs.monerorx.com" { type master; notify no; file "null.zone.file"; };
@@ -416,6 +412,7 @@ zone "hagebakken.no" { type master; notify no; file "null.zone.file"; };
 zone "harshraval.in" { type master; notify no; file "null.zone.file"; };
 zone "hd11315.com" { type master; notify no; file "null.zone.file"; };
 zone "hdkamera2003.hu" { type master; notify no; file "null.zone.file"; };
+zone "hdrest.fastlinktz.com" { type master; notify no; file "null.zone.file"; };
 zone "hds.sz4h.com" { type master; notify no; file "null.zone.file"; };
 zone "healthy20.net" { type master; notify no; file "null.zone.file"; };
 zone "heavymaq.cl" { type master; notify no; file "null.zone.file"; };
@@ -436,7 +433,6 @@ zone "hoayeuthuong-my.sharepoint.com" { type master; notify no; file "null.zone.
 zone "homefindersolutions.com" { type master; notify no; file "null.zone.file"; };
 zone "hongluosi.com" { type master; notify no; file "null.zone.file"; };
 zone "hookedupboatclub.com" { type master; notify no; file "null.zone.file"; };
-zone "hostelkielce.com" { type master; notify no; file "null.zone.file"; };
 zone "hostzaa.com" { type master; notify no; file "null.zone.file"; };
 zone "houstonshutters.site" { type master; notify no; file "null.zone.file"; };
 zone "hr2019.vrcom7.com" { type master; notify no; file "null.zone.file"; };
@@ -455,7 +451,6 @@ zone "idvindia.com" { type master; notify no; file "null.zone.file"; };
 zone "iesanjosemonitos.edu.co" { type master; notify no; file "null.zone.file"; };
 zone "ikexpert.com" { type master; notify no; file "null.zone.file"; };
 zone "ilrafrica.com" { type master; notify no; file "null.zone.file"; };
-zone "images.jermiau.com" { type master; notify no; file "null.zone.file"; };
 zone "imbueautoworx.co.za" { type master; notify no; file "null.zone.file"; };
 zone "incodimsa.com" { type master; notify no; file "null.zone.file"; };
 zone "incrediblepixels.com" { type master; notify no; file "null.zone.file"; };
@@ -473,8 +468,10 @@ zone "intersel-idf.org" { type master; notify no; file "null.zone.file"; };
 zone "intuitiveideas.com.my" { type master; notify no; file "null.zone.file"; };
 zone "inversiones.arrayanfinanciero.cl" { type master; notify no; file "null.zone.file"; };
 zone "invest.xpcorporative.com.br" { type master; notify no; file "null.zone.file"; };
+zone "investinae.com" { type master; notify no; file "null.zone.file"; };
 zone "ipmes.ma" { type master; notify no; file "null.zone.file"; };
 zone "iremart.es" { type master; notify no; file "null.zone.file"; };
+zone "iris101.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "isaac.mikhailmotoringschool.com" { type master; notify no; file "null.zone.file"; };
 zone "iscamenabe.com" { type master; notify no; file "null.zone.file"; };
 zone "ismf.com.ng" { type master; notify no; file "null.zone.file"; };
@@ -485,7 +482,6 @@ zone "isso.ps" { type master; notify no; file "null.zone.file"; };
 zone "it123.ru" { type master; notify no; file "null.zone.file"; };
 zone "itc-demo.softgig.co.ke" { type master; notify no; file "null.zone.file"; };
 zone "itconsultus.com.co" { type master; notify no; file "null.zone.file"; };
-zone "jamesjorgensen.newreadermedia.net" { type master; notify no; file "null.zone.file"; };
 zone "jamiekaylive.com" { type master; notify no; file "null.zone.file"; };
 zone "jamshed.pk" { type master; notify no; file "null.zone.file"; };
 zone "jansen-heesch.nl" { type master; notify no; file "null.zone.file"; };
@@ -493,7 +489,6 @@ zone "jathra.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "jay.diamondrelationscrm.us" { type master; notify no; file "null.zone.file"; };
 zone "jebs.net.au" { type master; notify no; file "null.zone.file"; };
 zone "jeffdahlke.com" { type master; notify no; file "null.zone.file"; };
-zone "jewsjuice.com" { type master; notify no; file "null.zone.file"; };
 zone "jhayesconsulting.com" { type master; notify no; file "null.zone.file"; };
 zone "jiaoyuzixun.cn" { type master; notify no; file "null.zone.file"; };
 zone "jing-da.com.tw" { type master; notify no; file "null.zone.file"; };
@@ -508,14 +503,11 @@ zone "josuarochoa.com" { type master; notify no; file "null.zone.file"; };
 zone "jpwoodfordco.com" { type master; notify no; file "null.zone.file"; };
 zone "jumpmanualjacobhiller.com" { type master; notify no; file "null.zone.file"; };
 zone "jupiter.toxsl.in" { type master; notify no; file "null.zone.file"; };
-zone "jurgensen.newreadermedia.net" { type master; notify no; file "null.zone.file"; };
 zone "justinscott.com.au" { type master; notify no; file "null.zone.file"; };
-zone "kaizenjanitorial.com" { type master; notify no; file "null.zone.file"; };
 zone "kalawatihomes.com" { type master; notify no; file "null.zone.file"; };
 zone "kalpataru-elitus-mulund.thakkers.in" { type master; notify no; file "null.zone.file"; };
 zone "karer.by" { type master; notify no; file "null.zone.file"; };
 zone "katanvetov.co.il" { type master; notify no; file "null.zone.file"; };
-zone "kbdom.com" { type master; notify no; file "null.zone.file"; };
 zone "kensingtondriving.com" { type master; notify no; file "null.zone.file"; };
 zone "kevinjewelry.com.co" { type master; notify no; file "null.zone.file"; };
 zone "keywatch.yourpageserver.com" { type master; notify no; file "null.zone.file"; };
@@ -553,7 +545,6 @@ zone "lidoraggiodisole.it" { type master; notify no; file "null.zone.file"; };
 zone "lifebeam.elin.co.za" { type master; notify no; file "null.zone.file"; };
 zone "lindnerelektroanlagen.de" { type master; notify no; file "null.zone.file"; };
 zone "linkintec.cn" { type master; notify no; file "null.zone.file"; };
-zone "litroxlitro.com" { type master; notify no; file "null.zone.file"; };
 zone "livetrack.in" { type master; notify no; file "null.zone.file"; };
 zone "lloydsindian.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "lm.stagingarea.co.za" { type master; notify no; file "null.zone.file"; };
@@ -567,11 +558,8 @@ zone "login.trezor.com.stockfootagesindia.com" { type master; notify no; file "n
 zone "logotypfabriken.se" { type master; notify no; file "null.zone.file"; };
 zone "lotix.de" { type master; notify no; file "null.zone.file"; };
 zone "lotusanddragonfly.com" { type master; notify no; file "null.zone.file"; };
-zone "lp.carrduci.com" { type master; notify no; file "null.zone.file"; };
 zone "lp.definerisco.com" { type master; notify no; file "null.zone.file"; };
 zone "lp.difusodesign.com" { type master; notify no; file "null.zone.file"; };
-zone "lp.juancamilogarciareyes.com" { type master; notify no; file "null.zone.file"; };
-zone "lp.tecnimasdecolombia.com.co" { type master; notify no; file "null.zone.file"; };
 zone "ltc.typoten.com" { type master; notify no; file "null.zone.file"; };
 zone "luckybrownie.com" { type master; notify no; file "null.zone.file"; };
 zone "luminouspneuma.com" { type master; notify no; file "null.zone.file"; };
@@ -601,6 +589,7 @@ zone "masjidhabeebiyarazviya.mysunni.com" { type master; notify no; file "null.z
 zone "materialescantu.com" { type master; notify no; file "null.zone.file"; };
 zone "matruchhaya.co.in" { type master; notify no; file "null.zone.file"; };
 zone "mattysplayground.com" { type master; notify no; file "null.zone.file"; };
+zone "maxiquim.cl" { type master; notify no; file "null.zone.file"; };
 zone "maxtox.com.pk" { type master; notify no; file "null.zone.file"; };
 zone "mbgrm.com" { type master; notify no; file "null.zone.file"; };
 zone "mbsolutions.ge" { type master; notify no; file "null.zone.file"; };
@@ -610,6 +599,7 @@ zone "media-server.skyinternet.com.pk" { type master; notify no; file "null.zone
 zone "mediamaster.co.za" { type master; notify no; file "null.zone.file"; };
 zone "medianews.ge" { type master; notify no; file "null.zone.file"; };
 zone "medistaffconsulting.com" { type master; notify no; file "null.zone.file"; };
+zone "meditreat.itwebservice.in" { type master; notify no; file "null.zone.file"; };
 zone "meeweb.com" { type master; notify no; file "null.zone.file"; };
 zone "megamart.afnan-amc.com" { type master; notify no; file "null.zone.file"; };
 zone "merbay.ru" { type master; notify no; file "null.zone.file"; };
@@ -680,7 +670,6 @@ zone "nidhi.iexist.in" { type master; notify no; file "null.zone.file"; };
 zone "nikanpolimer.ir" { type master; notify no; file "null.zone.file"; };
 zone "nilehouse.co.ug" { type master; notify no; file "null.zone.file"; };
 zone "nilinkeji.com" { type master; notify no; file "null.zone.file"; };
-zone "nisacooks.com" { type master; notify no; file "null.zone.file"; };
 zone "njtiledesigncenter.com" { type master; notify no; file "null.zone.file"; };
 zone "nobius.org" { type master; notify no; file "null.zone.file"; };
 zone "nocalnoodle.elin.co.za" { type master; notify no; file "null.zone.file"; };
@@ -695,7 +684,6 @@ zone "nuwagi.com" { type master; notify no; file "null.zone.file"; };
 zone "nyeh2o.com.au" { type master; notify no; file "null.zone.file"; };
 zone "oakleyandfriends.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "obseques-conseils.com" { type master; notify no; file "null.zone.file"; };
-zone "ocean.tecnasulstore.com.br" { type master; notify no; file "null.zone.file"; };
 zone "ohe.ie" { type master; notify no; file "null.zone.file"; };
 zone "ohsewgorgeous.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "oknoplastik.sk" { type master; notify no; file "null.zone.file"; };
@@ -746,7 +734,6 @@ zone "payerrealty.com" { type master; notify no; file "null.zone.file"; };
 zone "payments.atifsiddiqui.me" { type master; notify no; file "null.zone.file"; };
 zone "pcsoori.com" { type master; notify no; file "null.zone.file"; };
 zone "pd.oceaniarp.net" { type master; notify no; file "null.zone.file"; };
-zone "perpus.onlineman7-jombang.sch.id" { type master; notify no; file "null.zone.file"; };
 zone "perpustekim.untirta.ac.id" { type master; notify no; file "null.zone.file"; };
 zone "petercollie.com" { type master; notify no; file "null.zone.file"; };
 zone "ph4s.ru" { type master; notify no; file "null.zone.file"; };
@@ -767,6 +754,7 @@ zone "posmicrosystems.com" { type master; notify no; file "null.zone.file"; };
 zone "poulman.panagiotopoulos-tours.gr" { type master; notify no; file "null.zone.file"; };
 zone "ppdb.smk-ciptaskill.sch.id" { type master; notify no; file "null.zone.file"; };
 zone "pptvideotemplates.com" { type master; notify no; file "null.zone.file"; };
+zone "prestasicash.com.ar" { type master; notify no; file "null.zone.file"; };
 zone "prestigehomeautomation.net" { type master; notify no; file "null.zone.file"; };
 zone "prishaartcreations.com" { type master; notify no; file "null.zone.file"; };
 zone "production.sparshims.com" { type master; notify no; file "null.zone.file"; };
@@ -780,7 +768,6 @@ zone "prosoc.nl" { type master; notify no; file "null.zone.file"; };
 zone "prosyarmakassar.com" { type master; notify no; file "null.zone.file"; };
 zone "provence.elin.co.za" { type master; notify no; file "null.zone.file"; };
 zone "prueba.danielluza.com" { type master; notify no; file "null.zone.file"; };
-zone "ptpmeccatronica.eu" { type master; notify no; file "null.zone.file"; };
 zone "pujashoppe.in" { type master; notify no; file "null.zone.file"; };
 zone "punchdialogues.com" { type master; notify no; file "null.zone.file"; };
 zone "punjabdevelopersassociation.com.pk" { type master; notify no; file "null.zone.file"; };
@@ -832,7 +819,6 @@ zone "rs-toolkit.mikestclair.org" { type master; notify no; file "null.zone.file
 zone "rsgym.net" { type master; notify no; file "null.zone.file"; };
 zone "rubazar.pro" { type master; notify no; file "null.zone.file"; };
 zone "rubycityvietnam.com" { type master; notify no; file "null.zone.file"; };
-zone "ruch.newreadermedia.net" { type master; notify no; file "null.zone.file"; };
 zone "ruisgood.ru" { type master; notify no; file "null.zone.file"; };
 zone "ruwadalkuwait.com" { type master; notify no; file "null.zone.file"; };
 zone "rydchile.cl" { type master; notify no; file "null.zone.file"; };
@@ -866,6 +852,7 @@ zone "sentierodelviandante.ml" { type master; notify no; file "null.zone.file";
 zone "serendibsourcing.com" { type master; notify no; file "null.zone.file"; };
 zone "servicemhkd.myvnc.com" { type master; notify no; file "null.zone.file"; };
 zone "servicemhkd80.myvnc.com" { type master; notify no; file "null.zone.file"; };
+zone "serviciovirtual.com.ar" { type master; notify no; file "null.zone.file"; };
 zone "seyranikenger.com.tr" { type master; notify no; file "null.zone.file"; };
 zone "sgessy.com.br" { type master; notify no; file "null.zone.file"; };
 zone "shaheentbfoundation.com" { type master; notify no; file "null.zone.file"; };
@@ -880,7 +867,6 @@ zone "shop.goldspot.agency" { type master; notify no; file "null.zone.file"; };
 zone "shopsofe.com" { type master; notify no; file "null.zone.file"; };
 zone "shrushtiinfotech.com" { type master; notify no; file "null.zone.file"; };
 zone "sibernetix.fr" { type master; notify no; file "null.zone.file"; };
-zone "siddharthpanditpautra.com" { type master; notify no; file "null.zone.file"; };
 zone "sige.brisainformatica.com.br" { type master; notify no; file "null.zone.file"; };
 zone "signatureads.co.in" { type master; notify no; file "null.zone.file"; };
 zone "siili.net" { type master; notify no; file "null.zone.file"; };
@@ -931,7 +917,8 @@ zone "static.3001.net" { type master; notify no; file "null.zone.file"; };
 zone "statsres.com" { type master; notify no; file "null.zone.file"; };
 zone "statssound.com" { type master; notify no; file "null.zone.file"; };
 zone "statsspot.com" { type master; notify no; file "null.zone.file"; };
-zone "stattilion.bar" { type master; notify no; file "null.zone.file"; };
+zone "statsvilla.com" { type master; notify no; file "null.zone.file"; };
+zone "stemschool.net" { type master; notify no; file "null.zone.file"; };
 zone "stiepancasetia.ac.id" { type master; notify no; file "null.zone.file"; };
 zone "stott-thompson.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "stratexec.co.za" { type master; notify no; file "null.zone.file"; };
@@ -943,13 +930,13 @@ zone "sunmarkholidays.com" { type master; notify no; file "null.zone.file"; };
 zone "supermercadostia.com" { type master; notify no; file "null.zone.file"; };
 zone "support-4-free.com" { type master; notify no; file "null.zone.file"; };
 zone "support.clz.kr" { type master; notify no; file "null.zone.file"; };
+zone "supportit.online" { type master; notify no; file "null.zone.file"; };
 zone "sw.yourpageserver.com" { type master; notify no; file "null.zone.file"; };
 zone "sweaty.dk" { type master; notify no; file "null.zone.file"; };
 zone "sweet-diet.com" { type master; notify no; file "null.zone.file"; };
 zone "swentsai.com" { type master; notify no; file "null.zone.file"; };
 zone "swiftlogisticseg.com" { type master; notify no; file "null.zone.file"; };
 zone "swwbia.com" { type master; notify no; file "null.zone.file"; };
-zone "syedpro.dezinetimes.com" { type master; notify no; file "null.zone.file"; };
 zone "syracusecoffee.com" { type master; notify no; file "null.zone.file"; };
 zone "sys.pbmadu.co.id" { type master; notify no; file "null.zone.file"; };
 zone "sytraders.co" { type master; notify no; file "null.zone.file"; };
@@ -963,6 +950,7 @@ zone "taltus.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "tapalkoedacoffee.com" { type master; notify no; file "null.zone.file"; };
 zone "tarravalleyfoods.com.au" { type master; notify no; file "null.zone.file"; };
 zone "taurus.ug" { type master; notify no; file "null.zone.file"; };
+zone "tavo.cl" { type master; notify no; file "null.zone.file"; };
 zone "taxicabsrilanka.com" { type master; notify no; file "null.zone.file"; };
 zone "taxpos.com" { type master; notify no; file "null.zone.file"; };
 zone "tc.snpsresidential.com" { type master; notify no; file "null.zone.file"; };
@@ -983,6 +971,7 @@ zone "test.adventser.com" { type master; notify no; file "null.zone.file"; };
 zone "test.letraele.es" { type master; notify no; file "null.zone.file"; };
 zone "test.typoten.com" { type master; notify no; file "null.zone.file"; };
 zone "test.wanepghana.org" { type master; notify no; file "null.zone.file"; };
+zone "test1.asistencia247.com" { type master; notify no; file "null.zone.file"; };
 zone "test1.milenial.id" { type master; notify no; file "null.zone.file"; };
 zone "test1.tenplusone.my" { type master; notify no; file "null.zone.file"; };
 zone "test2.basis-web.com" { type master; notify no; file "null.zone.file"; };
@@ -1049,7 +1038,7 @@ zone "uniengrisb.com" { type master; notify no; file "null.zone.file"; };
 zone "unisoftcc.com" { type master; notify no; file "null.zone.file"; };
 zone "unyazitelecom.com" { type master; notify no; file "null.zone.file"; };
 zone "upcbpta.com" { type master; notify no; file "null.zone.file"; };
-zone "urbane.dezinetimes.com" { type master; notify no; file "null.zone.file"; };
+zone "urbantrapfest.cl" { type master; notify no; file "null.zone.file"; };
 zone "useformoney.000webhostapp.com" { type master; notify no; file "null.zone.file"; };
 zone "usmadetshirts.com" { type master; notify no; file "null.zone.file"; };
 zone "uss.ac.th" { type master; notify no; file "null.zone.file"; };
@@ -1058,7 +1047,6 @@ zone "vbcargo.hu" { type master; notify no; file "null.zone.file"; };
 zone "vcah.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "vegadelcasero.cl" { type master; notify no; file "null.zone.file"; };
 zone "vendas.lidiacarmeli.com.br" { type master; notify no; file "null.zone.file"; };
-zone "verify.aicosoft.com" { type master; notify no; file "null.zone.file"; };
 zone "vfocus.net" { type master; notify no; file "null.zone.file"; };
 zone "vidmattic.com" { type master; notify no; file "null.zone.file"; };
 zone "vienen.gblix.srv.br" { type master; notify no; file "null.zone.file"; };
@@ -1076,6 +1064,7 @@ zone "vladimirinternational.com" { type master; notify no; file "null.zone.file"
 zone "vokasi.ub.ac.id" { type master; notify no; file "null.zone.file"; };
 zone "vologroup.com.br" { type master; notify no; file "null.zone.file"; };
 zone "voteyouramerica.dekitout.com" { type master; notify no; file "null.zone.file"; };
+zone "vpinversiones.cl" { type master; notify no; file "null.zone.file"; };
 zone "vstsample.com" { type master; notify no; file "null.zone.file"; };
 zone "vtube.fadlymotivator.com" { type master; notify no; file "null.zone.file"; };
 zone "vvsskmodinationalschool.com" { type master; notify no; file "null.zone.file"; };
@@ -1130,6 +1119,5 @@ zone "yp.hnggzyjy.cn" { type master; notify no; file "null.zone.file"; };
 zone "yskadvisors.com" { type master; notify no; file "null.zone.file"; };
 zone "yummyyogaudaipur.com" { type master; notify no; file "null.zone.file"; };
 zone "yzkzixun.com" { type master; notify no; file "null.zone.file"; };
-zone "zakra.tecnasulstore.com.br" { type master; notify no; file "null.zone.file"; };
 zone "zytrox.tk" { type master; notify no; file "null.zone.file"; };
 zone "zz.690tx.com" { type master; notify no; file "null.zone.file"; };
diff --git a/urlhaus-filter-bind.conf b/urlhaus-filter-bind.conf
index da83acbf..235f561e 100644
--- a/urlhaus-filter-bind.conf
+++ b/urlhaus-filter-bind.conf
@@ -1,5 +1,5 @@
 # Title: Malicious Domains BIND Blocklist
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1453,6 +1453,7 @@ zone "6735a55d.ngrok.io" { type master; notify no; file "null.zone.file"; };
 zone "67373.vip" { type master; notify no; file "null.zone.file"; };
 zone "67lget9865181258.freebackup.fun" { type master; notify no; file "null.zone.file"; };
 zone "67ms.top" { type master; notify no; file "null.zone.file"; };
+zone "68468438438.xyz" { type master; notify no; file "null.zone.file"; };
 zone "68h7.com" { type master; notify no; file "null.zone.file"; };
 zone "695c0lock1.com" { type master; notify no; file "null.zone.file"; };
 zone "69market2.com" { type master; notify no; file "null.zone.file"; };
@@ -1775,6 +1776,7 @@ zone "998awol.com" { type master; notify no; file "null.zone.file"; };
 zone "999.buzz" { type master; notify no; file "null.zone.file"; };
 zone "999.co.id" { type master; notify no; file "null.zone.file"; };
 zone "999.rajaojek.com" { type master; notify no; file "null.zone.file"; };
+zone "999080321newfolder1002002131-service1002.space" { type master; notify no; file "null.zone.file"; };
 zone "999102com.cn" { type master; notify no; file "null.zone.file"; };
 zone "99bkx.com" { type master; notify no; file "null.zone.file"; };
 zone "99centsdigitals.com" { type master; notify no; file "null.zone.file"; };
@@ -3272,6 +3274,7 @@ zone "adventuredsocks.com" { type master; notify no; file "null.zone.file"; };
 zone "adventureexplorer.in" { type master; notify no; file "null.zone.file"; };
 zone "adventurehr.com" { type master; notify no; file "null.zone.file"; };
 zone "adventureitdate.com" { type master; notify no; file "null.zone.file"; };
+zone "adventureits.com" { type master; notify no; file "null.zone.file"; };
 zone "adventuremania.com" { type master; notify no; file "null.zone.file"; };
 zone "adventurersafaris.com" { type master; notify no; file "null.zone.file"; };
 zone "adventuresofarchibald.com" { type master; notify no; file "null.zone.file"; };
@@ -4300,6 +4303,7 @@ zone "akasyahediyelik.com" { type master; notify no; file "null.zone.file"; };
 zone "akatanomastos.net" { type master; notify no; file "null.zone.file"; };
 zone "akatlot.com" { type master; notify no; file "null.zone.file"; };
 zone "akatsolution.net" { type master; notify no; file "null.zone.file"; };
+zone "akauk09.top" { type master; notify no; file "null.zone.file"; };
 zone "akaunting.redocom.com" { type master; notify no; file "null.zone.file"; };
 zone "akawork.io" { type master; notify no; file "null.zone.file"; };
 zone "akbaara.com" { type master; notify no; file "null.zone.file"; };
@@ -4383,6 +4387,7 @@ zone "akouzelis-patra.gr" { type master; notify no; file "null.zone.file"; };
 zone "akowa.projet-test.com" { type master; notify no; file "null.zone.file"; };
 zone "akowalska.ecrm.pl" { type master; notify no; file "null.zone.file"; };
 zone "akpeugono.com" { type master; notify no; file "null.zone.file"; };
+zone "akpgi08.top" { type master; notify no; file "null.zone.file"; };
 zone "akpp-service.top" { type master; notify no; file "null.zone.file"; };
 zone "akppservis30.ru" { type master; notify no; file "null.zone.file"; };
 zone "akprokonaija.com" { type master; notify no; file "null.zone.file"; };
@@ -16335,6 +16340,7 @@ zone "camelliia.com" { type master; notify no; file "null.zone.file"; };
 zone "camelmorocco.com" { type master; notify no; file "null.zone.file"; };
 zone "camelotbrasil.com" { type master; notify no; file "null.zone.file"; };
 zone "camelotorganics.com" { type master; notify no; file "null.zone.file"; };
+zone "cameltrektours.com" { type master; notify no; file "null.zone.file"; };
 zone "camenisch-software.ch" { type master; notify no; file "null.zone.file"; };
 zone "camera.risami.net" { type master; notify no; file "null.zone.file"; };
 zone "camera88.vn" { type master; notify no; file "null.zone.file"; };
@@ -26356,6 +26362,7 @@ zone "dl-45538429.onedrives-en-live.com" { type master; notify no; file "null.zo
 zone "dl-675423.store-downloads.com" { type master; notify no; file "null.zone.file"; };
 zone "dl-80076342.md-downloads.com" { type master; notify no; file "null.zone.file"; };
 zone "dl-97674424.md-downloads.com" { type master; notify no; file "null.zone.file"; };
+zone "dl-link.link" { type master; notify no; file "null.zone.file"; };
 zone "dl-link.live" { type master; notify no; file "null.zone.file"; };
 zone "dl-link.network" { type master; notify no; file "null.zone.file"; };
 zone "dl-rw.com" { type master; notify no; file "null.zone.file"; };
@@ -28027,6 +28034,7 @@ zone "duck.org" { type master; notify no; file "null.zone.file"; };
 zone "duckhouse.org" { type master; notify no; file "null.zone.file"; };
 zone "duckiesplumbing.com.au" { type master; notify no; file "null.zone.file"; };
 zone "duckpvp.xyz" { type master; notify no; file "null.zone.file"; };
+zone "duckrambo.com" { type master; notify no; file "null.zone.file"; };
 zone "ducks.org.tw" { type master; notify no; file "null.zone.file"; };
 zone "ducontcl.esy.es" { type master; notify no; file "null.zone.file"; };
 zone "ducro.nl" { type master; notify no; file "null.zone.file"; };
@@ -35221,6 +35229,7 @@ zone "freedomlifestyleprogram.com" { type master; notify no; file "null.zone.fil
 zone "freedomsec.com.br" { type master; notify no; file "null.zone.file"; };
 zone "freedomsolutionsuk.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "freedomtoshine.co" { type master; notify no; file "null.zone.file"; };
+zone "freedomwellnesstherapy.com" { type master; notify no; file "null.zone.file"; };
 zone "freedownloadbravebrowser.com" { type master; notify no; file "null.zone.file"; };
 zone "freeeeweb-com.umbler.net" { type master; notify no; file "null.zone.file"; };
 zone "freeezguru.com" { type master; notify no; file "null.zone.file"; };
@@ -43176,6 +43185,7 @@ zone "iapp-hml.adttemp.com.br" { type master; notify no; file "null.zone.file";
 zone "iappco.ir" { type master; notify no; file "null.zone.file"; };
 zone "iar.webprojemiz.com" { type master; notify no; file "null.zone.file"; };
 zone "iarpp.ro" { type master; notify no; file "null.zone.file"; };
+zone "iasdcentralbucaramanga.com" { type master; notify no; file "null.zone.file"; };
 zone "iasgoogle.com" { type master; notify no; file "null.zone.file"; };
 zone "iashelpdesk.in" { type master; notify no; file "null.zone.file"; };
 zone "iasira.dm.files.1drv.com" { type master; notify no; file "null.zone.file"; };
@@ -45480,6 +45490,7 @@ zone "investicon.in" { type master; notify no; file "null.zone.file"; };
 zone "investigadoresforenses-abcjuris.com" { type master; notify no; file "null.zone.file"; };
 zone "investigatorsnorthwest.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "investime.info" { type master; notify no; file "null.zone.file"; };
+zone "investinae.com" { type master; notify no; file "null.zone.file"; };
 zone "investingbazar.com" { type master; notify no; file "null.zone.file"; };
 zone "investingpivot.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "investinscs.com" { type master; notify no; file "null.zone.file"; };
@@ -47703,6 +47714,7 @@ zone "joespoolandspaservice.com" { type master; notify no; file "null.zone.file"
 zone "joeundrosky.com" { type master; notify no; file "null.zone.file"; };
 zone "joezer-online.com" { type master; notify no; file "null.zone.file"; };
 zone "jofox.nl" { type master; notify no; file "null.zone.file"; };
+zone "jofre.eu" { type master; notify no; file "null.zone.file"; };
 zone "jogaae.jfoaigh.com" { type master; notify no; file "null.zone.file"; };
 zone "joghataisalam.ir" { type master; notify no; file "null.zone.file"; };
 zone "joghatay.ir" { type master; notify no; file "null.zone.file"; };
@@ -52147,7 +52159,6 @@ zone "laparomc.com" { type master; notify no; file "null.zone.file"; };
 zone "laparoscopysales.com" { type master; notify no; file "null.zone.file"; };
 zone "lapartenza-khl.com" { type master; notify no; file "null.zone.file"; };
 zone "lapc.com.pk" { type master; notify no; file "null.zone.file"; };
-zone "lapcare.com" { type master; notify no; file "null.zone.file"; };
 zone "lapcentervn.xyz" { type master; notify no; file "null.zone.file"; };
 zone "lapchallenge.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "lapelimmortelle.com.au" { type master; notify no; file "null.zone.file"; };
@@ -53213,7 +53224,6 @@ zone "lgjmcaz.cn" { type master; notify no; file "null.zone.file"; };
 zone "lglab.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "lgmi.org.uk" { type master; notify no; file "null.zone.file"; };
 zone "lgonlinecenter.com" { type master; notify no; file "null.zone.file"; };
-zone "lgpass.com" { type master; notify no; file "null.zone.file"; };
 zone "lgrp35.vatelstudents.fr" { type master; notify no; file "null.zone.file"; };
 zone "lgs.ec" { type master; notify no; file "null.zone.file"; };
 zone "lgservis.net" { type master; notify no; file "null.zone.file"; };
@@ -60571,7 +60581,6 @@ zone "moitruongtunglam.com" { type master; notify no; file "null.zone.file"; };
 zone "mojang.com.br" { type master; notify no; file "null.zone.file"; };
 zone "mojehaftom.com" { type master; notify no; file "null.zone.file"; };
 zone "mojewnetrza.pl" { type master; notify no; file "null.zone.file"; };
-zone "mojno--vse.ru" { type master; notify no; file "null.zone.file"; };
 zone "mojo-studios.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "mojorockstar.com" { type master; notify no; file "null.zone.file"; };
 zone "mojstudent.net" { type master; notify no; file "null.zone.file"; };
@@ -61098,7 +61107,6 @@ zone "motus.co.rs" { type master; notify no; file "null.zone.file"; };
 zone "motzadministraties.nl" { type master; notify no; file "null.zone.file"; };
 zone "mouas.xyz" { type master; notify no; file "null.zone.file"; };
 zone "mouaysha.com" { type master; notify no; file "null.zone.file"; };
-zone "moufed.com" { type master; notify no; file "null.zone.file"; };
 zone "moulin-de-la-hunelle.be" { type master; notify no; file "null.zone.file"; };
 zone "mouni11.xyz" { type master; notify no; file "null.zone.file"; };
 zone "mounicmadiraju.com" { type master; notify no; file "null.zone.file"; };
@@ -62406,6 +62414,7 @@ zone "mytelegramapi.ml" { type master; notify no; file "null.zone.file"; };
 zone "mytemplate.ro" { type master; notify no; file "null.zone.file"; };
 zone "mytempucheck.com" { type master; notify no; file "null.zone.file"; };
 zone "mytest.alessioatzeni.com" { type master; notify no; file "null.zone.file"; };
+zone "mytestingserver.ml" { type master; notify no; file "null.zone.file"; };
 zone "mytestwp.cf" { type master; notify no; file "null.zone.file"; };
 zone "mytex.pe" { type master; notify no; file "null.zone.file"; };
 zone "mythelxis.gr" { type master; notify no; file "null.zone.file"; };
@@ -64598,6 +64607,7 @@ zone "no18balloonroom.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "no1angelsescort.com" { type master; notify no; file "null.zone.file"; };
 zone "no1spinningfields.90degrees.digital" { type master; notify no; file "null.zone.file"; };
 zone "no1websitedesigner.com" { type master; notify no; file "null.zone.file"; };
+zone "no2politics.com" { type master; notify no; file "null.zone.file"; };
 zone "no70.fun" { type master; notify no; file "null.zone.file"; };
 zone "noabuseshere.top" { type master; notify no; file "null.zone.file"; };
 zone "noach.nl" { type master; notify no; file "null.zone.file"; };
@@ -66021,6 +66031,7 @@ zone "okz.wloclawek.pl" { type master; notify no; file "null.zone.file"; };
 zone "ol.cognitiononline.in" { type master; notify no; file "null.zone.file"; };
 zone "olacabattachment.com" { type master; notify no; file "null.zone.file"; };
 zone "oladi.sulinet.hu" { type master; notify no; file "null.zone.file"; };
+zone "olafyoutrue.xyz" { type master; notify no; file "null.zone.file"; };
 zone "olahnyomda.hu" { type master; notify no; file "null.zone.file"; };
 zone "olairdryport.com" { type master; notify no; file "null.zone.file"; };
 zone "olalekan419.000webhostapp.com" { type master; notify no; file "null.zone.file"; };
@@ -67151,6 +67162,7 @@ zone "ostappapa.ru" { type master; notify no; file "null.zone.file"; };
 zone "ostappnp.myjino.ru" { type master; notify no; file "null.zone.file"; };
 zone "ostaz.ml" { type master; notify no; file "null.zone.file"; };
 zone "osteklenie-balkonov.tomsk.ru" { type master; notify no; file "null.zone.file"; };
+zone "ostemeda.lt" { type master; notify no; file "null.zone.file"; };
 zone "osteoliv.com" { type master; notify no; file "null.zone.file"; };
 zone "osteopatasitgesblog.es" { type master; notify no; file "null.zone.file"; };
 zone "osteopathin-husum.de" { type master; notify no; file "null.zone.file"; };
@@ -69550,6 +69562,7 @@ zone "physicaltrainernearme.com" { type master; notify no; file "null.zone.file"
 zone "physicianmedical-legalconsulting.com" { type master; notify no; file "null.zone.file"; };
 zone "physicscafe.com.sg" { type master; notify no; file "null.zone.file"; };
 zone "physio-bo.de" { type master; notify no; file "null.zone.file"; };
+zone "physio-svdh.ch" { type master; notify no; file "null.zone.file"; };
 zone "physio-veda.de" { type master; notify no; file "null.zone.file"; };
 zone "physionize.com" { type master; notify no; file "null.zone.file"; };
 zone "physiotherapeutinnen.at" { type master; notify no; file "null.zone.file"; };
@@ -73651,6 +73664,7 @@ zone "radioinspiraciontv.com" { type master; notify no; file "null.zone.file"; }
 zone "radiolajee.com" { type master; notify no; file "null.zone.file"; };
 zone "radioland.eu" { type master; notify no; file "null.zone.file"; };
 zone "radiolavariada.net" { type master; notify no; file "null.zone.file"; };
+zone "radiolevi.ro" { type master; notify no; file "null.zone.file"; };
 zone "radiomaismg.com.br" { type master; notify no; file "null.zone.file"; };
 zone "radiomaxima.cl" { type master; notify no; file "null.zone.file"; };
 zone "radiomega-hit.com" { type master; notify no; file "null.zone.file"; };
@@ -76913,6 +76927,7 @@ zone "s-tech.hu" { type master; notify no; file "null.zone.file"; };
 zone "s-vrach.com.ua" { type master; notify no; file "null.zone.file"; };
 zone "s-zone.uz" { type master; notify no; file "null.zone.file"; };
 zone "s.51shijuan.com" { type master; notify no; file "null.zone.file"; };
+zone "s.lletlee.com" { type master; notify no; file "null.zone.file"; };
 zone "s.oooooooooo.ga" { type master; notify no; file "null.zone.file"; };
 zone "s.put.re" { type master; notify no; file "null.zone.file"; };
 zone "s.thechinesemuslim.com" { type master; notify no; file "null.zone.file"; };
@@ -79056,6 +79071,7 @@ zone "seiomon.eu" { type master; notify no; file "null.zone.file"; };
 zone "seioodsoi.club" { type master; notify no; file "null.zone.file"; };
 zone "seis.me" { type master; notify no; file "null.zone.file"; };
 zone "seismophonic.com" { type master; notify no; file "null.zone.file"; };
+zone "seitaiken.net" { type master; notify no; file "null.zone.file"; };
 zone "seitenstreifen.ch" { type master; notify no; file "null.zone.file"; };
 zone "seivenco.com" { type master; notify no; file "null.zone.file"; };
 zone "seiz-ib.de" { type master; notify no; file "null.zone.file"; };
@@ -93513,7 +93529,6 @@ zone "url-update.com" { type master; notify no; file "null.zone.file"; };
 zone "url-validation-clients.com" { type master; notify no; file "null.zone.file"; };
 zone "url.246546.com" { type master; notify no; file "null.zone.file"; };
 zone "url.57569.fr.snd52.ch" { type master; notify no; file "null.zone.file"; };
-zone "url.sg" { type master; notify no; file "null.zone.file"; };
 zone "url3.mailanyone.net" { type master; notify no; file "null.zone.file"; };
 zone "url5459.41southbar.com" { type master; notify no; file "null.zone.file"; };
 zone "url675.textilmallorca.com" { type master; notify no; file "null.zone.file"; };
diff --git a/urlhaus-filter-dnsmasq-online.conf b/urlhaus-filter-dnsmasq-online.conf
index d3d346bb..85621935 100644
--- a/urlhaus-filter-dnsmasq-online.conf
+++ b/urlhaus-filter-dnsmasq-online.conf
@@ -1,5 +1,5 @@
 # Title: Online Malicious Domains dnsmasq Blocklist
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -13,11 +13,13 @@ address=/1am.co.nz/0.0.0.0
 address=/20.dbstrony.pl/0.0.0.0
 address=/21robo.com/0.0.0.0
 address=/24.dbstrony.pl/0.0.0.0
+address=/32792.prolocksmithwinterpark.com/0.0.0.0
 address=/360.lcy2zzx.pw/0.0.0.0
 address=/360down7.miiyun.cn/0.0.0.0
+address=/68468438438.xyz/0.0.0.0
 address=/8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com/0.0.0.0
+address=/87du.vip/0.0.0.0
 address=/8poieq.bn.files.1drv.com/0.0.0.0
-address=/99centsdigitals.com/0.0.0.0
 address=/abcd.bg/0.0.0.0
 address=/abclicks.in/0.0.0.0
 address=/abissnet.net/0.0.0.0
@@ -25,6 +27,7 @@ address=/aboveandbelow.com.au/0.0.0.0
 address=/absoftechworld.com/0.0.0.0
 address=/absupplies.co.uk/0.0.0.0
 address=/abyssos.eu/0.0.0.0
+address=/academyshademani.com/0.0.0.0
 address=/acbick.com/0.0.0.0
 address=/accounts.thesmarttechhub.com/0.0.0.0
 address=/aceeprc.com.aceeprc.com/0.0.0.0
@@ -53,7 +56,9 @@ address=/agmcarpetcare.co.uk/0.0.0.0
 address=/aiqtest.com/0.0.0.0
 address=/ajpharmaholding.com/0.0.0.0
 address=/ajstudiollc.com/0.0.0.0
+address=/akauk09.top/0.0.0.0
 address=/akivj07.top/0.0.0.0
+address=/akpgi08.top/0.0.0.0
 address=/al-wahd.com/0.0.0.0
 address=/alasdemariposas.org/0.0.0.0
 address=/alemelektronik.com/0.0.0.0
@@ -87,6 +92,7 @@ address=/api-ms.cobainaja.id/0.0.0.0
 address=/api.cstdevs.com/0.0.0.0
 address=/api.quocbao.biz/0.0.0.0
 address=/api.sampy.io/0.0.0.0
+address=/aplicativoparasindicato.com.br/0.0.0.0
 address=/apoolcondo.com/0.0.0.0
 address=/app.adsensearticle.com/0.0.0.0
 address=/app.explicitsurveys.co.uk/0.0.0.0
@@ -94,7 +100,6 @@ address=/app.prerana.info/0.0.0.0
 address=/apps.saintsoporte.com/0.0.0.0
 address=/aqv.news/0.0.0.0
 address=/areyoulivingwell.com/0.0.0.0
-address=/arsapetrolab.com/0.0.0.0
 address=/artedibujoyarquitectura.com/0.0.0.0
 address=/ask-regard.call-save.biz/0.0.0.0
 address=/atfile.com/0.0.0.0
@@ -105,10 +110,8 @@ address=/attach.66rpg.com/0.0.0.0
 address=/atteuqpotentialunlimited.com/0.0.0.0
 address=/augustair.com/0.0.0.0
 address=/aulist.com/0.0.0.0
-address=/australiafashions.com/0.0.0.0
 address=/automaticrefreshments.com/0.0.0.0
 address=/avadhanagames.com/0.0.0.0
-address=/avissrilanka.com/0.0.0.0
 address=/ayamallah.com/0.0.0.0
 address=/azmeasurement.com/0.0.0.0
 address=/azraktours.com/0.0.0.0
@@ -146,12 +149,12 @@ address=/blog.callensaxen.com/0.0.0.0
 address=/blog.oyinblogs.com/0.0.0.0
 address=/blog.takbelit.com/0.0.0.0
 address=/bmlifestyle.co.uk/0.0.0.0
-address=/bnrbook.com/0.0.0.0
 address=/bnrnews.id/0.0.0.0
 address=/bodenstein.co.za/0.0.0.0
 address=/booksearch.com/0.0.0.0
 address=/bounces.mi-fs.com/0.0.0.0
 address=/bpo.correct.go.th/0.0.0.0
+address=/bradleyinstitute.co.za/0.0.0.0
 address=/brandtrust.com.pk/0.0.0.0
 address=/brendanquine.com/0.0.0.0
 address=/brideofmessiah.com/0.0.0.0
@@ -162,8 +165,6 @@ address=/brightstarshop.com/0.0.0.0
 address=/browardinsurancemiami.solucioneslink.com/0.0.0.0
 address=/bt2.elin.co.za/0.0.0.0
 address=/btdapi.robotake.com/0.0.0.0
-address=/bucrinsuranlceonlines.com/0.0.0.0
-address=/buenavista.co/0.0.0.0
 address=/buigiaphat.com.vn/0.0.0.0
 address=/bullseyemedia.in/0.0.0.0
 address=/busandvanrentalmalaysia.com/0.0.0.0
@@ -188,6 +189,7 @@ address=/cazyacustomfurniture.com/0.0.0.0
 address=/ccauthority.net/0.0.0.0
 address=/cdaonline.com.ar/0.0.0.0
 address=/cec.asso.ac-amiens.fr/0.0.0.0
+address=/cecra.cl/0.0.0.0
 address=/cellas.sk/0.0.0.0
 address=/cendekiabinaaksara.com/0.0.0.0
 address=/cespol-bote.com.mx/0.0.0.0
@@ -195,8 +197,6 @@ address=/cfs5.tistory.com/0.0.0.0
 address=/ch.rmu.ac.th/0.0.0.0
 address=/changematterscounselling.com/0.0.0.0
 address=/chardhamdodham.com/0.0.0.0
-address=/cheacrilnsurances.com/0.0.0.0
-address=/chealablilitycarinsurances.com/0.0.0.0
 address=/chezalice.co.za/0.0.0.0
 address=/childselect.com/0.0.0.0
 address=/chinhdropfile.myvnc.com/0.0.0.0
@@ -216,11 +216,9 @@ address=/config.cqhbkjzx.com/0.0.0.0
 address=/constructoralyon.com/0.0.0.0
 address=/consulateins.solucioneslink.com/0.0.0.0
 address=/contributeindustry.com/0.0.0.0
-address=/controladoradeplagasmm.com/0.0.0.0
 address=/controleautomacao.com.br/0.0.0.0
 address=/copelandscapes.com/0.0.0.0
 address=/coulsongraphics.com/0.0.0.0
-address=/coutler.newreadermedia.net/0.0.0.0
 address=/covid19.cyberschool.or.id/0.0.0.0
 address=/cr-sq.com/0.0.0.0
 address=/craftnesia.id/0.0.0.0
@@ -272,14 +270,14 @@ address=/despertaresi.com.br/0.0.0.0
 address=/destinymc.co.za/0.0.0.0
 address=/detorre.es/0.0.0.0
 address=/dev-interestingtech.pantheonsite.io/0.0.0.0
-address=/dev.sayse-tienda.com/0.0.0.0
 address=/dev.sebpo.net/0.0.0.0
+address=/dezcom.com/0.0.0.0
 address=/dfcf.91756.cn/0.0.0.0
-address=/dfsfcsfcdsfsdvcfsvcscv.com/0.0.0.0
 address=/diamantenegro.mi-fs.com/0.0.0.0
 address=/dienmayminhhung.com/0.0.0.0
 address=/digilib.dianhusada.ac.id/0.0.0.0
 address=/djking.f3322.net/0.0.0.0
+address=/dl-link.link/0.0.0.0
 address=/dl.1003b.56a.com/0.0.0.0
 address=/dl.198424.com/0.0.0.0
 address=/dl.installcdn-aws.com/0.0.0.0
@@ -302,7 +300,6 @@ address=/dosman.pl/0.0.0.0
 address=/dovberger.com/0.0.0.0
 address=/down.flash-plays.com/0.0.0.0
 address=/down.pcclear.com/0.0.0.0
-address=/down.udashi.com/0.0.0.0
 address=/down.webbora.com/0.0.0.0
 address=/down1.arpun.com/0.0.0.0
 address=/download.caihong.com/0.0.0.0
@@ -322,6 +319,7 @@ address=/drsha.innovativesolutions.mobi/0.0.0.0
 address=/dsenterprize.co.za/0.0.0.0
 address=/dsspainting.com/0.0.0.0
 address=/du-wizards.com/0.0.0.0
+address=/duckrambo.com/0.0.0.0
 address=/duque.guantanameratravel.com/0.0.0.0
 address=/dutapp.wisolve.co.za/0.0.0.0
 address=/duvalcharter.dekitout.com/0.0.0.0
@@ -332,7 +330,6 @@ address=/e.sldov.ru/0.0.0.0
 address=/ebruyatkin.com/0.0.0.0
 address=/econews.treegle.org/0.0.0.0
 address=/efficientegroup.com/0.0.0.0
-address=/elliot.newreadermedia.net/0.0.0.0
 address=/en.baoend.com/0.0.0.0
 address=/enc-tech.com/0.0.0.0
 address=/endurotanzania.co.tz/0.0.0.0
@@ -348,7 +345,6 @@ address=/evidencemarketing.ca/0.0.0.0
 address=/exilum.com/0.0.0.0
 address=/exitoalfaomega.co/0.0.0.0
 address=/extrovertoffers.com/0.0.0.0
-address=/f1sol.com/0.0.0.0
 address=/familydentist.site/0.0.0.0
 address=/farmaciasdrogaminas.com.br/0.0.0.0
 address=/fate3.xyz/0.0.0.0
@@ -359,6 +355,7 @@ address=/fi.bonitastores.com/0.0.0.0
 address=/files.martellexpress.us/0.0.0.0
 address=/final.makkahkmcc.com/0.0.0.0
 address=/fineartgallerym.com/0.0.0.0
+address=/fixauto.illumetechnology.com/0.0.0.0
 address=/fkd.derpcity.ru/0.0.0.0
 address=/flintspin.com/0.0.0.0
 address=/flyingbuddhadesign.com/0.0.0.0
@@ -368,7 +365,6 @@ address=/foothills.com.br/0.0.0.0
 address=/footweardirect.elin.co.za/0.0.0.0
 address=/forum.mdb.nu/0.0.0.0
 address=/fotoobjetivo.com/0.0.0.0
-address=/foundationrepairhoustontx.net/0.0.0.0
 address=/foxeps.com.br/0.0.0.0
 address=/freecnetdownload.com/0.0.0.0
 address=/freedombookshop.tickme.lk/0.0.0.0
@@ -390,7 +386,6 @@ address=/ghettohub.co.za/0.0.0.0
 address=/ghislain.dartois.pagesperso-orange.fr/0.0.0.0
 address=/giadungg7.com/0.0.0.0
 address=/giddos.ga/0.0.0.0
-address=/gilliem.com/0.0.0.0
 address=/girotexuniformes.com/0.0.0.0
 address=/giteletropical.com/0.0.0.0
 address=/globaltask.ar/0.0.0.0
@@ -406,6 +401,7 @@ address=/goldcoastoffice365.com.au/0.0.0.0
 address=/goldcupmortgage.com/0.0.0.0
 address=/golden-memories-funerals.yourpageserver.com/0.0.0.0
 address=/goldmen.in/0.0.0.0
+address=/gracejukes.com/0.0.0.0
 address=/grupoinmare.com/0.0.0.0
 address=/gruposelt.000webhostapp.com/0.0.0.0
 address=/gs.monerorx.com/0.0.0.0
@@ -416,6 +412,7 @@ address=/hagebakken.no/0.0.0.0
 address=/harshraval.in/0.0.0.0
 address=/hd11315.com/0.0.0.0
 address=/hdkamera2003.hu/0.0.0.0
+address=/hdrest.fastlinktz.com/0.0.0.0
 address=/hds.sz4h.com/0.0.0.0
 address=/healthy20.net/0.0.0.0
 address=/heavymaq.cl/0.0.0.0
@@ -436,7 +433,6 @@ address=/hoayeuthuong-my.sharepoint.com/0.0.0.0
 address=/homefindersolutions.com/0.0.0.0
 address=/hongluosi.com/0.0.0.0
 address=/hookedupboatclub.com/0.0.0.0
-address=/hostelkielce.com/0.0.0.0
 address=/hostzaa.com/0.0.0.0
 address=/houstonshutters.site/0.0.0.0
 address=/hr2019.vrcom7.com/0.0.0.0
@@ -455,7 +451,6 @@ address=/idvindia.com/0.0.0.0
 address=/iesanjosemonitos.edu.co/0.0.0.0
 address=/ikexpert.com/0.0.0.0
 address=/ilrafrica.com/0.0.0.0
-address=/images.jermiau.com/0.0.0.0
 address=/imbueautoworx.co.za/0.0.0.0
 address=/incodimsa.com/0.0.0.0
 address=/incrediblepixels.com/0.0.0.0
@@ -473,8 +468,10 @@ address=/intersel-idf.org/0.0.0.0
 address=/intuitiveideas.com.my/0.0.0.0
 address=/inversiones.arrayanfinanciero.cl/0.0.0.0
 address=/invest.xpcorporative.com.br/0.0.0.0
+address=/investinae.com/0.0.0.0
 address=/ipmes.ma/0.0.0.0
 address=/iremart.es/0.0.0.0
+address=/iris101.co.uk/0.0.0.0
 address=/isaac.mikhailmotoringschool.com/0.0.0.0
 address=/iscamenabe.com/0.0.0.0
 address=/ismf.com.ng/0.0.0.0
@@ -485,7 +482,6 @@ address=/isso.ps/0.0.0.0
 address=/it123.ru/0.0.0.0
 address=/itc-demo.softgig.co.ke/0.0.0.0
 address=/itconsultus.com.co/0.0.0.0
-address=/jamesjorgensen.newreadermedia.net/0.0.0.0
 address=/jamiekaylive.com/0.0.0.0
 address=/jamshed.pk/0.0.0.0
 address=/jansen-heesch.nl/0.0.0.0
@@ -493,7 +489,6 @@ address=/jathra.co.uk/0.0.0.0
 address=/jay.diamondrelationscrm.us/0.0.0.0
 address=/jebs.net.au/0.0.0.0
 address=/jeffdahlke.com/0.0.0.0
-address=/jewsjuice.com/0.0.0.0
 address=/jhayesconsulting.com/0.0.0.0
 address=/jiaoyuzixun.cn/0.0.0.0
 address=/jing-da.com.tw/0.0.0.0
@@ -508,14 +503,11 @@ address=/josuarochoa.com/0.0.0.0
 address=/jpwoodfordco.com/0.0.0.0
 address=/jumpmanualjacobhiller.com/0.0.0.0
 address=/jupiter.toxsl.in/0.0.0.0
-address=/jurgensen.newreadermedia.net/0.0.0.0
 address=/justinscott.com.au/0.0.0.0
-address=/kaizenjanitorial.com/0.0.0.0
 address=/kalawatihomes.com/0.0.0.0
 address=/kalpataru-elitus-mulund.thakkers.in/0.0.0.0
 address=/karer.by/0.0.0.0
 address=/katanvetov.co.il/0.0.0.0
-address=/kbdom.com/0.0.0.0
 address=/kensingtondriving.com/0.0.0.0
 address=/kevinjewelry.com.co/0.0.0.0
 address=/keywatch.yourpageserver.com/0.0.0.0
@@ -553,7 +545,6 @@ address=/lidoraggiodisole.it/0.0.0.0
 address=/lifebeam.elin.co.za/0.0.0.0
 address=/lindnerelektroanlagen.de/0.0.0.0
 address=/linkintec.cn/0.0.0.0
-address=/litroxlitro.com/0.0.0.0
 address=/livetrack.in/0.0.0.0
 address=/lloydsindian.co.uk/0.0.0.0
 address=/lm.stagingarea.co.za/0.0.0.0
@@ -567,11 +558,8 @@ address=/login.trezor.com.stockfootagesindia.com/0.0.0.0
 address=/logotypfabriken.se/0.0.0.0
 address=/lotix.de/0.0.0.0
 address=/lotusanddragonfly.com/0.0.0.0
-address=/lp.carrduci.com/0.0.0.0
 address=/lp.definerisco.com/0.0.0.0
 address=/lp.difusodesign.com/0.0.0.0
-address=/lp.juancamilogarciareyes.com/0.0.0.0
-address=/lp.tecnimasdecolombia.com.co/0.0.0.0
 address=/ltc.typoten.com/0.0.0.0
 address=/luckybrownie.com/0.0.0.0
 address=/luminouspneuma.com/0.0.0.0
@@ -601,6 +589,7 @@ address=/masjidhabeebiyarazviya.mysunni.com/0.0.0.0
 address=/materialescantu.com/0.0.0.0
 address=/matruchhaya.co.in/0.0.0.0
 address=/mattysplayground.com/0.0.0.0
+address=/maxiquim.cl/0.0.0.0
 address=/maxtox.com.pk/0.0.0.0
 address=/mbgrm.com/0.0.0.0
 address=/mbsolutions.ge/0.0.0.0
@@ -610,6 +599,7 @@ address=/media-server.skyinternet.com.pk/0.0.0.0
 address=/mediamaster.co.za/0.0.0.0
 address=/medianews.ge/0.0.0.0
 address=/medistaffconsulting.com/0.0.0.0
+address=/meditreat.itwebservice.in/0.0.0.0
 address=/meeweb.com/0.0.0.0
 address=/megamart.afnan-amc.com/0.0.0.0
 address=/merbay.ru/0.0.0.0
@@ -680,7 +670,6 @@ address=/nidhi.iexist.in/0.0.0.0
 address=/nikanpolimer.ir/0.0.0.0
 address=/nilehouse.co.ug/0.0.0.0
 address=/nilinkeji.com/0.0.0.0
-address=/nisacooks.com/0.0.0.0
 address=/njtiledesigncenter.com/0.0.0.0
 address=/nobius.org/0.0.0.0
 address=/nocalnoodle.elin.co.za/0.0.0.0
@@ -695,7 +684,6 @@ address=/nuwagi.com/0.0.0.0
 address=/nyeh2o.com.au/0.0.0.0
 address=/oakleyandfriends.co.uk/0.0.0.0
 address=/obseques-conseils.com/0.0.0.0
-address=/ocean.tecnasulstore.com.br/0.0.0.0
 address=/ohe.ie/0.0.0.0
 address=/ohsewgorgeous.co.uk/0.0.0.0
 address=/oknoplastik.sk/0.0.0.0
@@ -746,7 +734,6 @@ address=/payerrealty.com/0.0.0.0
 address=/payments.atifsiddiqui.me/0.0.0.0
 address=/pcsoori.com/0.0.0.0
 address=/pd.oceaniarp.net/0.0.0.0
-address=/perpus.onlineman7-jombang.sch.id/0.0.0.0
 address=/perpustekim.untirta.ac.id/0.0.0.0
 address=/petercollie.com/0.0.0.0
 address=/ph4s.ru/0.0.0.0
@@ -767,6 +754,7 @@ address=/posmicrosystems.com/0.0.0.0
 address=/poulman.panagiotopoulos-tours.gr/0.0.0.0
 address=/ppdb.smk-ciptaskill.sch.id/0.0.0.0
 address=/pptvideotemplates.com/0.0.0.0
+address=/prestasicash.com.ar/0.0.0.0
 address=/prestigehomeautomation.net/0.0.0.0
 address=/prishaartcreations.com/0.0.0.0
 address=/production.sparshims.com/0.0.0.0
@@ -780,7 +768,6 @@ address=/prosoc.nl/0.0.0.0
 address=/prosyarmakassar.com/0.0.0.0
 address=/provence.elin.co.za/0.0.0.0
 address=/prueba.danielluza.com/0.0.0.0
-address=/ptpmeccatronica.eu/0.0.0.0
 address=/pujashoppe.in/0.0.0.0
 address=/punchdialogues.com/0.0.0.0
 address=/punjabdevelopersassociation.com.pk/0.0.0.0
@@ -832,7 +819,6 @@ address=/rs-toolkit.mikestclair.org/0.0.0.0
 address=/rsgym.net/0.0.0.0
 address=/rubazar.pro/0.0.0.0
 address=/rubycityvietnam.com/0.0.0.0
-address=/ruch.newreadermedia.net/0.0.0.0
 address=/ruisgood.ru/0.0.0.0
 address=/ruwadalkuwait.com/0.0.0.0
 address=/rydchile.cl/0.0.0.0
@@ -866,6 +852,7 @@ address=/sentierodelviandante.ml/0.0.0.0
 address=/serendibsourcing.com/0.0.0.0
 address=/servicemhkd.myvnc.com/0.0.0.0
 address=/servicemhkd80.myvnc.com/0.0.0.0
+address=/serviciovirtual.com.ar/0.0.0.0
 address=/seyranikenger.com.tr/0.0.0.0
 address=/sgessy.com.br/0.0.0.0
 address=/shaheentbfoundation.com/0.0.0.0
@@ -880,7 +867,6 @@ address=/shop.goldspot.agency/0.0.0.0
 address=/shopsofe.com/0.0.0.0
 address=/shrushtiinfotech.com/0.0.0.0
 address=/sibernetix.fr/0.0.0.0
-address=/siddharthpanditpautra.com/0.0.0.0
 address=/sige.brisainformatica.com.br/0.0.0.0
 address=/signatureads.co.in/0.0.0.0
 address=/siili.net/0.0.0.0
@@ -931,7 +917,8 @@ address=/static.3001.net/0.0.0.0
 address=/statsres.com/0.0.0.0
 address=/statssound.com/0.0.0.0
 address=/statsspot.com/0.0.0.0
-address=/stattilion.bar/0.0.0.0
+address=/statsvilla.com/0.0.0.0
+address=/stemschool.net/0.0.0.0
 address=/stiepancasetia.ac.id/0.0.0.0
 address=/stott-thompson.co.uk/0.0.0.0
 address=/stratexec.co.za/0.0.0.0
@@ -943,13 +930,13 @@ address=/sunmarkholidays.com/0.0.0.0
 address=/supermercadostia.com/0.0.0.0
 address=/support-4-free.com/0.0.0.0
 address=/support.clz.kr/0.0.0.0
+address=/supportit.online/0.0.0.0
 address=/sw.yourpageserver.com/0.0.0.0
 address=/sweaty.dk/0.0.0.0
 address=/sweet-diet.com/0.0.0.0
 address=/swentsai.com/0.0.0.0
 address=/swiftlogisticseg.com/0.0.0.0
 address=/swwbia.com/0.0.0.0
-address=/syedpro.dezinetimes.com/0.0.0.0
 address=/syracusecoffee.com/0.0.0.0
 address=/sys.pbmadu.co.id/0.0.0.0
 address=/sytraders.co/0.0.0.0
@@ -963,6 +950,7 @@ address=/taltus.co.uk/0.0.0.0
 address=/tapalkoedacoffee.com/0.0.0.0
 address=/tarravalleyfoods.com.au/0.0.0.0
 address=/taurus.ug/0.0.0.0
+address=/tavo.cl/0.0.0.0
 address=/taxicabsrilanka.com/0.0.0.0
 address=/taxpos.com/0.0.0.0
 address=/tc.snpsresidential.com/0.0.0.0
@@ -983,6 +971,7 @@ address=/test.adventser.com/0.0.0.0
 address=/test.letraele.es/0.0.0.0
 address=/test.typoten.com/0.0.0.0
 address=/test.wanepghana.org/0.0.0.0
+address=/test1.asistencia247.com/0.0.0.0
 address=/test1.milenial.id/0.0.0.0
 address=/test1.tenplusone.my/0.0.0.0
 address=/test2.basis-web.com/0.0.0.0
@@ -1049,7 +1038,7 @@ address=/uniengrisb.com/0.0.0.0
 address=/unisoftcc.com/0.0.0.0
 address=/unyazitelecom.com/0.0.0.0
 address=/upcbpta.com/0.0.0.0
-address=/urbane.dezinetimes.com/0.0.0.0
+address=/urbantrapfest.cl/0.0.0.0
 address=/useformoney.000webhostapp.com/0.0.0.0
 address=/usmadetshirts.com/0.0.0.0
 address=/uss.ac.th/0.0.0.0
@@ -1058,7 +1047,6 @@ address=/vbcargo.hu/0.0.0.0
 address=/vcah.co.uk/0.0.0.0
 address=/vegadelcasero.cl/0.0.0.0
 address=/vendas.lidiacarmeli.com.br/0.0.0.0
-address=/verify.aicosoft.com/0.0.0.0
 address=/vfocus.net/0.0.0.0
 address=/vidmattic.com/0.0.0.0
 address=/vienen.gblix.srv.br/0.0.0.0
@@ -1076,6 +1064,7 @@ address=/vladimirinternational.com/0.0.0.0
 address=/vokasi.ub.ac.id/0.0.0.0
 address=/vologroup.com.br/0.0.0.0
 address=/voteyouramerica.dekitout.com/0.0.0.0
+address=/vpinversiones.cl/0.0.0.0
 address=/vstsample.com/0.0.0.0
 address=/vtube.fadlymotivator.com/0.0.0.0
 address=/vvsskmodinationalschool.com/0.0.0.0
@@ -1130,6 +1119,5 @@ address=/yp.hnggzyjy.cn/0.0.0.0
 address=/yskadvisors.com/0.0.0.0
 address=/yummyyogaudaipur.com/0.0.0.0
 address=/yzkzixun.com/0.0.0.0
-address=/zakra.tecnasulstore.com.br/0.0.0.0
 address=/zytrox.tk/0.0.0.0
 address=/zz.690tx.com/0.0.0.0
diff --git a/urlhaus-filter-dnsmasq.conf b/urlhaus-filter-dnsmasq.conf
index 35a85737..dda3c321 100644
--- a/urlhaus-filter-dnsmasq.conf
+++ b/urlhaus-filter-dnsmasq.conf
@@ -1,5 +1,5 @@
 # Title: Malicious Domains dnsmasq Blocklist
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1453,6 +1453,7 @@ address=/6735a55d.ngrok.io/0.0.0.0
 address=/67373.vip/0.0.0.0
 address=/67lget9865181258.freebackup.fun/0.0.0.0
 address=/67ms.top/0.0.0.0
+address=/68468438438.xyz/0.0.0.0
 address=/68h7.com/0.0.0.0
 address=/695c0lock1.com/0.0.0.0
 address=/69market2.com/0.0.0.0
@@ -1775,6 +1776,7 @@ address=/998awol.com/0.0.0.0
 address=/999.buzz/0.0.0.0
 address=/999.co.id/0.0.0.0
 address=/999.rajaojek.com/0.0.0.0
+address=/999080321newfolder1002002131-service1002.space/0.0.0.0
 address=/999102com.cn/0.0.0.0
 address=/99bkx.com/0.0.0.0
 address=/99centsdigitals.com/0.0.0.0
@@ -3272,6 +3274,7 @@ address=/adventuredsocks.com/0.0.0.0
 address=/adventureexplorer.in/0.0.0.0
 address=/adventurehr.com/0.0.0.0
 address=/adventureitdate.com/0.0.0.0
+address=/adventureits.com/0.0.0.0
 address=/adventuremania.com/0.0.0.0
 address=/adventurersafaris.com/0.0.0.0
 address=/adventuresofarchibald.com/0.0.0.0
@@ -4300,6 +4303,7 @@ address=/akasyahediyelik.com/0.0.0.0
 address=/akatanomastos.net/0.0.0.0
 address=/akatlot.com/0.0.0.0
 address=/akatsolution.net/0.0.0.0
+address=/akauk09.top/0.0.0.0
 address=/akaunting.redocom.com/0.0.0.0
 address=/akawork.io/0.0.0.0
 address=/akbaara.com/0.0.0.0
@@ -4383,6 +4387,7 @@ address=/akouzelis-patra.gr/0.0.0.0
 address=/akowa.projet-test.com/0.0.0.0
 address=/akowalska.ecrm.pl/0.0.0.0
 address=/akpeugono.com/0.0.0.0
+address=/akpgi08.top/0.0.0.0
 address=/akpp-service.top/0.0.0.0
 address=/akppservis30.ru/0.0.0.0
 address=/akprokonaija.com/0.0.0.0
@@ -16335,6 +16340,7 @@ address=/camelliia.com/0.0.0.0
 address=/camelmorocco.com/0.0.0.0
 address=/camelotbrasil.com/0.0.0.0
 address=/camelotorganics.com/0.0.0.0
+address=/cameltrektours.com/0.0.0.0
 address=/camenisch-software.ch/0.0.0.0
 address=/camera.risami.net/0.0.0.0
 address=/camera88.vn/0.0.0.0
@@ -26356,6 +26362,7 @@ address=/dl-45538429.onedrives-en-live.com/0.0.0.0
 address=/dl-675423.store-downloads.com/0.0.0.0
 address=/dl-80076342.md-downloads.com/0.0.0.0
 address=/dl-97674424.md-downloads.com/0.0.0.0
+address=/dl-link.link/0.0.0.0
 address=/dl-link.live/0.0.0.0
 address=/dl-link.network/0.0.0.0
 address=/dl-rw.com/0.0.0.0
@@ -28027,6 +28034,7 @@ address=/duck.org/0.0.0.0
 address=/duckhouse.org/0.0.0.0
 address=/duckiesplumbing.com.au/0.0.0.0
 address=/duckpvp.xyz/0.0.0.0
+address=/duckrambo.com/0.0.0.0
 address=/ducks.org.tw/0.0.0.0
 address=/ducontcl.esy.es/0.0.0.0
 address=/ducro.nl/0.0.0.0
@@ -35221,6 +35229,7 @@ address=/freedomlifestyleprogram.com/0.0.0.0
 address=/freedomsec.com.br/0.0.0.0
 address=/freedomsolutionsuk.co.uk/0.0.0.0
 address=/freedomtoshine.co/0.0.0.0
+address=/freedomwellnesstherapy.com/0.0.0.0
 address=/freedownloadbravebrowser.com/0.0.0.0
 address=/freeeeweb-com.umbler.net/0.0.0.0
 address=/freeezguru.com/0.0.0.0
@@ -43176,6 +43185,7 @@ address=/iapp-hml.adttemp.com.br/0.0.0.0
 address=/iappco.ir/0.0.0.0
 address=/iar.webprojemiz.com/0.0.0.0
 address=/iarpp.ro/0.0.0.0
+address=/iasdcentralbucaramanga.com/0.0.0.0
 address=/iasgoogle.com/0.0.0.0
 address=/iashelpdesk.in/0.0.0.0
 address=/iasira.dm.files.1drv.com/0.0.0.0
@@ -45480,6 +45490,7 @@ address=/investicon.in/0.0.0.0
 address=/investigadoresforenses-abcjuris.com/0.0.0.0
 address=/investigatorsnorthwest.co.uk/0.0.0.0
 address=/investime.info/0.0.0.0
+address=/investinae.com/0.0.0.0
 address=/investingbazar.com/0.0.0.0
 address=/investingpivot.co.uk/0.0.0.0
 address=/investinscs.com/0.0.0.0
@@ -47703,6 +47714,7 @@ address=/joespoolandspaservice.com/0.0.0.0
 address=/joeundrosky.com/0.0.0.0
 address=/joezer-online.com/0.0.0.0
 address=/jofox.nl/0.0.0.0
+address=/jofre.eu/0.0.0.0
 address=/jogaae.jfoaigh.com/0.0.0.0
 address=/joghataisalam.ir/0.0.0.0
 address=/joghatay.ir/0.0.0.0
@@ -52147,7 +52159,6 @@ address=/laparomc.com/0.0.0.0
 address=/laparoscopysales.com/0.0.0.0
 address=/lapartenza-khl.com/0.0.0.0
 address=/lapc.com.pk/0.0.0.0
-address=/lapcare.com/0.0.0.0
 address=/lapcentervn.xyz/0.0.0.0
 address=/lapchallenge.co.uk/0.0.0.0
 address=/lapelimmortelle.com.au/0.0.0.0
@@ -53213,7 +53224,6 @@ address=/lgjmcaz.cn/0.0.0.0
 address=/lglab.co.uk/0.0.0.0
 address=/lgmi.org.uk/0.0.0.0
 address=/lgonlinecenter.com/0.0.0.0
-address=/lgpass.com/0.0.0.0
 address=/lgrp35.vatelstudents.fr/0.0.0.0
 address=/lgs.ec/0.0.0.0
 address=/lgservis.net/0.0.0.0
@@ -60571,7 +60581,6 @@ address=/moitruongtunglam.com/0.0.0.0
 address=/mojang.com.br/0.0.0.0
 address=/mojehaftom.com/0.0.0.0
 address=/mojewnetrza.pl/0.0.0.0
-address=/mojno--vse.ru/0.0.0.0
 address=/mojo-studios.co.uk/0.0.0.0
 address=/mojorockstar.com/0.0.0.0
 address=/mojstudent.net/0.0.0.0
@@ -61098,7 +61107,6 @@ address=/motus.co.rs/0.0.0.0
 address=/motzadministraties.nl/0.0.0.0
 address=/mouas.xyz/0.0.0.0
 address=/mouaysha.com/0.0.0.0
-address=/moufed.com/0.0.0.0
 address=/moulin-de-la-hunelle.be/0.0.0.0
 address=/mouni11.xyz/0.0.0.0
 address=/mounicmadiraju.com/0.0.0.0
@@ -62406,6 +62414,7 @@ address=/mytelegramapi.ml/0.0.0.0
 address=/mytemplate.ro/0.0.0.0
 address=/mytempucheck.com/0.0.0.0
 address=/mytest.alessioatzeni.com/0.0.0.0
+address=/mytestingserver.ml/0.0.0.0
 address=/mytestwp.cf/0.0.0.0
 address=/mytex.pe/0.0.0.0
 address=/mythelxis.gr/0.0.0.0
@@ -64598,6 +64607,7 @@ address=/no18balloonroom.co.uk/0.0.0.0
 address=/no1angelsescort.com/0.0.0.0
 address=/no1spinningfields.90degrees.digital/0.0.0.0
 address=/no1websitedesigner.com/0.0.0.0
+address=/no2politics.com/0.0.0.0
 address=/no70.fun/0.0.0.0
 address=/noabuseshere.top/0.0.0.0
 address=/noach.nl/0.0.0.0
@@ -66021,6 +66031,7 @@ address=/okz.wloclawek.pl/0.0.0.0
 address=/ol.cognitiononline.in/0.0.0.0
 address=/olacabattachment.com/0.0.0.0
 address=/oladi.sulinet.hu/0.0.0.0
+address=/olafyoutrue.xyz/0.0.0.0
 address=/olahnyomda.hu/0.0.0.0
 address=/olairdryport.com/0.0.0.0
 address=/olalekan419.000webhostapp.com/0.0.0.0
@@ -67151,6 +67162,7 @@ address=/ostappapa.ru/0.0.0.0
 address=/ostappnp.myjino.ru/0.0.0.0
 address=/ostaz.ml/0.0.0.0
 address=/osteklenie-balkonov.tomsk.ru/0.0.0.0
+address=/ostemeda.lt/0.0.0.0
 address=/osteoliv.com/0.0.0.0
 address=/osteopatasitgesblog.es/0.0.0.0
 address=/osteopathin-husum.de/0.0.0.0
@@ -69550,6 +69562,7 @@ address=/physicaltrainernearme.com/0.0.0.0
 address=/physicianmedical-legalconsulting.com/0.0.0.0
 address=/physicscafe.com.sg/0.0.0.0
 address=/physio-bo.de/0.0.0.0
+address=/physio-svdh.ch/0.0.0.0
 address=/physio-veda.de/0.0.0.0
 address=/physionize.com/0.0.0.0
 address=/physiotherapeutinnen.at/0.0.0.0
@@ -73651,6 +73664,7 @@ address=/radioinspiraciontv.com/0.0.0.0
 address=/radiolajee.com/0.0.0.0
 address=/radioland.eu/0.0.0.0
 address=/radiolavariada.net/0.0.0.0
+address=/radiolevi.ro/0.0.0.0
 address=/radiomaismg.com.br/0.0.0.0
 address=/radiomaxima.cl/0.0.0.0
 address=/radiomega-hit.com/0.0.0.0
@@ -76913,6 +76927,7 @@ address=/s-tech.hu/0.0.0.0
 address=/s-vrach.com.ua/0.0.0.0
 address=/s-zone.uz/0.0.0.0
 address=/s.51shijuan.com/0.0.0.0
+address=/s.lletlee.com/0.0.0.0
 address=/s.oooooooooo.ga/0.0.0.0
 address=/s.put.re/0.0.0.0
 address=/s.thechinesemuslim.com/0.0.0.0
@@ -79056,6 +79071,7 @@ address=/seiomon.eu/0.0.0.0
 address=/seioodsoi.club/0.0.0.0
 address=/seis.me/0.0.0.0
 address=/seismophonic.com/0.0.0.0
+address=/seitaiken.net/0.0.0.0
 address=/seitenstreifen.ch/0.0.0.0
 address=/seivenco.com/0.0.0.0
 address=/seiz-ib.de/0.0.0.0
@@ -93513,7 +93529,6 @@ address=/url-update.com/0.0.0.0
 address=/url-validation-clients.com/0.0.0.0
 address=/url.246546.com/0.0.0.0
 address=/url.57569.fr.snd52.ch/0.0.0.0
-address=/url.sg/0.0.0.0
 address=/url3.mailanyone.net/0.0.0.0
 address=/url5459.41southbar.com/0.0.0.0
 address=/url675.textilmallorca.com/0.0.0.0
diff --git a/urlhaus-filter-domains-online.txt b/urlhaus-filter-domains-online.txt
index 8138cd33..bb00c61a 100644
--- a/urlhaus-filter-domains-online.txt
+++ b/urlhaus-filter-domains-online.txt
@@ -1,5 +1,5 @@
 # Title: Online Malicious Domains Blocklist
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -7,19 +7,20 @@
 0-24bpautomentes.hu
 0cl.sldov.ru
 1.11.234.99
+1.186.151.219
 1.222.140.251
-1.222.166.69
 1.222.196.60
 1.245.4.163
 1.246.222.107
 1.246.222.109
 1.246.222.113
 1.246.222.127
-1.246.222.134
+1.246.222.14
 1.246.222.153
 1.246.222.16
 1.246.222.165
 1.246.222.228
+1.246.222.232
 1.246.222.234
 1.246.222.237
 1.246.222.245
@@ -33,6 +34,7 @@
 1.246.222.69
 1.246.222.8
 1.246.222.80
+1.246.222.94
 1.246.222.98
 1.246.223.10
 1.246.223.103
@@ -48,9 +50,9 @@
 1.246.223.32
 1.246.223.35
 1.246.223.4
-1.246.223.48
 1.246.223.49
 1.246.223.54
+1.246.223.58
 1.246.223.59
 1.246.223.6
 1.246.223.61
@@ -70,7 +72,6 @@
 100.8.77.4
 1008691.com
 101.108.130.108
-101.109.246.33
 101.16.183.179
 101.16.98.170
 101.229.85.127
@@ -83,35 +84,40 @@
 101.30.38.204
 101.64.119.250
 101.64.161.70
+101.66.81.70
 101.75.157.99
 102.130.115.14
 102.141.240.139
 103.107.113.22
 103.124.104.118
 103.125.218.107
+103.126.35.40
 103.139.89.205
 103.141.138.12
 103.145.13.24
 103.146.174.208
+103.153.92.76
 103.156.221.66
 103.159.155.214
 103.16.145.25
 103.207.1.146
+103.214.191.141
 103.217.215.21
 103.224.200.40
 103.238.228.3
 103.238.228.4
 103.240.249.121
+103.245.49.180
 103.4.117.26
 103.66.78.171
 103.79.112.254
-103.82.145.111
 103.82.98.170
 103.84.240.130
 103.84.240.228
 103.84.241.123
 103.84.241.94
 103.91.245.12
+103.91.245.14
 103.91.245.16
 103.91.245.17
 103.91.245.19
@@ -123,6 +129,9 @@
 103.91.245.36
 103.91.245.41
 103.91.245.46
+103.91.245.49
+103.91.245.54
+103.91.245.58
 103.92.25.90
 103.92.25.95
 104.184.75.123
@@ -155,7 +164,6 @@
 109.124.90.229
 109.233.196.232
 109.235.7.228
-109.248.58.238
 109.86.85.253
 109.95.200.102
 109.95.200.230
@@ -181,14 +189,12 @@
 110.255.101.184
 110.255.167.147
 110.35.145.127
-110.35.208.21
+110.35.209.175
 110.35.221.77
-110.35.223.92
-110.35.225.24
-110.35.233.147
 110.35.235.57
 110.35.4.2
 110fss.net
+111.118.111.207
 111.118.88.61
 111.119.245.114
 111.125.67.125
@@ -228,17 +234,15 @@
 111.38.26.243
 111.38.8.81
 111.61.52.53
-112.105.117.227
-112.111.100.236
 112.111.108.184
 112.111.31.175
 112.122.62.224
-112.123.200.47
+112.122.63.70
 112.132.134.106
 112.132.147.102
 112.159.108.96
+112.167.165.139
 112.170.124.75
-112.170.219.168
 112.170.233.9
 112.186.210.211
 112.186.96.252
@@ -250,10 +254,8 @@
 112.225.52.145
 112.225.82.4
 112.226.118.229
-112.226.176.167
 112.226.195.104
 112.226.202.111
-112.226.205.96
 112.226.67.193
 112.226.92.34
 112.228.180.95
@@ -263,7 +265,6 @@
 112.229.188.28
 112.229.199.19
 112.230.251.85
-112.234.121.107
 112.234.134.244
 112.234.16.252
 112.234.194.178
@@ -293,18 +294,21 @@
 112.242.106.228
 112.242.18.128
 112.242.2.247
+112.242.97.131
 112.243.115.183
 112.245.12.89
+112.245.178.153
 112.245.5.141
 112.245.8.24
 112.246.162.50
 112.246.180.49
 112.247.100.14
-112.247.14.135
+112.247.16.222
 112.247.161.45
 112.247.191.118
 112.247.214.146
 112.247.240.226
+112.247.25.42
 112.247.81.173
 112.247.82.122
 112.248.148.90
@@ -329,6 +333,8 @@
 112.252.239.103
 112.252.245.249
 112.252.46.212
+112.254.128.160
+112.254.188.228
 112.254.208.123
 112.254.32.5
 112.255.127.212
@@ -344,7 +350,6 @@
 112.27.124.113
 112.27.124.117
 112.27.124.119
-112.27.124.120
 112.27.124.122
 112.27.124.124
 112.27.124.127
@@ -356,7 +361,6 @@
 112.27.124.136
 112.27.124.138
 112.27.124.139
-112.27.124.140
 112.27.124.142
 112.27.124.143
 112.27.124.146
@@ -372,6 +376,7 @@
 112.27.124.168
 112.27.124.171
 112.27.124.172
+112.27.124.174
 112.27.124.175
 112.27.124.176
 112.27.124.178
@@ -390,16 +395,19 @@
 112.27.88.116
 112.27.91.212
 112.27.91.247
+112.30.1.133
 112.30.1.149
 112.30.1.150
 112.30.1.158
-112.30.1.159
+112.30.1.164
 112.30.1.168
 112.30.1.177
 112.30.1.178
 112.30.1.181
+112.30.1.182
 112.30.1.188
 112.30.1.190
+112.30.1.194
 112.30.1.197
 112.30.1.211
 112.30.1.219
@@ -414,15 +422,15 @@
 112.30.1.90
 112.30.1.91
 112.30.100.228
-112.30.110.27
 112.30.110.30
 112.30.110.31
+112.30.110.36
 112.30.110.37
 112.30.110.38
 112.30.110.41
 112.30.110.42
 112.30.110.43
-112.30.110.45
+112.30.110.51
 112.30.110.52
 112.30.110.57
 112.30.110.58
@@ -438,6 +446,7 @@
 112.30.4.136
 112.30.4.37
 112.30.4.52
+112.30.4.53
 112.30.4.57
 112.30.4.61
 112.30.4.70
@@ -447,6 +456,7 @@
 112.31.176.16
 112.31.211.135
 112.31.82.160
+112.31.87.98
 112.53.224.79
 112.65.53.175
 112.72.153.37
@@ -455,6 +465,8 @@
 112.72.162.53
 112.72.176.112
 112.72.176.84
+112.72.226.202
+112.72.231.35
 112.78.45.158
 112.80.118.16
 112.80.127.91
@@ -473,31 +485,24 @@
 112.9.140.247
 112.91.219.195
 112.93.29.211
-112.95.80.165
 113.0.74.25
 113.11.95.254
 113.110.204.254
-113.110.243.79
-113.116.150.147
-113.116.176.26
-113.116.44.33
-113.116.89.82
 113.118.13.194
-113.118.133.113
-113.118.250.227
-113.118.6.104
+113.118.159.178
+113.119.37.141
 113.122.238.68
 113.122.59.84
 113.161.58.249
 113.172.250.35
 113.189.243.248
+113.193.29.42
 113.194.133.9
 113.194.135.154
 113.195.163.26
 113.195.166.46
 113.195.168.190
 113.201.219.47
-113.225.171.27
 113.226.42.250
 113.227.128.9
 113.227.169.170
@@ -505,28 +510,22 @@
 113.227.35.229
 113.231.211.131
 113.231.93.142
-113.232.211.182
+113.232.156.157
 113.234.224.130
 113.235.116.209
 113.253.144.141
 113.254.169.251
 113.59.128.133
-113.59.133.16
-113.59.144.42
 113.59.154.21
 113.59.191.47
 113.61.204.205
 113.86.204.13
 113.87.203.239
-113.87.227.222
-113.88.100.120
-113.88.104.194
-113.88.111.36
-113.88.209.47
 113.88.232.36
 113.88.38.232
+113.88.39.21
+113.90.27.218
 113.92.93.208
-114.199.204.37
 114.199.253.235
 114.224.203.128
 114.226.100.56
@@ -537,7 +536,6 @@
 114.229.52.14
 114.234.189.154
 114.235.115.236
-114.30.54.64
 114.79.161.94
 114.79.172.42
 115.165.216.112
@@ -545,45 +543,49 @@
 115.193.83.0
 115.201.38.185
 115.201.98.176
+115.205.197.221
 115.208.97.42
 115.209.234.226
 115.223.159.80
 115.229.250.130
-115.23.88.135
 115.42.47.36
 115.48.163.47
 115.48.179.43
 115.48.188.17
-115.48.200.115
-115.48.49.84
+115.48.201.26
+115.48.41.101
 115.49.124.80
 115.49.158.175
+115.49.24.63
 115.49.36.220
-115.49.43.52
-115.49.80.117
-115.49.96.88
-115.50.15.24
+115.49.79.131
+115.50.1.41
+115.50.168.160
+115.50.171.192
+115.50.175.205
 115.50.19.136
 115.50.20.73
 115.50.206.128
-115.50.226.30
-115.50.228.168
+115.50.211.74
 115.50.238.227
 115.50.239.77
-115.50.240.72
+115.50.242.7
+115.50.247.46
 115.50.61.82
+115.50.79.78
 115.50.91.30
 115.50.96.254
-115.51.104.85
-115.51.106.209
+115.51.7.254
 115.52.17.196
+115.52.172.72
 115.53.200.130
 115.53.224.134
 115.53.234.210
-115.53.238.224
+115.53.58.228
+115.54.113.49
 115.54.123.147
-115.54.70.108
-115.55.105.154
+115.54.158.251
+115.55.127.0
 115.55.144.42
 115.55.145.147
 115.55.157.96
@@ -591,64 +593,67 @@
 115.55.158.250
 115.55.161.38
 115.55.179.168
+115.55.198.105
 115.55.206.35
 115.55.206.78
 115.55.26.94
 115.55.42.200
+115.55.52.17
 115.56.111.63
 115.56.114.17
-115.56.132.61
+115.56.131.150
 115.56.133.96
 115.56.134.79
+115.56.135.255
 115.56.137.48
 115.56.139.122
-115.56.143.241
+115.56.142.45
 115.56.145.102
 115.56.148.22
+115.56.150.149
 115.56.151.65
 115.56.151.68
 115.56.154.147
-115.56.175.2
+115.56.155.50
 115.56.189.162
+115.56.31.11
 115.56.31.54
 115.56.98.205
 115.56.99.235
 115.58.132.199
 115.58.134.143
-115.58.161.17
+115.58.86.217
 115.58.90.143
+115.58.91.65
 115.59.198.69
-115.59.209.196
 115.59.212.193
 115.59.214.107
 115.59.228.237
-115.59.235.229
 115.59.253.202
 115.59.57.171
 115.59.82.123
-115.61.102.110
+115.61.103.197
+115.61.112.159
 115.61.118.201
 115.61.118.90
-115.61.139.74
-115.62.152.207
+115.61.158.98
 115.62.155.83
+115.62.171.143
 115.62.26.39
+115.63.131.173
 115.63.139.175
 115.63.141.147
 115.63.180.149
 115.63.189.77
 115.63.21.130
-115.63.37.6
 115.63.53.188
 115.73.3.11
 115.75.217.79
 115.78.133.146
 115.92.174.231
-115.96.61.246
-115.97.136.10
+115.97.139.32
 116.124.219.2
 116.149.243.14
-116.2.100.221
 116.206.164.46
 116.207.71.237
 116.211.100.26
@@ -656,22 +661,27 @@
 116.212.142.215
 116.30.4.2
 116.30.95.156
-116.72.51.230
-116.73.222.118
-116.75.199.105
-116.75.212.119
+116.72.28.239
+116.73.52.125
+116.74.101.150
+116.74.17.122
+116.75.193.33
+116.75.198.85
+116.75.212.81
 116.76.114.71
+116.9.43.220
 117.11.234.35
 117.12.48.157
 117.156.69.22
-117.192.224.103
-117.192.225.161
-117.192.225.195
-117.192.227.137
-117.194.160.78
-117.194.163.210
-117.194.166.103
-117.194.166.20
+117.194.148.198
+117.194.160.203
+117.194.164.123
+117.194.167.131
+117.196.48.148
+117.196.48.181
+117.196.50.154
+117.196.50.239
+117.196.50.76
 117.20.204.138
 117.20.204.5
 117.20.210.52
@@ -679,43 +689,17 @@
 117.20.243.40
 117.200.76.54
 117.200.76.60
-117.202.67.238
-117.202.67.246
-117.202.67.4
-117.202.70.96
-117.202.71.179
-117.207.5.156
-117.208.134.226
-117.208.134.64
-117.213.11.104
-117.213.14.17
-117.213.14.30
-117.213.14.62
-117.213.15.179
-117.213.43.219
-117.213.44.116
-117.213.46.160
-117.213.47.183
-117.213.8.163
-117.215.248.14
-117.215.251.253
-117.222.160.108
-117.222.162.50
-117.222.164.19
-117.222.164.21
-117.222.169.141
-117.222.172.16
-117.222.174.16
+117.202.67.92
+117.208.132.10
+117.208.132.45
+117.213.44.102
+117.222.161.42
+117.222.164.100
+117.222.164.189
+117.222.173.218
+117.222.175.120
 117.241.64.105
-117.241.67.141
-117.242.208.153
-117.242.208.95
-117.247.200.129
-117.247.202.150
-117.247.203.156
-117.247.204.118
-117.247.204.66
-117.251.60.194
+117.248.62.29
 117.26.235.164
 117.27.10.73
 117.60.204.190
@@ -727,7 +711,8 @@
 117.91.240.50
 117.93.115.242
 117.93.79.40
-118.172.80.79
+118.114.84.237
+118.172.176.41
 118.176.104.35
 118.176.157.64
 118.176.7.132
@@ -749,10 +734,8 @@
 118.250.51.192
 118.42.125.246
 118.43.180.33
-118.68.245.69
 118.70.83.140
 118.75.120.136
-118.75.200.198
 118.75.240.136
 118.75.240.239
 118.75.50.253
@@ -763,23 +746,21 @@
 118.79.218.157
 118.79.50.203
 118.79.58.82
+118.79.96.11
 118.83.79.43
-118.91.24.27
+118.91.41.135
 118.99.179.164
 118.99.183.235
 118.99.239.217
 119.100.40.250
 119.108.251.176
-119.109.34.245
 119.112.22.58
-119.112.27.20
 119.115.247.23
+119.118.150.84
+119.119.176.198
 119.119.52.202
-119.123.125.139
-119.123.216.42
-119.123.218.76
-119.123.221.158
-119.123.237.218
+119.123.173.95
+119.123.175.210
 119.14.143.145
 119.147.213.57
 119.162.109.111
@@ -837,7 +818,6 @@
 119.189.227.244
 119.190.211.99
 119.190.234.181
-119.190.240.238
 119.191.150.85
 119.191.187.206
 119.191.215.221
@@ -849,13 +829,12 @@
 119.251.12.85
 119.251.14.251
 119.56.131.155
+119.56.140.73
 119.56.143.46
 119.56.143.71
-119.56.144.75
 119.56.148.115
 119.56.155.57
 119.56.172.28
-119.56.195.90
 119.96.37.55
 119.96.70.116
 119.99.188.187
@@ -870,6 +849,7 @@
 12.207.39.227
 120.12.153.54
 120.12.212.5
+120.12.231.61
 120.142.222.22
 120.150.213.110
 120.151.248.134
@@ -892,6 +872,7 @@
 120.193.91.201
 120.193.91.202
 120.193.91.204
+120.193.91.205
 120.193.91.207
 120.193.91.208
 120.193.91.212
@@ -913,31 +894,28 @@
 120.5.15.95
 120.50.66.60
 120.50.93.115
+120.57.214.228
 120.57.98.208
 120.6.141.142
+120.6.241.130
 120.6.8.11
 120.69.131.51
 120.7.75.99
 120.7.90.104
 120.83.189.232
 120.85.165.112
-120.85.169.113
-120.85.170.109
-120.85.173.234
 120.85.185.141
-120.85.236.95
+120.85.196.211
+120.85.208.107
 120.85.238.10
-120.85.238.244
 120.9.32.51
 121.100.114.164
 121.100.96.8
 121.121.44.222
 121.123.53.25
 121.127.155.220
-121.136.249.5
 121.141.11.56
 121.15.142.137
-121.151.78.190
 121.159.22.144
 121.17.103.176
 121.170.234.142
@@ -955,32 +933,25 @@
 121.25.101.86
 121.254.43.215
 121.254.76.17
-121.61.101.93
 121.61.102.1
 121.61.107.189
 121.61.97.195
 121.61.98.151
 121.88.99.236
 122.100.150.204
-122.137.52.122
 122.160.147.53
 122.176.44.34
 122.188.86.225
-122.190.19.204
-122.192.190.203
 122.199.66.28
 122.199.72.23
 122.199.79.27
 122.202.37.85
 122.202.41.23
 122.252.199.3
-122.252.250.22
 122.254.183.207
 122.254.29.37
 122.254.33.214
 123.0.240.58
-123.10.131.225
-123.10.41.32
 123.10.83.136
 123.11.11.207
 123.11.4.168
@@ -993,16 +964,19 @@
 123.110.19.248
 123.110.200.98
 123.110.238.188
-123.12.7.82
+123.12.189.247
+123.12.225.70
+123.12.235.159
+123.12.243.85
 123.128.128.205
 123.128.133.91
 123.128.177.161
 123.129.84.36
 123.129.88.123
-123.13.44.60
 123.130.202.8
 123.130.208.52
 123.130.23.110
+123.130.27.19
 123.130.37.182
 123.130.61.210
 123.130.77.225
@@ -1014,16 +988,19 @@
 123.133.98.135
 123.134.14.130
 123.134.50.186
-123.135.157.193
 123.135.39.36
 123.135.71.150
-123.14.172.149
-123.14.86.82
+123.14.127.238
+123.14.173.199
+123.14.249.33
+123.14.34.240
+123.14.37.32
+123.14.50.214
 123.14.93.154
 123.144.211.86
 123.152.42.4
-123.152.43.21
 123.153.80.178
+123.154.116.116
 123.154.236.114
 123.154.94.1
 123.155.118.36
@@ -1060,22 +1037,23 @@
 123.28.217.23
 123.4.11.40
 123.4.166.2
-123.4.176.22
 123.4.177.93
-123.4.193.171
+123.4.194.152
 123.4.209.154
 123.4.241.118
+123.4.45.31
 123.4.76.117
 123.4.83.66
 123.4.85.149
-123.5.123.60
 123.5.143.203
 123.5.146.238
 123.5.190.167
 123.5.5.242
 123.5.8.211
 123.8.56.94
+123.8.71.27
 123.9.194.169
+123.9.240.115
 123.9.245.207
 124.105.105.222
 124.129.162.169
@@ -1087,7 +1065,9 @@
 124.131.130.95
 124.131.131.71
 124.131.136.75
+124.131.137.147
 124.131.151.135
+124.131.24.185
 124.131.26.243
 124.131.26.78
 124.131.41.48
@@ -1111,7 +1091,6 @@
 124.199.56.198
 124.226.24.117
 124.230.174.233
-124.234.6.130
 124.254.254.61
 124.5.92.20
 124.6.0.4
@@ -1119,8 +1098,8 @@
 124.7.254.85
 124.80.46.73
 124.91.237.147
+124.92.135.37
 124.93.94.207
-124.95.17.41
 125.105.219.169
 125.126.69.95
 125.128.28.161
@@ -1131,65 +1110,64 @@
 125.36.148.42
 125.40.1.127
 125.40.113.66
-125.40.160.116
-125.40.17.14
-125.40.237.130
 125.40.25.140
 125.40.65.120
 125.40.73.6
 125.40.74.153
 125.40.75.22
+125.41.141.41
+125.41.164.60
+125.41.185.186
+125.41.196.114
 125.41.208.139
-125.41.244.43
 125.41.6.192
 125.41.7.204
 125.41.74.22
 125.41.96.238
 125.41.96.33
+125.41.97.231
 125.41.97.81
 125.42.107.136
 125.42.124.114
-125.42.98.24
-125.42.98.35
 125.43.112.123
 125.43.112.182
 125.43.133.130
 125.43.167.192
-125.43.2.169
-125.43.21.157
 125.43.215.244
-125.43.26.36
 125.43.33.20
-125.43.37.138
 125.43.53.50
 125.43.53.9
+125.43.6.186
 125.43.60.218
-125.43.73.19
-125.43.92.62
+125.43.63.47
 125.44.10.125
 125.44.107.182
 125.44.175.118
 125.44.198.62
+125.44.208.152
 125.44.212.131
-125.44.243.220
-125.44.31.79
+125.44.227.51
+125.44.70.64
 125.44.8.227
 125.45.153.91
+125.45.43.63
 125.45.55.146
-125.46.138.117
+125.46.166.112
 125.46.166.125
 125.46.205.88
 125.46.206.160
 125.46.217.52
 125.46.241.237
+125.47.125.16
 125.47.241.188
 125.47.245.200
+125.47.248.131
 125.47.250.98
-125.47.252.106
-125.47.254.154
 125.47.254.44
 125.47.28.18
+125.47.38.142
 125.47.45.218
+125.47.47.212
 125.47.57.80
 125.47.91.51
 125.79.192.197
@@ -1202,12 +1180,13 @@
 139.159.226.180
 139.170.173.198
 139.170.174.162
+139.213.97.191
 139.216.102.151
 139.227.46.137
 14.102.17.222
 14.102.97.204
+14.109.126.96
 14.136.80.242
-14.138.109.129
 14.138.109.26
 14.138.8.215
 14.138.8.51
@@ -1225,27 +1204,25 @@
 14.55.29.2
 14.98.184.178
 140.237.30.113
+140.237.30.172
 140.237.5.43
+140.240.151.177
 142.11.216.5
 142.177.56.127
 146.71.79.230
 148.69.108.177
 149.20.176.179
-149.255.15.112
 149.255.15.134
+149.255.15.172
 149.255.15.180
 149.255.15.182
 149.255.15.184
-149.255.15.191
 149.255.15.213
-149.255.15.235
-149.255.15.27
 149.255.15.43
 149.255.15.87
 149.255.15.99
 149.3.124.194
-149.3.36.210
-149.3.85.55
+149.3.73.210
 150.116.207.99
 151.177.163.87
 151.33.230.191
@@ -1258,7 +1235,6 @@
 153.34.135.92
 153.34.23.76
 153.34.29.28
-153.35.111.46
 153.35.27.49
 153.36.126.35
 158.101.165.14
@@ -1269,27 +1245,28 @@
 162.191.205.175
 162.194.28.60
 162.209.98.174
-163.125.125.6
-163.125.157.64
+162.212.203.250
 163.125.18.93
 163.125.193.148
-163.125.195.248
-163.125.200.199
+163.125.200.118
+163.125.200.242
 163.125.202.193
-163.125.202.195
-163.125.202.21
+163.125.202.255
+163.125.202.87
 163.125.203.198
+163.125.203.236
 163.125.204.156
-163.125.204.244
 163.125.204.34
-163.125.207.61
-163.125.243.131
+163.125.206.16
 163.125.255.165
 163.204.208.169
+163.204.211.136
 163.204.211.228
 163.204.211.58
 163.53.206.228
 165.90.16.5
+168.194.146.145
+168.205.223.254
 168.90.204.207
 170.81.238.178
 171.113.36.216
@@ -1303,11 +1280,13 @@
 171.120.125.147
 171.121.6.162
 171.123.134.239
+171.125.122.91
 171.125.242.71
 171.125.30.233
 171.125.30.93
 171.125.64.223
 171.125.65.22
+171.125.65.89
 171.125.75.68
 171.126.70.133
 171.223.72.123
@@ -1321,7 +1300,6 @@
 171.36.249.91
 171.38.145.146
 171.38.148.69
-171.38.217.222
 171.38.219.189
 171.38.223.110
 171.38.223.213
@@ -1353,12 +1331,13 @@
 175.145.200.216
 175.146.17.227
 175.150.168.92
-175.153.144.2
 175.162.137.166
 175.162.195.27
 175.162.69.13
+175.164.61.215
 175.165.90.198
 175.168.139.182
+175.169.13.182
 175.17.90.14
 175.174.93.57
 175.199.33.139
@@ -1375,10 +1354,8 @@
 176.111.174.67
 176.113.161.104
 176.113.161.113
-176.113.161.120
 176.113.161.128
-176.113.161.138
-176.113.161.59
+176.113.161.60
 176.113.161.65
 176.113.161.66
 176.113.161.76
@@ -1392,37 +1369,36 @@
 176.123.7.127
 176.123.9.243
 176.124.7.225
+176.221.251.238
 176.240.40.142
 176.240.84.106
 177.11.92.78
 177.131.226.235
 177.229.64.218
-177.44.61.243
-177.86.235.143
+177.54.82.154
 178.124.182.187
-178.141.125.98
+178.134.185.112
 178.141.25.82
+178.141.44.152
 178.141.45.2
 178.141.57.166
 178.150.174.65
 178.151.143.2
 178.165.122.141
 178.175.0.140
-178.175.0.42
-178.175.0.47
 178.175.1.139
-178.175.1.143
 178.175.1.153
+178.175.1.176
 178.175.1.182
-178.175.1.224
 178.175.1.244
-178.175.1.247
 178.175.1.249
 178.175.1.250
 178.175.1.252
+178.175.1.44
 178.175.1.80
-178.175.1.99
-178.175.10.102
+178.175.10.104
+178.175.10.121
+178.175.10.178
 178.175.10.34
 178.175.10.42
 178.175.10.71
@@ -1430,118 +1406,117 @@
 178.175.100.110
 178.175.100.129
 178.175.100.180
-178.175.100.187
-178.175.100.190
+178.175.100.191
 178.175.100.218
 178.175.100.34
 178.175.100.4
-178.175.100.87
+178.175.100.52
 178.175.101.110
-178.175.101.243
+178.175.101.173
+178.175.101.191
 178.175.102.134
-178.175.102.152
-178.175.102.190
+178.175.102.14
 178.175.102.221
-178.175.102.228
 178.175.102.245
 178.175.102.35
 178.175.102.53
 178.175.103.172
-178.175.103.195
+178.175.103.24
+178.175.103.246
 178.175.103.27
 178.175.104.106
 178.175.104.110
 178.175.104.120
 178.175.104.140
+178.175.104.151
 178.175.104.155
 178.175.104.16
-178.175.104.169
-178.175.104.183
-178.175.104.196
+178.175.104.199
 178.175.104.206
+178.175.104.239
 178.175.104.49
+178.175.105.122
 178.175.105.125
 178.175.105.146
 178.175.105.197
 178.175.105.217
-178.175.105.220
+178.175.105.240
 178.175.105.245
+178.175.105.248
 178.175.106.104
 178.175.106.106
 178.175.106.118
+178.175.106.149
 178.175.106.18
 178.175.106.193
+178.175.106.36
 178.175.106.37
 178.175.106.77
+178.175.106.83
 178.175.107.0
 178.175.107.133
 178.175.107.149
 178.175.107.240
 178.175.107.245
 178.175.107.83
+178.175.108.65
 178.175.108.87
 178.175.108.94
 178.175.109.132
 178.175.109.140
+178.175.109.227
 178.175.109.37
 178.175.109.77
-178.175.11.109
+178.175.11.155
 178.175.11.165
 178.175.11.176
-178.175.11.184
 178.175.11.204
+178.175.11.241
 178.175.11.57
 178.175.11.6
 178.175.110.155
 178.175.110.169
+178.175.110.194
 178.175.110.197
 178.175.110.198
 178.175.110.221
-178.175.110.250
 178.175.111.105
 178.175.111.159
 178.175.111.187
 178.175.111.190
-178.175.111.203
+178.175.111.195
 178.175.111.206
-178.175.111.36
 178.175.111.98
 178.175.112.139
 178.175.112.147
 178.175.112.159
 178.175.112.4
 178.175.112.46
-178.175.112.59
-178.175.112.66
 178.175.112.85
-178.175.113.174
 178.175.114.200
 178.175.114.254
-178.175.114.29
-178.175.114.51
 178.175.114.55
 178.175.114.63
 178.175.114.90
 178.175.114.99
-178.175.115.138
+178.175.115.147
+178.175.115.175
 178.175.115.206
 178.175.115.208
+178.175.115.88
+178.175.116.101
+178.175.116.170
 178.175.116.188
-178.175.116.200
 178.175.116.227
 178.175.116.48
 178.175.116.64
-178.175.117.209
-178.175.117.215
+178.175.117.12
 178.175.117.39
-178.175.117.51
 178.175.118.112
 178.175.118.113
-178.175.118.165
 178.175.118.192
 178.175.118.198
 178.175.118.47
-178.175.118.60
 178.175.119.215
 178.175.119.237
 178.175.119.26
@@ -1553,53 +1528,45 @@
 178.175.12.40
 178.175.12.53
 178.175.12.70
+178.175.12.93
 178.175.12.97
-178.175.120.133
-178.175.120.162
 178.175.120.184
-178.175.120.196
 178.175.120.203
 178.175.120.231
 178.175.120.4
+178.175.120.5
+178.175.121.104
 178.175.121.116
-178.175.121.122
 178.175.121.123
 178.175.121.155
-178.175.121.190
+178.175.121.19
+178.175.121.192
+178.175.121.193
 178.175.121.229
-178.175.121.63
-178.175.121.83
-178.175.122.123
-178.175.122.130
-178.175.122.168
+178.175.122.199
 178.175.122.201
+178.175.122.208
 178.175.122.217
 178.175.122.245
 178.175.122.26
 178.175.122.28
 178.175.123.191
-178.175.123.196
 178.175.123.2
+178.175.123.26
 178.175.123.30
-178.175.123.40
 178.175.123.56
 178.175.123.7
 178.175.123.90
 178.175.124.109
 178.175.124.122
-178.175.124.131
 178.175.124.197
 178.175.124.4
 178.175.124.79
 178.175.124.89
-178.175.124.9
 178.175.125.14
 178.175.125.153
-178.175.125.174
-178.175.125.227
-178.175.125.39
+178.175.125.56
 178.175.126.167
-178.175.126.171
 178.175.126.220
 178.175.126.222
 178.175.126.237
@@ -1608,27 +1575,26 @@
 178.175.126.83
 178.175.126.93
 178.175.127.10
-178.175.127.119
 178.175.127.122
 178.175.127.15
 178.175.127.159
 178.175.127.166
+178.175.127.168
 178.175.127.176
+178.175.127.219
 178.175.127.230
 178.175.127.231
 178.175.127.236
-178.175.127.237
+178.175.127.43
 178.175.127.63
 178.175.127.64
 178.175.127.75
-178.175.13.1
-178.175.13.157
+178.175.127.97
 178.175.13.19
 178.175.13.220
 178.175.13.237
-178.175.13.250
+178.175.14.131
 178.175.14.178
-178.175.14.185
 178.175.14.230
 178.175.14.60
 178.175.14.69
@@ -1636,11 +1602,9 @@
 178.175.15.199
 178.175.15.215
 178.175.15.217
-178.175.15.253
 178.175.15.35
 178.175.15.45
 178.175.15.5
-178.175.15.85
 178.175.16.1
 178.175.16.108
 178.175.16.114
@@ -1648,11 +1612,11 @@
 178.175.16.179
 178.175.16.221
 178.175.16.49
-178.175.16.59
 178.175.16.73
 178.175.16.97
+178.175.17.118
 178.175.17.245
-178.175.18.93
+178.175.17.66
 178.175.19.163
 178.175.19.174
 178.175.19.229
@@ -1660,6 +1624,7 @@
 178.175.2.108
 178.175.2.110
 178.175.2.123
+178.175.2.186
 178.175.2.188
 178.175.2.237
 178.175.2.41
@@ -1668,22 +1633,21 @@
 178.175.2.54
 178.175.20.117
 178.175.20.170
-178.175.20.225
 178.175.20.237
 178.175.20.24
 178.175.20.70
+178.175.20.97
 178.175.21.149
-178.175.21.170
 178.175.21.184
 178.175.21.233
 178.175.21.238
+178.175.21.28
 178.175.21.76
 178.175.21.8
 178.175.22.110
 178.175.22.147
 178.175.22.237
 178.175.22.247
-178.175.23.102
 178.175.23.156
 178.175.23.228
 178.175.23.250
@@ -1693,24 +1657,22 @@
 178.175.24.171
 178.175.24.172
 178.175.24.177
-178.175.24.216
+178.175.24.198
 178.175.24.218
 178.175.24.238
 178.175.24.243
 178.175.24.77
 178.175.25.113
 178.175.25.117
-178.175.25.169
+178.175.25.148
 178.175.25.177
 178.175.25.28
 178.175.25.46
 178.175.25.56
-178.175.25.64
 178.175.25.75
 178.175.25.77
 178.175.26.112
 178.175.26.116
-178.175.26.164
 178.175.26.165
 178.175.26.209
 178.175.26.215
@@ -1719,7 +1681,7 @@
 178.175.26.246
 178.175.26.34
 178.175.27.106
-178.175.27.122
+178.175.27.137
 178.175.27.138
 178.175.27.14
 178.175.27.167
@@ -1727,43 +1689,50 @@
 178.175.27.177
 178.175.27.179
 178.175.27.199
-178.175.27.202
 178.175.27.215
 178.175.27.225
 178.175.27.233
 178.175.27.239
+178.175.27.244
 178.175.27.32
 178.175.27.37
 178.175.27.46
 178.175.27.48
-178.175.27.68
 178.175.27.69
 178.175.28.102
 178.175.28.199
+178.175.28.200
+178.175.28.51
+178.175.28.69
 178.175.29.16
 178.175.29.173
 178.175.29.174
 178.175.29.2
 178.175.29.201
 178.175.29.207
+178.175.29.208
 178.175.29.220
+178.175.29.7
 178.175.3.116
-178.175.3.130
 178.175.3.166
 178.175.3.172
 178.175.3.190
 178.175.3.196
 178.175.3.214
+178.175.3.66
+178.175.3.87
 178.175.30.0
 178.175.30.135
 178.175.30.213
-178.175.30.252
 178.175.30.70
 178.175.30.93
 178.175.30.96
 178.175.31.171
 178.175.31.251
+178.175.31.252
 178.175.31.6
+178.175.31.99
+178.175.32.14
 178.175.32.197
 178.175.32.198
 178.175.32.2
@@ -1771,36 +1740,38 @@
 178.175.32.211
 178.175.32.229
 178.175.32.243
+178.175.32.244
 178.175.32.89
-178.175.32.95
 178.175.33.112
 178.175.33.141
 178.175.33.162
 178.175.33.173
 178.175.33.181
-178.175.33.2
+178.175.33.196
 178.175.33.208
+178.175.33.21
 178.175.33.215
 178.175.33.228
 178.175.33.234
+178.175.33.245
 178.175.33.26
-178.175.33.28
-178.175.33.63
 178.175.34.1
 178.175.34.2
 178.175.34.200
-178.175.34.243
-178.175.35.144
+178.175.34.53
 178.175.35.21
 178.175.35.38
 178.175.35.83
+178.175.35.91
 178.175.36.0
 178.175.36.127
 178.175.36.129
+178.175.36.184
 178.175.36.218
 178.175.36.231
 178.175.36.245
 178.175.36.33
+178.175.36.5
 178.175.37.107
 178.175.37.135
 178.175.37.153
@@ -1809,25 +1780,26 @@
 178.175.37.38
 178.175.37.56
 178.175.37.6
+178.175.37.71
 178.175.37.81
 178.175.37.83
 178.175.38.1
 178.175.38.132
-178.175.38.141
 178.175.38.165
-178.175.38.191
-178.175.38.28
 178.175.38.98
+178.175.39.110
+178.175.39.129
 178.175.39.158
 178.175.39.245
 178.175.39.57
+178.175.39.63
 178.175.4.144
+178.175.4.192
 178.175.4.219
-178.175.4.222
 178.175.4.231
+178.175.4.233
 178.175.4.95
 178.175.40.155
-178.175.40.166
 178.175.40.226
 178.175.40.228
 178.175.40.41
@@ -1837,12 +1809,14 @@
 178.175.41.203
 178.175.41.34
 178.175.42.171
+178.175.42.228
+178.175.42.240
+178.175.42.25
 178.175.43.1
 178.175.43.106
 178.175.43.121
 178.175.43.138
 178.175.43.147
-178.175.43.217
 178.175.43.30
 178.175.43.33
 178.175.43.69
@@ -1850,7 +1824,6 @@
 178.175.44.134
 178.175.44.143
 178.175.44.155
-178.175.44.186
 178.175.44.197
 178.175.44.217
 178.175.44.22
@@ -1859,11 +1832,9 @@
 178.175.44.89
 178.175.44.90
 178.175.44.95
-178.175.44.96
-178.175.45.191
 178.175.45.205
+178.175.45.25
 178.175.45.6
-178.175.45.87
 178.175.46.119
 178.175.46.187
 178.175.46.224
@@ -1871,28 +1842,34 @@
 178.175.47.11
 178.175.47.141
 178.175.47.151
+178.175.47.16
 178.175.47.168
 178.175.47.245
 178.175.48.110
 178.175.48.168
 178.175.49.139
+178.175.49.214
 178.175.49.247
+178.175.49.252
 178.175.49.3
 178.175.5.17
 178.175.5.51
+178.175.5.79
 178.175.50.131
+178.175.50.168
 178.175.50.177
 178.175.50.22
 178.175.50.236
 178.175.50.237
-178.175.50.27
+178.175.50.32
 178.175.51.137
 178.175.51.160
 178.175.51.202
 178.175.51.66
+178.175.52.146
 178.175.52.161
+178.175.52.21
 178.175.52.212
-178.175.52.71
 178.175.52.94
 178.175.53.135
 178.175.53.151
@@ -1903,16 +1880,16 @@
 178.175.53.56
 178.175.53.58
 178.175.53.79
+178.175.54.15
 178.175.54.158
 178.175.54.163
+178.175.54.167
 178.175.54.205
-178.175.54.214
 178.175.54.225
 178.175.54.64
 178.175.55.103
 178.175.55.14
 178.175.55.163
-178.175.55.181
 178.175.55.25
 178.175.55.29
 178.175.55.38
@@ -1922,122 +1899,114 @@
 178.175.56.103
 178.175.56.11
 178.175.56.120
-178.175.56.18
-178.175.56.196
 178.175.56.24
 178.175.56.252
 178.175.56.33
 178.175.56.37
 178.175.56.50
+178.175.56.52
 178.175.56.54
 178.175.56.72
 178.175.56.75
 178.175.57.10
 178.175.57.141
 178.175.57.179
+178.175.57.99
 178.175.58.28
-178.175.58.29
 178.175.58.74
 178.175.58.79
 178.175.59.161
+178.175.59.241
 178.175.59.33
-178.175.59.47
 178.175.59.54
 178.175.6.134
 178.175.6.157
 178.175.6.189
+178.175.6.89
 178.175.60.209
 178.175.60.212
-178.175.60.251
+178.175.60.76
 178.175.61.156
 178.175.61.163
 178.175.61.17
 178.175.61.171
+178.175.61.178
 178.175.61.219
 178.175.61.237
+178.175.61.95
 178.175.62.111
 178.175.62.115
+178.175.62.141
 178.175.62.166
 178.175.62.168
-178.175.62.208
 178.175.62.42
 178.175.62.43
 178.175.62.70
 178.175.62.8
 178.175.62.84
-178.175.63.167
+178.175.63.192
 178.175.63.21
-178.175.63.73
+178.175.63.230
+178.175.63.78
 178.175.63.96
 178.175.64.12
+178.175.64.155
 178.175.64.156
 178.175.64.158
 178.175.64.187
+178.175.64.190
 178.175.64.22
-178.175.64.30
-178.175.64.50
-178.175.65.115
+178.175.64.231
+178.175.65.19
 178.175.65.202
 178.175.65.236
-178.175.66.105
-178.175.66.123
 178.175.66.186
 178.175.66.192
 178.175.66.199
 178.175.66.211
 178.175.66.228
-178.175.66.43
 178.175.66.54
 178.175.66.93
 178.175.67.0
 178.175.67.36
 178.175.67.51
-178.175.67.8
+178.175.67.55
 178.175.67.81
 178.175.67.83
 178.175.67.89
-178.175.68.109
+178.175.68.116
 178.175.68.44
 178.175.68.66
 178.175.68.85
 178.175.69.111
-178.175.69.112
 178.175.69.119
 178.175.69.128
 178.175.69.18
-178.175.69.4
-178.175.69.96
 178.175.7.6
 178.175.7.60
 178.175.7.71
+178.175.70.10
 178.175.70.109
-178.175.70.12
-178.175.70.147
-178.175.70.18
 178.175.70.196
 178.175.70.218
 178.175.70.246
-178.175.70.38
 178.175.70.5
 178.175.70.50
-178.175.70.64
 178.175.70.71
 178.175.70.83
-178.175.71.202
+178.175.70.93
+178.175.71.160
 178.175.71.45
-178.175.71.55
 178.175.71.84
 178.175.72.108
-178.175.72.13
 178.175.72.222
 178.175.72.30
 178.175.72.37
-178.175.73.127
-178.175.73.77
+178.175.72.47
 178.175.73.96
 178.175.74.182
+178.175.74.205
 178.175.74.48
-178.175.75.130
 178.175.75.181
 178.175.75.19
 178.175.75.84
@@ -2049,97 +2018,101 @@
 178.175.76.217
 178.175.76.83
 178.175.76.9
+178.175.77.248
+178.175.77.34
 178.175.77.46
 178.175.77.47
-178.175.77.71
-178.175.78.118
 178.175.78.198
 178.175.78.243
-178.175.78.46
+178.175.78.57
 178.175.78.97
 178.175.79.17
 178.175.79.244
 178.175.79.247
 178.175.79.69
 178.175.8.100
+178.175.8.227
+178.175.8.64
 178.175.80.100
-178.175.80.114
 178.175.80.129
-178.175.80.17
+178.175.80.197
 178.175.80.20
-178.175.80.35
 178.175.80.41
 178.175.80.61
+178.175.80.68
 178.175.80.79
 178.175.80.86
-178.175.81.17
+178.175.80.89
+178.175.81.19
 178.175.81.192
 178.175.81.226
 178.175.81.232
 178.175.81.244
 178.175.81.253
-178.175.81.50
-178.175.82.137
-178.175.82.32
+178.175.82.23
+178.175.82.73
+178.175.83.144
 178.175.83.2
+178.175.83.20
 178.175.83.247
 178.175.84.102
-178.175.84.109
 178.175.84.159
+178.175.84.17
 178.175.84.215
+178.175.84.28
 178.175.84.42
 178.175.85.153
 178.175.85.183
 178.175.85.23
-178.175.85.55
+178.175.85.230
 178.175.85.57
 178.175.86.119
+178.175.86.122
 178.175.86.36
 178.175.86.59
 178.175.87.126
 178.175.87.139
 178.175.87.144
 178.175.87.253
-178.175.87.68
-178.175.88.127
-178.175.88.140
+178.175.88.160
 178.175.88.166
 178.175.88.181
 178.175.88.182
+178.175.88.24
+178.175.88.248
 178.175.88.69
 178.175.89.157
 178.175.89.169
-178.175.89.24
+178.175.89.30
 178.175.9.125
 178.175.9.139
 178.175.9.175
 178.175.9.179
-178.175.9.183
 178.175.9.198
 178.175.9.210
 178.175.9.215
 178.175.9.225
+178.175.9.64
 178.175.9.84
 178.175.9.95
 178.175.90.122
 178.175.90.167
 178.175.90.172
+178.175.90.185
 178.175.90.21
-178.175.90.212
-178.175.90.244
 178.175.90.4
 178.175.90.74
+178.175.90.81
+178.175.90.90
 178.175.91.108
 178.175.91.13
 178.175.91.15
 178.175.91.244
 178.175.91.253
-178.175.91.40
 178.175.91.96
-178.175.92.128
 178.175.92.132
-178.175.92.141
 178.175.92.186
+178.175.92.200
 178.175.92.215
 178.175.92.231
 178.175.92.253
@@ -2148,37 +2121,32 @@
 178.175.93.143
 178.175.93.150
 178.175.93.159
-178.175.93.34
-178.175.93.45
+178.175.93.199
+178.175.93.44
 178.175.93.62
-178.175.93.93
 178.175.94.195
 178.175.94.200
+178.175.94.27
 178.175.94.40
 178.175.94.55
+178.175.95.116
 178.175.95.141
+178.175.95.163
 178.175.95.17
 178.175.95.227
-178.175.95.237
 178.175.95.4
 178.175.95.56
-178.175.96.169
-178.175.96.192
-178.175.97.1
+178.175.96.81
 178.175.97.128
 178.175.97.135
-178.175.97.143
-178.175.97.78
+178.175.98.216
 178.175.98.228
 178.175.98.254
 178.175.98.29
-178.175.98.36
+178.175.98.44
 178.175.98.68
 178.175.99.123
 178.175.99.130
-178.175.99.22
-178.175.99.45
-178.175.99.88
 178.175.99.91
 178.19.183.14
 178.205.101.33
@@ -2193,6 +2161,7 @@
 178.95.136.35
 179.159.58.134
 179.4.187.39
+179.42.107.139
 179.43.157.173
 179.60.84.7
 179.99.210.161
@@ -2205,7 +2174,6 @@
 180.125.44.194
 180.157.66.204
 180.175.236.209
-180.175.93.52
 180.176.105.41
 180.176.110.243
 180.176.165.230
@@ -2216,6 +2184,7 @@
 180.177.242.73
 180.218.5.171
 180.248.80.38
+180.253.99.109
 180.66.111.36
 180.66.53.93
 180.94.170.166
@@ -2226,123 +2195,131 @@
 181.193.107.10
 181.199.170.222
 181.199.170.230
-181.199.170.240
 181.210.45.42
 181.215.47.82
 181.224.242.131
 181.49.236.4
 181.49.59.162
+182.112.28.118
+182.112.34.220
 182.112.43.249
 182.112.52.131
+182.113.238.197
+182.113.29.28
+182.114.105.40
 182.114.111.64
-182.114.24.20
-182.114.49.104
 182.114.64.27
+182.114.76.42
 182.114.79.103
 182.114.83.88
 182.114.92.90
 182.114.93.96
-182.116.101.82
-182.116.103.234
 182.116.104.106
-182.116.108.180
+182.116.105.208
 182.116.108.244
+182.116.116.70
 182.116.118.250
+182.116.119.66
+182.116.36.175
 182.116.60.73
 182.116.61.252
 182.116.80.107
 182.116.94.196
 182.116.99.150
+182.117.13.57
 182.117.15.172
 182.117.25.120
 182.117.26.235
 182.117.29.220
 182.117.39.51
 182.117.43.27
+182.117.49.127
 182.118.146.181
+182.118.166.128
 182.119.100.135
 182.119.109.173
 182.119.118.218
 182.119.14.252
+182.119.15.78
 182.119.166.208
-182.119.176.209
+182.119.166.76
+182.119.179.193
+182.119.197.123
+182.119.202.180
+182.119.21.68
 182.119.211.69
 182.119.214.120
 182.119.221.141
-182.119.225.30
+182.119.226.84
 182.119.255.115
 182.119.7.54
+182.119.89.107
 182.120.16.22
 182.120.16.46
-182.120.33.117
 182.120.37.251
 182.120.43.0
-182.121.11.43
 182.121.129.163
-182.121.130.67
-182.121.133.46
 182.121.134.70
-182.121.158.141
+182.121.15.223
+182.121.157.35
 182.121.205.201
 182.121.205.237
 182.121.207.195
-182.121.40.234
-182.121.50.111
+182.121.254.147
+182.121.55.106
 182.121.66.189
 182.121.9.117
 182.121.94.13
-182.122.181.105
 182.122.202.18
 182.123.203.21
 182.123.211.239
+182.123.241.195
 182.124.123.107
 182.124.177.48
 182.124.19.87
+182.124.201.207
 182.124.88.122
 182.126.113.127
-182.126.120.66
+182.126.123.19
 182.126.126.203
 182.126.127.254
-182.126.181.121
-182.126.52.233
 182.126.67.24
-182.126.80.108
 182.126.83.79
 182.126.88.138
+182.127.0.16
 182.127.103.79
 182.127.104.235
-182.127.110.147
+182.127.106.43
 182.127.152.3
 182.127.155.157
-182.127.209.26
 182.127.221.243
+182.127.93.38
 182.160.98.250
 182.172.36.164
 182.233.0.252
 182.235.252.31
 182.53.197.62
-182.58.219.8
+182.56.193.251
+182.59.235.150
 183.105.104.83
 183.105.225.154
 183.109.169.45
 183.11.238.228
 183.136.252.233
-183.150.138.131
 183.150.244.122
 183.16.208.30
 183.185.112.19
+183.185.162.225
 183.187.163.176
 183.188.151.225
 183.188.180.116
 183.188.188.186
 183.188.228.38
+183.188.93.116
 183.83.105.21
-183.83.125.235
 183.83.127.89
 183.83.26.115
-183.83.99.87
 183.92.195.140
-183.95.147.102
 183.97.22.14
 184.164.185.41
 184.175.115.10
@@ -2384,14 +2361,11 @@
 186.225.120.173
 186.232.44.86
 186.28.60.184
-186.33.112.218
-186.33.112.228
-186.33.112.66
-186.33.113.241
 186.33.113.77
 186.4.125.48
 186.73.188.132
 187.12.10.98
+187.188.124.229
 187.212.200.162
 187.233.208.103
 187.33.71.68
@@ -2399,12 +2373,12 @@
 188.10.231.246
 188.113.102.18
 188.113.81.17
+188.119.45.194
 188.13.179.87
 188.138.200.32
 188.152.41.141
 188.169.178.50
-188.169.199.59
-188.169.36.163
+188.169.179.151
 188.169.45.140
 188.242.167.159
 188.242.242.144
@@ -2438,6 +2412,7 @@
 190.216.140.123
 190.35.225.36
 190.65.206.162
+190.73.12.149
 190.92.4.231
 190.98.37.135
 190.98.37.200
@@ -2445,7 +2420,6 @@
 191.255.248.220
 192.210.175.130
 192.210.241.200
-192.227.185.106
 192.227.209.27
 192.227.220.55
 192.227.228.67
@@ -2454,6 +2428,7 @@
 192.99.240.77
 193.142.146.25
 193.228.135.144
+193.38.55.9
 193.91.131.237
 194.147.142.230
 194.15.36.167
@@ -2470,7 +2445,6 @@
 197.50.27.115
 198.23.133.218
 198.23.207.121
-198.23.213.57
 198.23.251.105
 198.251.72.110
 198.46.201.76
@@ -2482,7 +2456,9 @@
 2.45.111.158
 2.45.4.24
 2.55.125.182
+2.58.69.44
 2.83.152.16
+20.185.42.197
 20.dbstrony.pl
 200.105.167.98
 200.111.189.70
@@ -2495,17 +2471,16 @@
 201.187.102.73
 201.200.254.86
 201.203.221.20
+201.203.27.37
 201.215.84.97
 201.218.97.142
 202.107.233.41
+202.150.176.100
 202.164.153.80
 202.166.217.54
 202.169.234.22
 202.169.234.37
-202.169.234.47
 202.169.234.52
-202.169.234.55
-202.169.234.9
 202.29.95.12
 202.4.124.58
 202.51.176.114
@@ -2513,12 +2488,10 @@
 202.74.236.9
 203.109.201.243
 203.130.69.205
-203.170.115.82
 203.189.156.107
 203.204.232.18
 203.229.21.56
 203.236.190.28
-203.238.86.202
 203.70.166.107
 203.77.80.159
 203.80.119.166
@@ -2528,7 +2501,6 @@
 203.93.6.28
 204.195.116.171
 205.185.115.74
-205.185.123.217
 206.248.137.132
 206.47.41.166
 207.5.32.6
@@ -2540,6 +2512,7 @@
 210.124.149.19
 210.216.152.122
 210.216.153.142
+210.57.234.131
 210.57.234.93
 210.57.237.70
 210.57.245.109
@@ -2561,6 +2534,7 @@
 211.247.113.49
 211.247.5.96
 211.36.174.137
+211.47.102.51
 211.51.174.149
 212.122.86.105
 212.143.227.22
@@ -2575,11 +2549,11 @@
 213.149.190.193
 213.163.104.12
 213.163.104.138
-213.163.104.160
+213.163.104.7
 213.163.104.99
+213.163.113.100
 213.163.113.135
 213.163.113.225
-213.163.113.23
 213.163.113.237
 213.163.113.51
 213.163.114.155
@@ -2591,7 +2565,9 @@
 213.163.115.33
 213.163.115.71
 213.163.116.132
+213.163.116.181
 213.163.116.192
+213.163.116.197
 213.163.116.203
 213.163.116.33
 213.163.116.85
@@ -2600,21 +2576,21 @@
 213.163.117.97
 213.163.118.129
 213.163.118.144
+213.163.118.236
 213.163.118.238
-213.163.118.65
 213.163.119.24
 213.163.119.240
-213.163.126.104
 213.163.126.20
 213.163.126.243
+213.163.126.249
 213.163.126.60
 213.163.126.7
 213.163.126.84
 213.163.127.204
 213.163.127.217
+213.163.127.242
 213.163.127.46
 213.189.178.163
-213.226.140.23
 213.240.218.15
 213.249.156.189
 213.27.8.6
@@ -2642,6 +2618,7 @@
 218.35.81.81
 218.48.135.50
 218.56.93.129
+218.57.109.48
 218.57.53.55
 218.59.116.203
 218.72.198.15
@@ -2649,33 +2626,37 @@
 218.93.102.63
 218.93.102.75
 219.154.103.40
-219.154.114.132
 219.154.114.45
 219.154.115.250
+219.154.116.168
 219.154.126.205
+219.154.142.35
+219.154.143.132
 219.154.147.58
 219.154.148.116
 219.154.173.163
+219.154.178.138
+219.154.41.36
 219.155.102.14
+219.155.11.252
 219.155.113.58
 219.155.14.17
-219.155.170.22
+219.155.209.253
 219.155.24.246
 219.155.243.184
 219.155.26.204
-219.155.26.37
 219.155.29.165
 219.155.31.15
 219.155.31.67
-219.155.42.216
+219.155.86.156
 219.155.98.64
 219.156.131.116
-219.156.167.103
 219.156.17.217
+219.156.176.153
 219.156.23.29
 219.156.60.224
+219.156.65.47
 219.156.88.219
-219.156.9.32
 219.157.11.39
 219.157.146.200
 219.157.147.87
@@ -2683,8 +2664,8 @@
 219.157.178.201
 219.157.178.210
 219.157.183.29
+219.157.214.235
 219.157.223.241
-219.157.223.245
 219.157.42.228
 219.157.67.171
 219.241.6.180
@@ -2692,6 +2673,7 @@
 219.68.1.84
 219.68.163.7
 219.68.171.144
+219.68.245.63
 219.68.251.32
 219.68.5.140
 219.69.71.186
@@ -2703,21 +2685,21 @@
 220.133.30.200
 220.200.22.163
 220.71.239.115
+220.90.159.188
 221.1.162.82
 221.124.78.15
-221.14.11.33
 221.14.122.127
 221.14.165.237
+221.14.185.105
 221.14.47.162
-221.14.58.5
+221.14.47.189
+221.14.57.175
 221.15.108.55
+221.15.112.103
 221.15.125.190
-221.15.127.124
-221.15.147.220
-221.15.21.133
-221.15.212.123
+221.15.155.186
+221.15.190.2
 221.15.234.159
-221.15.236.211
 221.15.237.107
 221.15.250.213
 221.15.253.236
@@ -2731,8 +2713,10 @@
 221.196.12.96
 221.198.167.192
 221.2.190.22
+221.202.232.230
 221.214.130.147
 221.214.224.184
+221.214.251.109
 221.215.116.167
 221.215.172.207
 221.215.184.31
@@ -2757,52 +2741,50 @@
 222.135.219.29
 222.135.26.161
 222.135.67.115
-222.136.49.252
 222.136.53.227
+222.136.77.190
 222.137.101.251
 222.137.101.33
 222.137.121.127
 222.137.137.5
 222.137.138.252
 222.137.148.192
-222.137.160.202
+222.137.161.88
 222.137.172.250
 222.137.198.247
+222.137.220.215
+222.137.237.203
 222.137.239.124
 222.137.49.36
-222.137.5.150
-222.137.57.234
+222.137.53.193
 222.137.72.146
-222.137.85.26
 222.137.96.9
+222.138.118.192
 222.138.143.84
 222.138.151.100
 222.138.189.138
 222.138.201.241
-222.138.23.254
+222.138.213.235
+222.138.226.142
 222.138.96.79
-222.139.16.229
-222.140.129.239
+222.139.106.55
 222.140.162.140
 222.140.163.112
 222.140.17.245
+222.140.179.142
+222.140.208.18
 222.140.209.222
-222.140.254.11
 222.140.39.66
+222.141.101.39
 222.141.120.26
 222.141.13.77
-222.141.44.36
-222.141.73.249
+222.141.40.69
+222.141.46.119
 222.141.9.0
-222.142.162.164
 222.142.192.66
 222.142.209.231
-222.142.209.7
-222.142.245.207
 222.179.215.189
 222.185.116.233
-222.186.20.19
-222.187.184.136
 222.187.9.178
 222.211.72.66
 222.214.54.208
@@ -2811,7 +2793,7 @@
 222.238.230.7
 222.239.83.232
 222.248.64.253
-222.83.150.240
+222.81.156.229
 222.92.9.126
 222.99.171.192
 223.166.117.210
@@ -2856,7 +2838,7 @@
 27.141.218.17
 27.147.29.52
 27.147.40.128
-27.153.207.1
+27.153.142.115
 27.184.244.14
 27.184.54.199
 27.187.248.22
@@ -2864,7 +2846,6 @@
 27.193.196.190
 27.193.217.210
 27.194.149.142
-27.194.158.229
 27.194.192.66
 27.194.210.20
 27.197.17.88
@@ -2890,13 +2871,11 @@
 27.203.165.138
 27.203.175.203
 27.203.185.42
-27.203.185.48
 27.203.213.79
 27.203.246.96
 27.203.255.42
 27.203.28.115
 27.203.4.188
-27.203.54.217
 27.203.68.144
 27.203.87.75
 27.203.94.134
@@ -2920,11 +2899,10 @@
 27.208.164.18
 27.208.166.13
 27.208.201.212
-27.208.214.139
 27.208.247.130
 27.208.25.59
 27.208.34.2
-27.208.46.167
+27.208.70.115
 27.208.92.64
 27.209.160.222
 27.209.231.15
@@ -2940,6 +2918,7 @@
 27.213.109.105
 27.213.109.58
 27.213.145.221
+27.213.166.50
 27.213.167.175
 27.213.175.208
 27.213.220.5
@@ -2952,6 +2931,7 @@
 27.215.212.209
 27.215.212.80
 27.215.253.149
+27.215.27.143
 27.215.34.242
 27.215.38.119
 27.215.38.166
@@ -2966,7 +2946,6 @@
 27.216.227.95
 27.216.234.98
 27.216.46.85
-27.216.58.120
 27.216.95.56
 27.217.120.226
 27.217.133.53
@@ -3001,23 +2980,30 @@
 27.35.154.13
 27.35.212.124
 27.35.58.5
-27.41.143.46
+27.41.159.28
+27.41.37.155
+27.41.9.105
 27.41.9.44
+27.41.97.36
+27.43.108.78
+27.43.111.161
+27.43.117.66
+27.46.23.10
 27.46.44.130
-27.46.44.161
+27.46.44.153
+27.46.45.86
 27.46.46.100
 27.46.46.252
-27.5.23.215
-27.5.34.254
-27.5.46.18
-27.6.195.65
-27.6.240.125
-27.6.242.65
+27.5.23.69
+27.5.47.16
+27.6.240.171
+27.6.38.96
 31.0.98.131
 31.11.51.57
 31.13.23.180
 31.154.234.3
 31.163.191.11
+31.168.124.130
 31.168.179.83
 31.168.184.59
 31.168.191.243
@@ -3038,11 +3024,13 @@
 31.30.119.23
 32.208.157.193
 32.218.180.9
+32792.prolocksmithwinterpark.com
 35.184.169.169
 36.108.231.218
 36.250.203.246
 36.251.157.225
 36.251.18.18
+36.251.18.63
 36.251.19.88
 36.251.51.244
 36.255.90.219
@@ -3050,10 +3038,13 @@
 36.33.160.167
 36.34.150.236
 36.36.243.67
+36.43.11.16
 36.66.105.159
 36.66.111.203
 36.66.133.125
 36.66.139.36
+36.67.152.161
+36.81.23.38
 36.89.18.133
 36.96.187.93
 360.lcy2zzx.pw
@@ -3108,9 +3099,11 @@
 39.77.150.203
 39.77.197.81
 39.77.209.209
+39.77.48.213
 39.77.94.189
 39.77.95.50
 39.79.146.67
+39.79.163.188
 39.79.166.31
 39.79.218.46
 39.79.62.43
@@ -3122,6 +3115,7 @@
 39.80.205.255
 39.80.24.54
 39.80.36.151
+39.80.37.182
 39.81.251.0
 39.81.27.15
 39.81.29.231
@@ -3141,17 +3135,14 @@
 39.86.216.144
 39.86.234.187
 39.86.248.91
-39.86.60.98
 39.86.66.24
 39.86.73.100
-39.86.78.228
 39.87.63.58
 39.87.90.210
 39.87.93.109
 39.88.141.172
 39.88.155.96
 39.88.233.131
-39.88.41.73
 39.88.67.238
 39.88.72.9
 39.89.146.198
@@ -3166,66 +3157,84 @@
 41.219.185.171
 41.230.31.58
 41.72.203.82
+41.86.18.133
 41.86.18.148
-41.86.18.200
+41.86.18.157
+41.86.18.164
+41.86.18.165
 41.86.18.71
-41.86.21.23
-41.86.5.233
-41.86.5.236
+41.86.19.206
+41.86.19.80
+41.86.21.38
+41.86.21.44
+41.86.21.62
+41.86.5.142
+41.86.5.198
+41.86.5.206
 42.176.112.72
 42.177.164.171
 42.179.162.208
 42.179.163.177
 42.202.101.147
+42.224.122.183
 42.224.122.39
-42.224.169.111
 42.224.171.104
 42.224.172.125
-42.224.18.165
+42.224.188.223
+42.224.189.79
 42.224.19.55
 42.224.220.37
 42.224.233.247
 42.224.234.23
 42.224.245.91
 42.224.249.160
+42.224.249.188
+42.224.3.187
 42.224.36.220
-42.224.56.81
+42.224.52.81
+42.224.68.72
 42.224.69.11
 42.224.70.213
 42.225.120.122
 42.225.205.191
 42.225.241.5
-42.226.89.25
 42.227.194.95
 42.227.196.123
 42.227.66.88
-42.228.39.232
+42.228.196.68
 42.228.40.56
 42.228.60.114
 42.228.67.135
 42.228.68.118
 42.228.70.126
 42.228.70.231
-42.228.84.206
-42.230.153.183
-42.230.219.175
+42.230.218.252
 42.230.25.164
+42.230.46.55
 42.230.48.162
-42.231.95.195
+42.231.95.247
 42.232.102.163
-42.232.23.76
+42.232.46.169
+42.233.159.21
 42.233.78.236
-42.233.90.183
+42.234.247.41
 42.234.85.184
 42.235.23.163
-42.235.3.187
-42.235.82.129
-42.235.86.211
+42.235.67.162
+42.235.82.112
+42.235.87.100
 42.235.90.32
 42.235.95.254
 42.236.148.201
+42.237.142.157
+42.237.24.151
 42.237.252.159
+42.237.60.73
+42.238.228.0
+42.239.155.147
+42.239.202.121
 42.239.21.27
+42.239.218.137
 42.239.98.70
 42.242.200.90
 42.56.15.227
@@ -3234,6 +3243,7 @@
 42.87.29.162
 43.230.156.44
 43.241.106.183
+43.252.8.94
 45.133.1.137
 45.133.1.139
 45.133.1.242
@@ -3248,10 +3258,13 @@
 45.144.225.65
 45.148.10.47
 45.148.10.94
+45.165.215.19
 45.176.108.116
+45.176.108.164
 45.176.108.22
 45.176.108.248
 45.176.110.99
+45.176.111.119
 45.176.111.154
 45.176.111.16
 45.176.111.202
@@ -3267,10 +3280,10 @@
 45.81.235.31
 45.9.148.37
 46.151.155.218
+46.161.185.15
 46.172.75.231
 46.175.184.121
 46.182.173.246
-46.182.173.247
 46.20.63.218
 46.21.153.231
 46.214.27.4
@@ -3292,7 +3305,6 @@
 49.142.87.36
 49.143.32.36
 49.143.43.93
-49.156.35.166
 49.158.201.200
 49.159.20.121
 49.159.21.3
@@ -3303,13 +3315,14 @@
 49.68.221.252
 49.68.249.121
 49.70.15.16
+49.70.95.181
 5.146.202.18
 5.181.135.114
 5.2.70.50
+5.42.37.74
 5.53.146.179
 5.8.10.62
 50.115.174.102
-50.115.174.106
 50.121.91.255
 50.252.47.29
 51.171.146.13
@@ -3317,6 +3330,7 @@
 54.36.114.136
 54.36.180.122
 58.114.246.26
+58.115.108.164
 58.115.162.92
 58.115.174.4
 58.125.191.4
@@ -3331,7 +3345,6 @@
 58.218.67.253
 58.22.212.107
 58.226.129.29
-58.229.194.122
 58.23.245.24
 58.230.89.42
 58.238.42.192
@@ -3340,92 +3353,57 @@
 58.241.78.55
 58.243.126.133
 58.248.112.254
-58.248.140.46
+58.248.117.238
+58.248.142.5
 58.248.143.240
-58.248.144.122
-58.248.144.88
-58.248.147.235
-58.248.151.128
+58.248.144.229
+58.248.147.196
+58.248.151.33
 58.248.153.224
-58.248.76.23
+58.248.74.240
 58.248.77.38
-58.248.82.34
 58.249.12.80
 58.249.14.53
 58.249.16.173
 58.249.19.127
-58.249.23.58
-58.249.73.182
-58.249.74.197
+58.249.72.88
+58.249.74.243
 58.249.74.245
-58.249.75.107
-58.249.75.158
+58.249.75.213
 58.249.77.88
-58.249.79.62
+58.249.80.25
 58.249.82.35
-58.249.86.11
-58.249.87.54
-58.249.88.218
+58.249.87.171
+58.249.89.158
 58.252.176.71
-58.253.13.50
+58.255.133.161
+58.255.140.150
 58.48.154.143
 58.50.221.148
 58.72.165.153
 58.72.165.39
 58.76.151.189
+58.76.151.51
 58.97.206.33
 59.0.211.161
 59.102.168.189
+59.127.11.50
 59.151.202.3
 59.151.214.4
+59.151.246.125
 59.29.133.229
-59.32.97.190
-59.42.62.0
 59.45.235.176
 59.58.104.244
 59.58.117.226
 59.7.124.148
 59.8.35.22
-59.92.176.186
-59.92.18.43
-59.92.181.100
-59.92.182.21
-59.92.182.84
-59.92.218.209
-59.92.218.254
-59.93.17.66
-59.93.18.37
-59.93.22.45
-59.94.180.222
-59.94.181.124
-59.94.183.163
-59.95.174.230
-59.95.175.37
-59.96.38.154
-59.96.38.182
-59.97.168.127
-59.97.169.111
-59.97.169.173
-59.97.171.61
-59.97.172.0
-59.97.173.49
-59.97.174.151
-59.97.175.163
-59.99.136.22
-59.99.136.63
-59.99.138.83
-59.99.139.190
-59.99.141.237
-59.99.40.173
-59.99.40.27
-59.99.41.192
-59.99.44.136
-59.99.44.201
-59.99.44.5
-59.99.47.220
-59.99.47.96
-59.99.93.136
-59.99.94.181
+59.92.180.232
+59.92.217.35
+59.94.180.230
+59.96.37.181
+59.96.37.192
+59.96.39.222
+59.97.193.255
 60.13.61.12
 60.14.48.221
 60.16.247.78
@@ -3443,6 +3421,7 @@
 60.211.19.63
 60.211.6.112
 60.212.100.83
+60.212.111.39
 60.212.162.152
 60.212.202.218
 60.212.206.246
@@ -3453,6 +3432,8 @@
 60.213.162.59
 60.213.58.188
 60.213.83.55
+60.214.217.96
+60.214.32.17
 60.214.73.6
 60.214.93.166
 60.215.165.64
@@ -3466,15 +3447,15 @@
 60.25.115.48
 60.25.76.224
 60.253.15.104
-60.253.39.88
+60.253.4.72
 60.253.42.72
 60.253.51.127
-60.253.8.81
 60.26.17.221
 60.7.10.121
 60.7.8.43
 60.7.99.254
 61.102.243.124
+61.130.195.121
 61.162.169.210
 61.162.55.42
 61.163.142.96
@@ -3482,52 +3463,49 @@
 61.179.171.60
 61.179.91.194
 61.179.91.230
-61.18.112.48
 61.192.73.253
 61.213.118.28
 61.247.224.66
 61.253.94.230
-61.3.124.126
-61.3.124.8
-61.3.127.102
-61.3.149.89
+61.3.124.125
+61.3.151.60
 61.47.220.169
 61.52.103.144
+61.52.103.217
+61.52.109.9
 61.52.11.87
 61.52.159.231
+61.52.167.66
 61.52.195.226
+61.52.210.53
+61.52.211.61
 61.52.212.191
 61.52.214.11
+61.52.234.193
 61.52.237.212
 61.52.242.56
+61.52.30.172
+61.52.4.214
+61.52.42.174
 61.52.48.40
 61.52.76.72
 61.52.9.166
 61.52.9.62
+61.52.98.22
 61.52.99.161
-61.53.100.87
 61.53.102.137
 61.53.117.115
 61.53.119.161
 61.53.122.161
 61.53.123.162
 61.53.192.49
-61.53.2.35
 61.53.201.162
-61.53.54.255
-61.53.72.250
-61.53.81.18
-61.53.99.179
 61.54.103.56
 61.54.168.35
 61.54.232.45
 61.54.40.202
-61.54.58.190
 61.54.58.20
-61.54.63.23
 61.54.64.104
-61.54.76.122
-61.54.77.175
 61.56.180.67
 61.56.181.7
 61.57.96.116
@@ -3572,17 +3550,18 @@
 67.3.169.223
 67.8.138.101
 67.81.98.111
-67.82.242.243
 67.83.49.234
 67.84.138.165
 68.151.244.128
 68.174.182.226
 68.175.107.153
+68.183.25.71
 68.188.144.143
 68.204.88.29
 68.205.106.84
 68.205.119.241
 68.78.33.33
+68468438438.xyz
 69.115.37.205
 69.120.237.255
 69.123.245.151
@@ -3606,7 +3585,6 @@
 71.127.148.69
 71.146.190.91
 71.167.164.113
-71.19.150.93
 71.204.63.239
 71.29.48.164
 71.34.191.213
@@ -3624,16 +3602,17 @@
 72.214.69.226
 72.229.230.118
 72.229.35.40
+72.31.40.122
 73.204.216.103
 74.101.1.159
 74.108.224.112
+74.116.216.141
 74.194.117.165
 74.195.115.176
 74.199.84.77
 74.64.139.223
 74.75.165.81
 75.127.141.52
-75.176.213.114
 75.83.102.27
 75.99.213.61
 76.108.199.153
@@ -3648,6 +3627,7 @@
 77.71.52.220
 77.79.191.32
 77.89.203.238
+77.94.89.20
 78.186.155.18
 78.187.141.144
 78.187.240.125
@@ -3700,7 +3680,6 @@
 82.80.154.214
 82.80.187.109
 82.81.100.54
-82.81.106.65
 82.81.108.172
 82.81.131.158
 82.81.19.42
@@ -3723,9 +3702,9 @@
 84.210.219.208
 84.210.219.213
 84.212.219.127
-84.224.162.170
 84.228.50.118
 84.228.95.204
+84.238.24.35
 84.247.83.74
 84.254.39.129
 84.33.111.227
@@ -3745,6 +3724,7 @@
 85.97.195.129
 86.35.43.220
 87.61.89.40
+87du.vip
 88.119.171.253
 88.2.208.71
 88.2.219.179
@@ -3758,7 +3738,6 @@
 88.250.254.90
 89.122.183.130
 89.29.213.33
-89.34.26.165
 89.35.62.96
 89.40.85.166
 89.40.87.5
@@ -3780,7 +3759,6 @@
 92.114.191.82
 92.241.78.114
 92.27.246.202
-92.54.237.143
 92.54.237.237
 92.83.62.139
 92.85.18.138
@@ -3803,6 +3781,7 @@
 95.153.241.63
 95.154.20.231
 95.158.19.130
+95.170.113.227
 95.170.113.52
 95.170.201.34
 95.181.155.112
@@ -3812,7 +3791,6 @@
 95.9.120.40
 96.239.73.246
 96.47.147.169
-97.103.64.196
 97.68.140.254
 97.96.199.75
 98.0.210.218
@@ -3826,7 +3804,6 @@
 98.30.24.54
 99.150.245.203
 99.33.195.164
-99centsdigitals.com
 abcd.bg
 abclicks.in
 abissnet.net
@@ -3834,6 +3811,7 @@ aboveandbelow.com.au
 absoftechworld.com
 absupplies.co.uk
 abyssos.eu
+academyshademani.com
 acbick.com
 accounts.thesmarttechhub.com
 aceeprc.com.aceeprc.com
@@ -3862,7 +3840,9 @@ agmcarpetcare.co.uk
 aiqtest.com
 ajpharmaholding.com
 ajstudiollc.com
+akauk09.top
 akivj07.top
+akpgi08.top
 al-wahd.com
 alasdemariposas.org
 alemelektronik.com
@@ -3896,6 +3876,7 @@ api-ms.cobainaja.id
 api.cstdevs.com
 api.quocbao.biz
 api.sampy.io
+aplicativoparasindicato.com.br
 apoolcondo.com
 app.adsensearticle.com
 app.explicitsurveys.co.uk
@@ -3903,7 +3884,6 @@ app.prerana.info
 apps.saintsoporte.com
 aqv.news
 areyoulivingwell.com
-arsapetrolab.com
 artedibujoyarquitectura.com
 ask-regard.call-save.biz
 atfile.com
@@ -3914,10 +3894,8 @@ attach.66rpg.com
 atteuqpotentialunlimited.com
 augustair.com
 aulist.com
-australiafashions.com
 automaticrefreshments.com
 avadhanagames.com
-avissrilanka.com
 ayamallah.com
 azmeasurement.com
 azraktours.com
@@ -3955,12 +3933,12 @@ blog.callensaxen.com
 blog.oyinblogs.com
 blog.takbelit.com
 bmlifestyle.co.uk
-bnrbook.com
 bnrnews.id
 bodenstein.co.za
 booksearch.com
 bounces.mi-fs.com
 bpo.correct.go.th
+bradleyinstitute.co.za
 brandtrust.com.pk
 brendanquine.com
 brideofmessiah.com
@@ -3971,8 +3949,6 @@ brightstarshop.com
 browardinsurancemiami.solucioneslink.com
 bt2.elin.co.za
 btdapi.robotake.com
-bucrinsuranlceonlines.com
-buenavista.co
 buigiaphat.com.vn
 bullseyemedia.in
 busandvanrentalmalaysia.com
@@ -3997,6 +3973,7 @@ cazyacustomfurniture.com
 ccauthority.net
 cdaonline.com.ar
 cec.asso.ac-amiens.fr
+cecra.cl
 cellas.sk
 cendekiabinaaksara.com
 cespol-bote.com.mx
@@ -4004,8 +3981,6 @@ cfs5.tistory.com
 ch.rmu.ac.th
 changematterscounselling.com
 chardhamdodham.com
-cheacrilnsurances.com
-chealablilitycarinsurances.com
 chezalice.co.za
 childselect.com
 chinhdropfile.myvnc.com
@@ -4025,11 +4000,9 @@ config.cqhbkjzx.com
 constructoralyon.com
 consulateins.solucioneslink.com
 contributeindustry.com
-controladoradeplagasmm.com
 controleautomacao.com.br
 copelandscapes.com
 coulsongraphics.com
-coutler.newreadermedia.net
 covid19.cyberschool.or.id
 cr-sq.com
 craftnesia.id
@@ -4081,14 +4054,14 @@ despertaresi.com.br
 destinymc.co.za
 detorre.es
 dev-interestingtech.pantheonsite.io
-dev.sayse-tienda.com
 dev.sebpo.net
+dezcom.com
 dfcf.91756.cn
-dfsfcsfcdsfsdvcfsvcscv.com
 diamantenegro.mi-fs.com
 dienmayminhhung.com
 digilib.dianhusada.ac.id
 djking.f3322.net
+dl-link.link
 dl.1003b.56a.com
 dl.198424.com
 dl.installcdn-aws.com
@@ -4111,7 +4084,6 @@ dosman.pl
 dovberger.com
 down.flash-plays.com
 down.pcclear.com
-down.udashi.com
 down.webbora.com
 down1.arpun.com
 download.caihong.com
@@ -4131,6 +4103,7 @@ drsha.innovativesolutions.mobi
 dsenterprize.co.za
 dsspainting.com
 du-wizards.com
+duckrambo.com
 duque.guantanameratravel.com
 dutapp.wisolve.co.za
 duvalcharter.dekitout.com
@@ -4141,7 +4114,6 @@ e.sldov.ru
 ebruyatkin.com
 econews.treegle.org
 efficientegroup.com
-elliot.newreadermedia.net
 en.baoend.com
 enc-tech.com
 endurotanzania.co.tz
@@ -4157,7 +4129,6 @@ evidencemarketing.ca
 exilum.com
 exitoalfaomega.co
 extrovertoffers.com
-f1sol.com
 familydentist.site
 farmaciasdrogaminas.com.br
 fate3.xyz
@@ -4168,6 +4139,7 @@ fi.bonitastores.com
 files.martellexpress.us
 final.makkahkmcc.com
 fineartgallerym.com
+fixauto.illumetechnology.com
 fkd.derpcity.ru
 flintspin.com
 flyingbuddhadesign.com
@@ -4177,7 +4149,6 @@ foothills.com.br
 footweardirect.elin.co.za
 forum.mdb.nu
 fotoobjetivo.com
-foundationrepairhoustontx.net
 foxeps.com.br
 freecnetdownload.com
 freedombookshop.tickme.lk
@@ -4199,7 +4170,6 @@ ghettohub.co.za
 ghislain.dartois.pagesperso-orange.fr
 giadungg7.com
 giddos.ga
-gilliem.com
 girotexuniformes.com
 giteletropical.com
 globaltask.ar
@@ -4215,6 +4185,7 @@ goldcoastoffice365.com.au
 goldcupmortgage.com
 golden-memories-funerals.yourpageserver.com
 goldmen.in
+gracejukes.com
 grupoinmare.com
 gruposelt.000webhostapp.com
 gs.monerorx.com
@@ -4225,6 +4196,7 @@ hagebakken.no
 harshraval.in
 hd11315.com
 hdkamera2003.hu
+hdrest.fastlinktz.com
 hds.sz4h.com
 healthy20.net
 heavymaq.cl
@@ -4245,7 +4217,6 @@ hoayeuthuong-my.sharepoint.com
 homefindersolutions.com
 hongluosi.com
 hookedupboatclub.com
-hostelkielce.com
 hostzaa.com
 houstonshutters.site
 hr2019.vrcom7.com
@@ -4264,7 +4235,6 @@ idvindia.com
 iesanjosemonitos.edu.co
 ikexpert.com
 ilrafrica.com
-images.jermiau.com
 imbueautoworx.co.za
 incodimsa.com
 incrediblepixels.com
@@ -4282,8 +4252,10 @@ intersel-idf.org
 intuitiveideas.com.my
 inversiones.arrayanfinanciero.cl
 invest.xpcorporative.com.br
+investinae.com
 ipmes.ma
 iremart.es
+iris101.co.uk
 isaac.mikhailmotoringschool.com
 iscamenabe.com
 ismf.com.ng
@@ -4294,7 +4266,6 @@ isso.ps
 it123.ru
 itc-demo.softgig.co.ke
 itconsultus.com.co
-jamesjorgensen.newreadermedia.net
 jamiekaylive.com
 jamshed.pk
 jansen-heesch.nl
@@ -4302,7 +4273,6 @@ jathra.co.uk
 jay.diamondrelationscrm.us
 jebs.net.au
 jeffdahlke.com
-jewsjuice.com
 jhayesconsulting.com
 jiaoyuzixun.cn
 jing-da.com.tw
@@ -4317,14 +4287,11 @@ josuarochoa.com
 jpwoodfordco.com
 jumpmanualjacobhiller.com
 jupiter.toxsl.in
-jurgensen.newreadermedia.net
 justinscott.com.au
-kaizenjanitorial.com
 kalawatihomes.com
 kalpataru-elitus-mulund.thakkers.in
 karer.by
 katanvetov.co.il
-kbdom.com
 kensingtondriving.com
 kevinjewelry.com.co
 keywatch.yourpageserver.com
@@ -4362,7 +4329,6 @@ lidoraggiodisole.it
 lifebeam.elin.co.za
 lindnerelektroanlagen.de
 linkintec.cn
-litroxlitro.com
 livetrack.in
 lloydsindian.co.uk
 lm.stagingarea.co.za
@@ -4376,11 +4342,8 @@ login.trezor.com.stockfootagesindia.com
 logotypfabriken.se
 lotix.de
 lotusanddragonfly.com
-lp.carrduci.com
 lp.definerisco.com
 lp.difusodesign.com
-lp.juancamilogarciareyes.com
-lp.tecnimasdecolombia.com.co
 ltc.typoten.com
 luckybrownie.com
 luminouspneuma.com
@@ -4410,6 +4373,7 @@ masjidhabeebiyarazviya.mysunni.com
 materialescantu.com
 matruchhaya.co.in
 mattysplayground.com
+maxiquim.cl
 maxtox.com.pk
 mbgrm.com
 mbsolutions.ge
@@ -4419,6 +4383,7 @@ media-server.skyinternet.com.pk
 mediamaster.co.za
 medianews.ge
 medistaffconsulting.com
+meditreat.itwebservice.in
 meeweb.com
 megamart.afnan-amc.com
 merbay.ru
@@ -4489,7 +4454,6 @@ nidhi.iexist.in
 nikanpolimer.ir
 nilehouse.co.ug
 nilinkeji.com
-nisacooks.com
 njtiledesigncenter.com
 nobius.org
 nocalnoodle.elin.co.za
@@ -4504,7 +4468,6 @@ nuwagi.com
 nyeh2o.com.au
 oakleyandfriends.co.uk
 obseques-conseils.com
-ocean.tecnasulstore.com.br
 ohe.ie
 ohsewgorgeous.co.uk
 oknoplastik.sk
@@ -4555,7 +4518,6 @@ payerrealty.com
 payments.atifsiddiqui.me
 pcsoori.com
 pd.oceaniarp.net
-perpus.onlineman7-jombang.sch.id
 perpustekim.untirta.ac.id
 petercollie.com
 ph4s.ru
@@ -4576,6 +4538,7 @@ posmicrosystems.com
 poulman.panagiotopoulos-tours.gr
 ppdb.smk-ciptaskill.sch.id
 pptvideotemplates.com
+prestasicash.com.ar
 prestigehomeautomation.net
 prishaartcreations.com
 production.sparshims.com
@@ -4589,7 +4552,6 @@ prosoc.nl
 prosyarmakassar.com
 provence.elin.co.za
 prueba.danielluza.com
-ptpmeccatronica.eu
 pujashoppe.in
 punchdialogues.com
 punjabdevelopersassociation.com.pk
@@ -4641,7 +4603,6 @@ rs-toolkit.mikestclair.org
 rsgym.net
 rubazar.pro
 rubycityvietnam.com
-ruch.newreadermedia.net
 ruisgood.ru
 ruwadalkuwait.com
 rydchile.cl
@@ -4675,6 +4636,7 @@ sentierodelviandante.ml
 serendibsourcing.com
 servicemhkd.myvnc.com
 servicemhkd80.myvnc.com
+serviciovirtual.com.ar
 seyranikenger.com.tr
 sgessy.com.br
 shaheentbfoundation.com
@@ -4689,7 +4651,6 @@ shop.goldspot.agency
 shopsofe.com
 shrushtiinfotech.com
 sibernetix.fr
-siddharthpanditpautra.com
 sige.brisainformatica.com.br
 signatureads.co.in
 siili.net
@@ -4740,7 +4701,8 @@ static.3001.net
 statsres.com
 statssound.com
 statsspot.com
-stattilion.bar
+statsvilla.com
+stemschool.net
 stiepancasetia.ac.id
 stott-thompson.co.uk
 stratexec.co.za
@@ -4752,13 +4714,13 @@ sunmarkholidays.com
 supermercadostia.com
 support-4-free.com
 support.clz.kr
+supportit.online
 sw.yourpageserver.com
 sweaty.dk
 sweet-diet.com
 swentsai.com
 swiftlogisticseg.com
 swwbia.com
-syedpro.dezinetimes.com
 syracusecoffee.com
 sys.pbmadu.co.id
 sytraders.co
@@ -4772,6 +4734,7 @@ taltus.co.uk
 tapalkoedacoffee.com
 tarravalleyfoods.com.au
 taurus.ug
+tavo.cl
 taxicabsrilanka.com
 taxpos.com
 tc.snpsresidential.com
@@ -4792,6 +4755,7 @@ test.adventser.com
 test.letraele.es
 test.typoten.com
 test.wanepghana.org
+test1.asistencia247.com
 test1.milenial.id
 test1.tenplusone.my
 test2.basis-web.com
@@ -4858,7 +4822,7 @@ uniengrisb.com
 unisoftcc.com
 unyazitelecom.com
 upcbpta.com
-urbane.dezinetimes.com
+urbantrapfest.cl
 useformoney.000webhostapp.com
 usmadetshirts.com
 uss.ac.th
@@ -4867,7 +4831,6 @@ vbcargo.hu
 vcah.co.uk
 vegadelcasero.cl
 vendas.lidiacarmeli.com.br
-verify.aicosoft.com
 vfocus.net
 vidmattic.com
 vienen.gblix.srv.br
@@ -4885,6 +4848,7 @@ vladimirinternational.com
 vokasi.ub.ac.id
 vologroup.com.br
 voteyouramerica.dekitout.com
+vpinversiones.cl
 vstsample.com
 vtube.fadlymotivator.com
 vvsskmodinationalschool.com
@@ -4939,6 +4903,5 @@ yp.hnggzyjy.cn
 yskadvisors.com
 yummyyogaudaipur.com
 yzkzixun.com
-zakra.tecnasulstore.com.br
 zytrox.tk
 zz.690tx.com
diff --git a/urlhaus-filter-domains.txt b/urlhaus-filter-domains.txt
index 28205a86..8786c9ae 100644
--- a/urlhaus-filter-domains.txt
+++ b/urlhaus-filter-domains.txt
@@ -1,5 +1,5 @@
 # Title: Malicious Domains Blocklist
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1867,6 +1867,7 @@
 101.108.142.60
 101.108.142.75
 101.108.142.82
+101.108.142.9
 101.108.143.105
 101.108.143.110
 101.108.143.137
@@ -2393,6 +2394,7 @@
 101.66.80.23
 101.66.80.72
 101.66.81.166
+101.66.81.70
 101.67.176.237
 101.67.180.154
 101.67.198.121
@@ -2972,6 +2974,7 @@
 103.126.100.31
 103.126.100.9
 103.126.217.58
+103.126.35.40
 103.127.104.16
 103.127.104.165
 103.127.104.184
@@ -4275,6 +4278,7 @@
 103.245.48.197
 103.245.49.135
 103.245.49.147
+103.245.49.180
 103.245.49.183
 103.245.49.204
 103.245.49.24
@@ -8722,6 +8726,7 @@
 107.173.160.139
 107.173.160.14
 107.173.171.123
+107.173.171.143
 107.173.171.168
 107.173.175.135
 107.173.176.100
@@ -12358,6 +12363,7 @@
 112.122.63.240
 112.122.63.54
 112.122.63.6
+112.122.63.70
 112.122.63.9
 112.122.90.208
 112.122.99.186
@@ -14453,6 +14459,7 @@
 112.235.188.86
 112.235.194.43
 112.235.210.15
+112.235.210.251
 112.235.217.106
 112.235.217.213
 112.235.219.224
@@ -16832,6 +16839,7 @@
 112.242.96.25
 112.242.96.4
 112.242.96.56
+112.242.97.131
 112.242.97.165
 112.242.97.195
 112.242.98.194
@@ -16886,6 +16894,7 @@
 112.245.177.136
 112.245.177.145
 112.245.177.215
+112.245.178.153
 112.245.179.96
 112.245.182.56
 112.245.182.9
@@ -17214,6 +17223,7 @@
 112.247.156.74
 112.247.158.19
 112.247.16.190
+112.247.16.222
 112.247.161.45
 112.247.161.83
 112.247.163.177
@@ -17281,6 +17291,7 @@
 112.247.248.76
 112.247.249.198
 112.247.249.82
+112.247.25.42
 112.247.250.193
 112.247.250.96
 112.247.251.11
@@ -18713,6 +18724,7 @@
 112.254.125.2
 112.254.127.63
 112.254.128.119
+112.254.128.160
 112.254.128.224
 112.254.129.79
 112.254.129.95
@@ -18816,6 +18828,7 @@
 112.254.188.12
 112.254.188.137
 112.254.188.19
+112.254.188.228
 112.254.188.35
 112.254.189.137
 112.254.189.16
@@ -21506,6 +21519,7 @@
 113.116.177.248
 113.116.177.29
 113.116.177.81
+113.116.177.90
 113.116.178.100
 113.116.178.133
 113.116.178.138
@@ -22345,6 +22359,7 @@
 113.116.89.25
 113.116.89.29
 113.116.89.40
+113.116.89.41
 113.116.89.45
 113.116.89.55
 113.116.89.82
@@ -22699,6 +22714,7 @@
 113.118.159.142
 113.118.159.144
 113.118.159.153
+113.118.159.178
 113.118.159.215
 113.118.159.22
 113.118.159.232
@@ -23152,6 +23168,7 @@
 113.118.87.84
 113.118.87.88
 113.119.36.91
+113.119.37.141
 113.119.85.16
 113.122.238.68
 113.122.32.245
@@ -26886,6 +26903,7 @@
 113.88.39.104
 113.88.39.194
 113.88.39.2
+113.88.39.21
 113.88.39.35
 113.88.39.37
 113.88.39.55
@@ -27594,6 +27612,7 @@
 113.90.26.54
 113.90.26.6
 113.90.27.178
+113.90.27.218
 113.90.92.191
 113.90.93.98
 113.90.94.120
@@ -27721,6 +27740,7 @@
 113.92.196.102
 113.92.196.116
 113.92.196.145
+113.92.196.173
 113.92.196.192
 113.92.196.227
 113.92.196.235
@@ -30187,6 +30207,7 @@
 115.205.14.76
 115.205.15.79
 115.205.171.34
+115.205.197.221
 115.205.235.30
 115.205.66.30
 115.205.70.49
@@ -32676,6 +32697,7 @@
 115.48.201.222
 115.48.201.244
 115.48.201.255
+115.48.201.26
 115.48.201.31
 115.48.201.37
 115.48.201.40
@@ -33513,6 +33535,7 @@
 115.48.40.227
 115.48.40.3
 115.48.40.63
+115.48.41.101
 115.48.41.141
 115.48.41.156
 115.48.41.184
@@ -34453,6 +34476,7 @@
 115.49.24.52
 115.49.24.58
 115.49.24.60
+115.49.24.63
 115.49.240.125
 115.49.240.14
 115.49.240.147
@@ -36543,6 +36567,7 @@
 115.50.168.145
 115.50.168.153
 115.50.168.159
+115.50.168.160
 115.50.168.168
 115.50.168.183
 115.50.168.19
@@ -36685,6 +36710,7 @@
 115.50.171.172
 115.50.171.184
 115.50.171.188
+115.50.171.192
 115.50.171.196
 115.50.171.248
 115.50.171.250
@@ -37470,6 +37496,7 @@
 115.50.211.56
 115.50.211.62
 115.50.211.65
+115.50.211.74
 115.50.211.8
 115.50.211.80
 115.50.212.1
@@ -38653,6 +38680,7 @@
 115.50.242.244
 115.50.242.246
 115.50.242.43
+115.50.242.7
 115.50.242.81
 115.50.242.89
 115.50.243.10
@@ -38770,6 +38798,7 @@
 115.50.247.245
 115.50.247.33
 115.50.247.40
+115.50.247.46
 115.50.247.47
 115.50.247.56
 115.50.247.80
@@ -40643,6 +40672,7 @@
 115.50.79.50
 115.50.79.7
 115.50.79.73
+115.50.79.78
 115.50.79.95
 115.50.8.131
 115.50.8.159
@@ -41823,6 +41853,7 @@
 115.51.58.162
 115.51.61.137
 115.51.7.177
+115.51.7.254
 115.51.78.11
 115.51.88.101
 115.51.88.11
@@ -42458,6 +42489,7 @@
 115.52.172.58
 115.52.172.63
 115.52.172.64
+115.52.172.72
 115.52.172.74
 115.52.172.91
 115.52.172.93
@@ -43809,6 +43841,7 @@
 115.53.56.72
 115.53.57.189
 115.53.58.162
+115.53.58.228
 115.53.58.24
 115.53.59.170
 115.53.59.68
@@ -43924,6 +43957,7 @@
 115.54.112.31
 115.54.113.101
 115.54.113.128
+115.54.113.49
 115.54.114.20
 115.54.114.211
 115.54.115.1
@@ -44112,6 +44146,7 @@
 115.54.158.17
 115.54.158.176
 115.54.158.210
+115.54.158.251
 115.54.158.255
 115.54.158.67
 115.54.159.101
@@ -45801,6 +45836,7 @@
 115.55.126.58
 115.55.126.59
 115.55.126.88
+115.55.127.0
 115.55.127.101
 115.55.127.126
 115.55.127.146
@@ -48041,6 +48077,7 @@
 115.55.197.78
 115.55.197.99
 115.55.198.103
+115.55.198.105
 115.55.198.117
 115.55.198.127
 115.55.198.143
@@ -48843,6 +48880,7 @@
 115.55.52.113
 115.55.52.125
 115.55.52.136
+115.55.52.17
 115.55.52.200
 115.55.52.206
 115.55.52.208
@@ -49748,6 +49786,7 @@
 115.56.131.136
 115.56.131.144
 115.56.131.148
+115.56.131.150
 115.56.131.166
 115.56.131.170
 115.56.131.186
@@ -49997,6 +50036,7 @@
 115.56.135.237
 115.56.135.247
 115.56.135.250
+115.56.135.255
 115.56.135.28
 115.56.135.33
 115.56.135.36
@@ -50417,6 +50457,7 @@
 115.56.142.39
 115.56.142.4
 115.56.142.44
+115.56.142.45
 115.56.142.49
 115.56.142.5
 115.56.142.66
@@ -50744,6 +50785,7 @@
 115.56.150.130
 115.56.150.139
 115.56.150.14
+115.56.150.149
 115.56.150.150
 115.56.150.152
 115.56.150.156
@@ -50993,6 +51035,7 @@
 115.56.155.38
 115.56.155.42
 115.56.155.43
+115.56.155.50
 115.56.155.51
 115.56.155.54
 115.56.155.64
@@ -52594,6 +52637,7 @@
 115.56.27.88
 115.56.3.209
 115.56.31.10
+115.56.31.11
 115.56.31.156
 115.56.31.170
 115.56.31.176
@@ -54742,6 +54786,7 @@
 115.58.91.225
 115.58.91.240
 115.58.91.52
+115.58.91.65
 115.58.91.74
 115.58.91.86
 115.58.91.9
@@ -57992,6 +58037,7 @@
 115.61.112.13
 115.61.112.14
 115.61.112.140
+115.61.112.159
 115.61.112.161
 115.61.112.168
 115.61.112.185
@@ -58629,6 +58675,7 @@
 115.61.158.55
 115.61.158.90
 115.61.158.93
+115.61.158.98
 115.61.159.102
 115.61.159.115
 115.61.159.118
@@ -60153,6 +60200,7 @@
 115.62.170.41
 115.62.170.82
 115.62.170.91
+115.62.171.143
 115.62.171.177
 115.62.171.71
 115.62.171.81
@@ -60547,6 +60595,7 @@
 115.63.131.168
 115.63.131.169
 115.63.131.170
+115.63.131.173
 115.63.131.176
 115.63.131.229
 115.63.131.230
@@ -60778,6 +60827,7 @@
 115.63.139.178
 115.63.139.183
 115.63.139.186
+115.63.139.187
 115.63.139.229
 115.63.139.246
 115.63.139.25
@@ -68428,6 +68478,7 @@
 115.97.139.254
 115.97.139.28
 115.97.139.3
+115.97.139.32
 115.97.139.35
 115.97.139.4
 115.97.139.43
@@ -92780,6 +92831,7 @@
 116.68.98.160
 116.68.98.163
 116.68.98.17
+116.68.98.173
 116.68.98.178
 116.68.98.182
 116.68.98.184
@@ -94890,6 +94942,7 @@
 116.72.28.187
 116.72.28.204
 116.72.28.226
+116.72.28.239
 116.72.28.48
 116.72.28.49
 116.72.28.76
@@ -96507,6 +96560,7 @@
 116.73.52.121
 116.73.52.122
 116.73.52.124
+116.73.52.125
 116.73.52.127
 116.73.52.13
 116.73.52.132
@@ -98338,6 +98392,7 @@
 116.73.99.95
 116.73.99.97
 116.74.101.118
+116.74.101.150
 116.74.101.161
 116.74.101.177
 116.74.101.210
@@ -100254,6 +100309,7 @@
 116.74.23.37
 116.74.23.44
 116.74.23.45
+116.74.23.46
 116.74.23.48
 116.74.23.51
 116.74.23.52
@@ -100345,6 +100401,7 @@
 116.74.24.75
 116.74.24.76
 116.74.24.79
+116.74.24.8
 116.74.24.82
 116.74.24.84
 116.74.24.85
@@ -111715,6 +111772,7 @@
 116.88.65.131
 116.9.145.199
 116.9.43.106
+116.9.43.220
 116.9.43.235
 116.90.238.142
 116.91.202.79
@@ -112816,6 +112874,7 @@
 117.194.148.188
 117.194.148.189
 117.194.148.190
+117.194.148.198
 117.194.148.202
 117.194.148.205
 117.194.148.207
@@ -113098,6 +113157,7 @@
 117.194.151.176
 117.194.151.178
 117.194.151.180
+117.194.151.184
 117.194.151.192
 117.194.151.196
 117.194.151.198
@@ -114049,6 +114109,7 @@
 117.194.164.97
 117.194.164.99
 117.194.165.0
+117.194.165.1
 117.194.165.100
 117.194.165.101
 117.194.165.102
@@ -114740,6 +114801,7 @@
 117.196.48.178
 117.196.48.179
 117.196.48.180
+117.196.48.181
 117.196.48.183
 117.196.48.184
 117.196.48.185
@@ -115030,6 +115092,7 @@
 117.196.50.147
 117.196.50.15
 117.196.50.150
+117.196.50.154
 117.196.50.158
 117.196.50.161
 117.196.50.164
@@ -115073,6 +115136,7 @@
 117.196.50.23
 117.196.50.230
 117.196.50.236
+117.196.50.239
 117.196.50.24
 117.196.50.240
 117.196.50.241
@@ -115117,6 +115181,7 @@
 117.196.50.7
 117.196.50.71
 117.196.50.72
+117.196.50.76
 117.196.50.77
 117.196.50.78
 117.196.50.79
@@ -115995,6 +116060,7 @@
 117.202.66.40
 117.202.66.41
 117.202.66.42
+117.202.66.44
 117.202.66.45
 117.202.66.46
 117.202.66.47
@@ -117611,6 +117677,7 @@
 117.207.47.96
 117.207.5.156
 117.207.50.5
+117.208.132.10
 117.208.132.101
 117.208.132.102
 117.208.132.103
@@ -117884,6 +117951,7 @@
 117.208.133.86
 117.208.133.87
 117.208.133.9
+117.208.133.91
 117.208.133.92
 117.208.133.97
 117.208.134.0
@@ -119325,6 +119393,7 @@
 117.213.41.74
 117.213.41.75
 117.213.41.78
+117.213.41.8
 117.213.41.80
 117.213.41.82
 117.213.41.83
@@ -120268,6 +120337,7 @@
 117.213.47.134
 117.213.47.136
 117.213.47.138
+117.213.47.139
 117.213.47.14
 117.213.47.140
 117.213.47.142
@@ -120527,6 +120597,7 @@
 117.215.210.230
 117.215.210.243
 117.215.210.245
+117.215.210.249
 117.215.210.25
 117.215.210.250
 117.215.210.251
@@ -120588,6 +120659,7 @@
 117.215.212.153
 117.215.212.166
 117.215.212.168
+117.215.212.174
 117.215.212.176
 117.215.212.180
 117.215.212.182
@@ -120729,6 +120801,7 @@
 117.215.248.158
 117.215.248.17
 117.215.248.181
+117.215.248.198
 117.215.248.20
 117.215.248.201
 117.215.248.205
@@ -121572,6 +121645,7 @@
 117.222.162.70
 117.222.162.71
 117.222.162.72
+117.222.162.73
 117.222.162.74
 117.222.162.75
 117.222.162.76
@@ -122345,6 +122419,7 @@
 117.222.166.28
 117.222.166.3
 117.222.166.30
+117.222.166.36
 117.222.166.38
 117.222.166.39
 117.222.166.4
@@ -122821,6 +122896,7 @@
 117.222.170.217
 117.222.170.223
 117.222.170.224
+117.222.170.234
 117.222.170.237
 117.222.170.238
 117.222.170.239
@@ -124469,6 +124545,7 @@
 117.242.210.238
 117.242.210.239
 117.242.210.24
+117.242.210.240
 117.242.210.241
 117.242.210.244
 117.242.210.246
@@ -124749,6 +124826,7 @@
 117.242.48.212
 117.242.48.232
 117.242.48.57
+117.242.49.157
 117.242.49.166
 117.242.49.185
 117.242.49.21
@@ -126494,6 +126572,7 @@
 117.248.63.61
 117.248.63.62
 117.248.63.67
+117.248.63.70
 117.248.63.73
 117.248.63.74
 117.248.63.75
@@ -127586,6 +127665,7 @@
 117.251.63.206
 117.251.63.207
 117.251.63.209
+117.251.63.21
 117.251.63.211
 117.251.63.212
 117.251.63.214
@@ -128461,6 +128541,7 @@
 118.113.244.200
 118.113.245.110
 118.114.216.131
+118.114.84.237
 118.116.192.103
 118.116.192.53
 118.117.167.48
@@ -128780,6 +128861,7 @@
 118.172.224.136
 118.172.224.179
 118.172.224.205
+118.172.224.37
 118.172.231.79
 118.172.232.164
 118.172.234.157
@@ -130316,6 +130398,7 @@
 118.79.91.203
 118.79.92.29
 118.79.93.194
+118.79.96.11
 118.79.96.249
 118.79.96.9
 118.79.97.100
@@ -130632,6 +130715,7 @@
 119.118.128.127
 119.118.139.228
 119.118.143.250
+119.118.150.84
 119.118.161.115
 119.118.167.179
 119.118.172.168
@@ -131012,6 +131096,7 @@
 119.123.173.46
 119.123.173.73
 119.123.173.91
+119.123.173.95
 119.123.173.96
 119.123.174.102
 119.123.174.11
@@ -131056,6 +131141,7 @@
 119.123.175.174
 119.123.175.175
 119.123.175.185
+119.123.175.210
 119.123.175.215
 119.123.175.222
 119.123.175.228
@@ -131274,6 +131360,7 @@
 119.123.219.194
 119.123.219.204
 119.123.219.230
+119.123.219.232
 119.123.219.234
 119.123.219.240
 119.123.219.247
@@ -131317,6 +131404,7 @@
 119.123.221.5
 119.123.221.6
 119.123.221.74
+119.123.221.94
 119.123.222.0
 119.123.222.112
 119.123.222.128
@@ -131457,6 +131545,7 @@
 119.123.239.109
 119.123.239.117
 119.123.239.122
+119.123.239.131
 119.123.239.142
 119.123.239.153
 119.123.239.180
@@ -137597,6 +137686,7 @@
 120.57.214.195
 120.57.214.200
 120.57.214.223
+120.57.214.228
 120.57.214.251
 120.57.214.38
 120.57.214.44
@@ -139449,6 +139539,7 @@
 120.6.233.250
 120.6.239.231
 120.6.240.130
+120.6.241.130
 120.6.242.41
 120.6.248.88
 120.6.4.156
@@ -140461,6 +140552,7 @@
 120.85.196.179
 120.85.196.196
 120.85.196.205
+120.85.196.211
 120.85.196.217
 120.85.196.220
 120.85.196.23
@@ -140560,6 +140652,7 @@
 120.85.199.91
 120.85.199.97
 120.85.208.103
+120.85.208.107
 120.85.208.111
 120.85.208.114
 120.85.208.121
@@ -140738,6 +140831,7 @@
 120.85.238.0
 120.85.238.10
 120.85.238.107
+120.85.238.129
 120.85.238.13
 120.85.238.137
 120.85.238.139
@@ -140754,6 +140848,7 @@
 120.85.238.218
 120.85.238.219
 120.85.238.233
+120.85.238.238
 120.85.238.240
 120.85.238.244
 120.85.238.25
@@ -145412,6 +145507,7 @@
 123.11.125.93
 123.11.126.117
 123.11.126.2
+123.11.126.225
 123.11.126.241
 123.11.126.62
 123.11.126.76
@@ -146829,6 +146925,7 @@
 123.11.62.73
 123.11.62.76
 123.11.63.112
+123.11.63.113
 123.11.63.133
 123.11.63.170
 123.11.63.180
@@ -147453,6 +147550,7 @@
 123.12.185.95
 123.12.186.64
 123.12.187.224
+123.12.189.247
 123.12.189.252
 123.12.189.93
 123.12.19.142
@@ -147564,6 +147662,7 @@
 123.12.225.250
 123.12.225.254
 123.12.225.62
+123.12.225.70
 123.12.225.90
 123.12.225.94
 123.12.226.11
@@ -147904,6 +148003,7 @@
 123.12.243.76
 123.12.243.82
 123.12.243.83
+123.12.243.85
 123.12.243.89
 123.12.243.95
 123.12.243.99
@@ -149462,6 +149562,7 @@
 123.130.254.2
 123.130.26.116
 123.130.27.172
+123.130.27.19
 123.130.28.103
 123.130.28.105
 123.130.28.213
@@ -150427,6 +150528,7 @@
 123.14.127.174
 123.14.127.209
 123.14.127.219
+123.14.127.238
 123.14.127.243
 123.14.127.250
 123.14.127.33
@@ -150769,6 +150871,7 @@
 123.14.173.130
 123.14.173.154
 123.14.173.159
+123.14.173.199
 123.14.173.202
 123.14.173.218
 123.14.174.128
@@ -151257,6 +151360,7 @@
 123.14.249.250
 123.14.249.253
 123.14.249.30
+123.14.249.33
 123.14.249.34
 123.14.249.38
 123.14.249.46
@@ -151509,6 +151613,7 @@
 123.14.34.184
 123.14.34.200
 123.14.34.222
+123.14.34.240
 123.14.34.246
 123.14.34.36
 123.14.34.42
@@ -151564,6 +151669,7 @@
 123.14.37.215
 123.14.37.228
 123.14.37.231
+123.14.37.32
 123.14.37.81
 123.14.38.0
 123.14.38.11
@@ -151711,6 +151817,7 @@
 123.14.50.184
 123.14.50.185
 123.14.50.207
+123.14.50.214
 123.14.50.221
 123.14.50.251
 123.14.50.3
@@ -152491,6 +152598,7 @@
 123.153.59.88
 123.153.80.178
 123.153.88.252
+123.154.116.116
 123.154.116.130
 123.154.116.155
 123.154.116.19
@@ -154351,6 +154459,7 @@
 123.4.194.144
 123.4.194.147
 123.4.194.15
+123.4.194.152
 123.4.194.167
 123.4.194.173
 123.4.194.18
@@ -154563,6 +154672,7 @@
 123.4.213.128
 123.4.213.152
 123.4.213.169
+123.4.213.239
 123.4.213.74
 123.4.213.83
 123.4.214.10
@@ -155115,6 +155225,7 @@
 123.4.45.112
 123.4.45.192
 123.4.45.221
+123.4.45.31
 123.4.45.4
 123.4.45.7
 123.4.46.136
@@ -159753,6 +159864,7 @@
 123.8.71.235
 123.8.71.243
 123.8.71.246
+123.8.71.27
 123.8.71.32
 123.8.71.7
 123.8.71.82
@@ -161025,6 +161137,7 @@
 123.9.239.80
 123.9.240.102
 123.9.240.103
+123.9.240.115
 123.9.240.138
 123.9.240.146
 123.9.240.16
@@ -162384,6 +162497,7 @@
 124.131.136.92
 124.131.137.113
 124.131.137.137
+124.131.137.147
 124.131.137.183
 124.131.137.190
 124.131.137.192
@@ -162744,6 +162858,7 @@
 124.131.23.131
 124.131.23.177
 124.131.239.254
+124.131.24.185
 124.131.24.187
 124.131.24.219
 124.131.24.229
@@ -164134,6 +164249,7 @@
 124.92.133.100
 124.92.135.150
 124.92.135.30
+124.92.135.37
 124.92.137.146
 124.92.137.71
 124.92.139.198
@@ -164377,6 +164493,7 @@
 125.106.44.171
 125.106.45.123
 125.106.45.200
+125.106.46.225
 125.106.47.217
 125.106.48.237
 125.106.48.250
@@ -167518,6 +167635,7 @@
 125.41.164.56
 125.41.164.59
 125.41.164.6
+125.41.164.60
 125.41.164.69
 125.41.164.92
 125.41.164.93
@@ -167713,6 +167831,7 @@
 125.41.184.230
 125.41.184.251
 125.41.185.110
+125.41.185.186
 125.41.185.237
 125.41.185.252
 125.41.185.65
@@ -167871,6 +167990,7 @@
 125.41.191.8
 125.41.191.88
 125.41.196.104
+125.41.196.114
 125.41.196.119
 125.41.196.128
 125.41.196.132
@@ -169759,6 +169879,7 @@
 125.41.97.224
 125.41.97.226
 125.41.97.228
+125.41.97.231
 125.41.97.234
 125.41.97.237
 125.41.97.238
@@ -173145,6 +173266,7 @@
 125.43.6.111
 125.43.6.114
 125.43.6.138
+125.43.6.186
 125.43.6.191
 125.43.6.204
 125.43.6.216
@@ -173239,6 +173361,7 @@
 125.43.63.252
 125.43.63.39
 125.43.63.46
+125.43.63.47
 125.43.63.49
 125.43.63.50
 125.43.63.55
@@ -174992,6 +175115,7 @@
 125.44.207.72
 125.44.207.91
 125.44.207.97
+125.44.208.152
 125.44.208.153
 125.44.208.164
 125.44.208.165
@@ -175470,6 +175594,7 @@
 125.44.227.242
 125.44.227.248
 125.44.227.4
+125.44.227.51
 125.44.227.65
 125.44.227.69
 125.44.228.124
@@ -176413,6 +176538,7 @@
 125.44.70.28
 125.44.70.31
 125.44.70.5
+125.44.70.64
 125.44.70.68
 125.44.70.87
 125.44.71.10
@@ -177125,6 +177251,7 @@
 125.45.43.19
 125.45.43.190
 125.45.43.209
+125.45.43.63
 125.45.43.78
 125.45.48.101
 125.45.48.154
@@ -178192,6 +178319,7 @@
 125.46.165.83
 125.46.166.10
 125.46.166.101
+125.46.166.112
 125.46.166.121
 125.46.166.123
 125.46.166.125
@@ -179424,6 +179552,7 @@
 125.47.124.60
 125.47.124.62
 125.47.125.129
+125.47.125.16
 125.47.126.230
 125.47.126.53
 125.47.126.63
@@ -180393,6 +180522,7 @@
 125.47.248.117
 125.47.248.119
 125.47.248.124
+125.47.248.131
 125.47.248.135
 125.47.248.141
 125.47.248.142
@@ -180899,9 +181029,11 @@
 125.47.37.56
 125.47.37.68
 125.47.38.10
+125.47.38.114
 125.47.38.119
 125.47.38.124
 125.47.38.132
+125.47.38.142
 125.47.38.152
 125.47.38.168
 125.47.38.17
@@ -181002,6 +181134,7 @@
 125.47.47.198
 125.47.47.209
 125.47.47.21
+125.47.47.212
 125.47.47.217
 125.47.47.220
 125.47.47.233
@@ -182998,6 +183131,7 @@
 125.99.220.202
 125.99.220.216
 125.99.222.152
+125.99.222.2
 125.99.222.245
 125.99.222.76
 125.99.223.227
@@ -185548,6 +185682,7 @@
 139.213.7.128
 139.213.7.230
 139.213.96.26
+139.213.97.191
 139.213.97.23
 139.214.62.66
 139.214.62.96
@@ -185776,6 +185911,7 @@
 14.109.109.129
 14.109.111.219
 14.109.112.100
+14.109.126.96
 14.113.12.153
 14.113.13.184
 14.113.14.145
@@ -186795,6 +186931,7 @@
 140.237.28.148
 140.237.29.28
 140.237.30.113
+140.237.30.172
 140.237.30.179
 140.237.30.188
 140.237.31.197
@@ -187598,6 +187735,7 @@
 149.255.15.112
 149.255.15.121
 149.255.15.134
+149.255.15.172
 149.255.15.180
 149.255.15.182
 149.255.15.184
@@ -190282,6 +190420,7 @@
 163.125.2.36
 163.125.2.67
 163.125.200.107
+163.125.200.118
 163.125.200.126
 163.125.200.129
 163.125.200.13
@@ -190303,6 +190442,7 @@
 163.125.200.230
 163.125.200.233
 163.125.200.238
+163.125.200.242
 163.125.200.247
 163.125.200.37
 163.125.200.40
@@ -190391,6 +190531,7 @@
 163.125.202.235
 163.125.202.245
 163.125.202.246
+163.125.202.255
 163.125.202.27
 163.125.202.4
 163.125.202.57
@@ -190398,6 +190539,7 @@
 163.125.202.74
 163.125.202.8
 163.125.202.83
+163.125.202.87
 163.125.202.9
 163.125.203.10
 163.125.203.118
@@ -190415,6 +190557,7 @@
 163.125.203.213
 163.125.203.214
 163.125.203.23
+163.125.203.236
 163.125.203.32
 163.125.203.33
 163.125.203.4
@@ -190473,6 +190616,7 @@
 163.125.206.133
 163.125.206.145
 163.125.206.151
+163.125.206.16
 163.125.206.162
 163.125.206.164
 163.125.206.187
@@ -190800,6 +190944,7 @@
 163.204.21.75
 163.204.210.243
 163.204.210.34
+163.204.211.136
 163.204.211.205
 163.204.211.228
 163.204.211.47
@@ -191887,6 +192032,7 @@
 168.187.202.184
 168.187.234.86
 168.194.110.39
+168.194.146.145
 168.194.176.180
 168.194.214.107
 168.194.214.113
@@ -192886,6 +193032,7 @@
 171.125.122.33
 171.125.122.54
 171.125.122.90
+171.125.122.91
 171.125.123.88
 171.125.124.133
 171.125.124.58
@@ -193149,6 +193296,7 @@
 171.125.65.193
 171.125.65.202
 171.125.65.22
+171.125.65.89
 171.125.66.6
 171.125.68.45
 171.125.7.181
@@ -198101,6 +198249,7 @@
 175.164.59.67
 175.164.6.45
 175.164.61.169
+175.164.61.215
 175.164.63.75
 175.164.63.94
 175.164.66.17
@@ -198243,6 +198392,7 @@
 175.169.118.51
 175.169.127.142
 175.169.127.205
+175.169.13.182
 175.169.15.220
 175.169.160.119
 175.169.163.231
@@ -201146,6 +201296,7 @@
 178.141.41.122
 178.141.41.125
 178.141.41.239
+178.141.44.152
 178.141.44.159
 178.141.44.184
 178.141.44.21
@@ -201409,6 +201560,7 @@
 178.175.1.155
 178.175.1.157
 178.175.1.159
+178.175.1.16
 178.175.1.161
 178.175.1.162
 178.175.1.164
@@ -201416,6 +201568,7 @@
 178.175.1.172
 178.175.1.174
 178.175.1.175
+178.175.1.176
 178.175.1.178
 178.175.1.179
 178.175.1.182
@@ -201451,6 +201604,7 @@
 178.175.1.33
 178.175.1.34
 178.175.1.43
+178.175.1.44
 178.175.1.46
 178.175.1.48
 178.175.1.5
@@ -201480,6 +201634,7 @@
 178.175.10.108
 178.175.10.113
 178.175.10.12
+178.175.10.121
 178.175.10.124
 178.175.10.125
 178.175.10.133
@@ -201499,6 +201654,7 @@
 178.175.10.173
 178.175.10.175
 178.175.10.177
+178.175.10.178
 178.175.10.182
 178.175.10.184
 178.175.10.186
@@ -201577,6 +201733,7 @@
 178.175.100.185
 178.175.100.187
 178.175.100.190
+178.175.100.191
 178.175.100.193
 178.175.100.2
 178.175.100.201
@@ -201615,6 +201772,7 @@
 178.175.100.48
 178.175.100.49
 178.175.100.5
+178.175.100.52
 178.175.100.54
 178.175.100.58
 178.175.100.61
@@ -201664,11 +201822,13 @@
 178.175.101.168
 178.175.101.170
 178.175.101.171
+178.175.101.173
 178.175.101.174
 178.175.101.177
 178.175.101.186
 178.175.101.187
 178.175.101.189
+178.175.101.191
 178.175.101.194
 178.175.101.196
 178.175.101.199
@@ -201880,8 +202040,10 @@
 178.175.103.233
 178.175.103.234
 178.175.103.239
+178.175.103.24
 178.175.103.242
 178.175.103.245
+178.175.103.246
 178.175.103.253
 178.175.103.26
 178.175.103.27
@@ -201947,6 +202109,7 @@
 178.175.104.145
 178.175.104.148
 178.175.104.15
+178.175.104.151
 178.175.104.152
 178.175.104.153
 178.175.104.154
@@ -201955,6 +202118,7 @@
 178.175.104.16
 178.175.104.161
 178.175.104.163
+178.175.104.166
 178.175.104.167
 178.175.104.169
 178.175.104.17
@@ -201974,6 +202138,7 @@
 178.175.104.195
 178.175.104.196
 178.175.104.198
+178.175.104.199
 178.175.104.200
 178.175.104.202
 178.175.104.206
@@ -201987,6 +202152,7 @@
 178.175.104.230
 178.175.104.234
 178.175.104.235
+178.175.104.239
 178.175.104.241
 178.175.104.243
 178.175.104.244
@@ -201995,6 +202161,7 @@
 178.175.104.252
 178.175.104.253
 178.175.104.255
+178.175.104.26
 178.175.104.27
 178.175.104.29
 178.175.104.34
@@ -202072,6 +202239,7 @@
 178.175.105.208
 178.175.105.21
 178.175.105.213
+178.175.105.214
 178.175.105.215
 178.175.105.217
 178.175.105.220
@@ -202080,6 +202248,7 @@
 178.175.105.235
 178.175.105.237
 178.175.105.238
+178.175.105.240
 178.175.105.245
 178.175.105.247
 178.175.105.248
@@ -202121,6 +202290,7 @@
 178.175.105.93
 178.175.105.94
 178.175.105.96
+178.175.105.99
 178.175.106.100
 178.175.106.102
 178.175.106.103
@@ -202140,6 +202310,7 @@
 178.175.106.136
 178.175.106.144
 178.175.106.146
+178.175.106.149
 178.175.106.15
 178.175.106.154
 178.175.106.156
@@ -202201,6 +202372,7 @@
 178.175.106.28
 178.175.106.31
 178.175.106.32
+178.175.106.36
 178.175.106.37
 178.175.106.42
 178.175.106.44
@@ -202220,6 +202392,7 @@
 178.175.106.78
 178.175.106.79
 178.175.106.8
+178.175.106.83
 178.175.106.84
 178.175.106.87
 178.175.106.9
@@ -202571,6 +202744,7 @@
 178.175.11.149
 178.175.11.150
 178.175.11.154
+178.175.11.155
 178.175.11.156
 178.175.11.157
 178.175.11.158
@@ -202604,6 +202778,7 @@
 178.175.11.23
 178.175.11.230
 178.175.11.235
+178.175.11.241
 178.175.11.243
 178.175.11.244
 178.175.11.246
@@ -202688,6 +202863,7 @@
 178.175.110.190
 178.175.110.191
 178.175.110.192
+178.175.110.194
 178.175.110.195
 178.175.110.197
 178.175.110.198
@@ -202838,6 +203014,7 @@
 178.175.112.103
 178.175.112.106
 178.175.112.109
+178.175.112.110
 178.175.112.113
 178.175.112.114
 178.175.112.117
@@ -203067,6 +203244,7 @@
 178.175.114.123
 178.175.114.124
 178.175.114.125
+178.175.114.127
 178.175.114.129
 178.175.114.13
 178.175.114.135
@@ -203277,6 +203455,7 @@
 178.175.116.1
 178.175.116.10
 178.175.116.100
+178.175.116.101
 178.175.116.103
 178.175.116.104
 178.175.116.106
@@ -203303,6 +203482,7 @@
 178.175.116.159
 178.175.116.165
 178.175.116.169
+178.175.116.170
 178.175.116.171
 178.175.116.174
 178.175.116.175
@@ -203783,6 +203963,7 @@
 178.175.12.78
 178.175.12.79
 178.175.12.91
+178.175.12.93
 178.175.12.97
 178.175.120.100
 178.175.120.101
@@ -203864,6 +204045,7 @@
 178.175.120.44
 178.175.120.47
 178.175.120.49
+178.175.120.5
 178.175.120.52
 178.175.120.57
 178.175.120.58
@@ -203916,6 +204098,8 @@
 178.175.121.180
 178.175.121.19
 178.175.121.190
+178.175.121.192
+178.175.121.193
 178.175.121.2
 178.175.121.202
 178.175.121.204
@@ -204157,6 +204341,7 @@
 178.175.123.247
 178.175.123.249
 178.175.123.255
+178.175.123.26
 178.175.123.27
 178.175.123.29
 178.175.123.3
@@ -204577,6 +204762,7 @@
 178.175.127.214
 178.175.127.216
 178.175.127.217
+178.175.127.219
 178.175.127.225
 178.175.127.228
 178.175.127.23
@@ -204599,6 +204785,7 @@
 178.175.127.35
 178.175.127.36
 178.175.127.38
+178.175.127.43
 178.175.127.45
 178.175.127.46
 178.175.127.53
@@ -204622,6 +204809,7 @@
 178.175.127.91
 178.175.127.92
 178.175.127.95
+178.175.127.97
 178.175.13.0
 178.175.13.1
 178.175.13.101
@@ -204716,6 +204904,7 @@
 178.175.14.126
 178.175.14.13
 178.175.14.130
+178.175.14.131
 178.175.14.141
 178.175.14.144
 178.175.14.152
@@ -205043,6 +205232,7 @@
 178.175.17.62
 178.175.17.63
 178.175.17.64
+178.175.17.66
 178.175.17.70
 178.175.17.74
 178.175.17.77
@@ -205255,6 +205445,7 @@
 178.175.2.18
 178.175.2.181
 178.175.2.184
+178.175.2.186
 178.175.2.187
 178.175.2.188
 178.175.2.189
@@ -205409,6 +205600,7 @@
 178.175.20.87
 178.175.20.93
 178.175.20.96
+178.175.20.97
 178.175.21.1
 178.175.21.110
 178.175.21.115
@@ -205606,6 +205798,7 @@
 178.175.23.184
 178.175.23.185
 178.175.23.187
+178.175.23.19
 178.175.23.198
 178.175.23.199
 178.175.23.201
@@ -205698,6 +205891,7 @@
 178.175.24.189
 178.175.24.190
 178.175.24.191
+178.175.24.198
 178.175.24.199
 178.175.24.200
 178.175.24.204
@@ -205971,6 +206165,7 @@
 178.175.27.122
 178.175.27.124
 178.175.27.125
+178.175.27.137
 178.175.27.138
 178.175.27.14
 178.175.27.143
@@ -206023,6 +206218,7 @@
 178.175.27.239
 178.175.27.24
 178.175.27.241
+178.175.27.244
 178.175.27.245
 178.175.27.246
 178.175.27.247
@@ -206111,6 +206307,7 @@
 178.175.28.198
 178.175.28.199
 178.175.28.20
+178.175.28.200
 178.175.28.202
 178.175.28.205
 178.175.28.206
@@ -206136,6 +206333,7 @@
 178.175.28.4
 178.175.28.5
 178.175.28.50
+178.175.28.51
 178.175.28.55
 178.175.28.59
 178.175.28.6
@@ -206143,6 +206341,7 @@
 178.175.28.64
 178.175.28.65
 178.175.28.66
+178.175.28.69
 178.175.28.7
 178.175.28.72
 178.175.28.74
@@ -206192,6 +206391,7 @@
 178.175.29.204
 178.175.29.205
 178.175.29.207
+178.175.29.208
 178.175.29.209
 178.175.29.219
 178.175.29.220
@@ -206228,6 +206428,7 @@
 178.175.29.55
 178.175.29.59
 178.175.29.6
+178.175.29.7
 178.175.29.72
 178.175.29.73
 178.175.29.77
@@ -206304,6 +206505,7 @@
 178.175.3.28
 178.175.3.3
 178.175.3.31
+178.175.3.32
 178.175.3.33
 178.175.3.34
 178.175.3.4
@@ -206316,6 +206518,7 @@
 178.175.3.58
 178.175.3.6
 178.175.3.62
+178.175.3.66
 178.175.3.68
 178.175.3.69
 178.175.3.72
@@ -206325,6 +206528,7 @@
 178.175.3.80
 178.175.3.81
 178.175.3.85
+178.175.3.87
 178.175.3.94
 178.175.3.98
 178.175.30.0
@@ -206483,6 +206687,7 @@
 178.175.31.247
 178.175.31.249
 178.175.31.251
+178.175.31.252
 178.175.31.253
 178.175.31.29
 178.175.31.3
@@ -206514,6 +206719,7 @@
 178.175.31.94
 178.175.31.97
 178.175.31.98
+178.175.31.99
 178.175.32.0
 178.175.32.1
 178.175.32.100
@@ -206533,6 +206739,7 @@
 178.175.32.133
 178.175.32.135
 178.175.32.138
+178.175.32.14
 178.175.32.140
 178.175.32.141
 178.175.32.142
@@ -206582,6 +206789,7 @@
 178.175.32.24
 178.175.32.241
 178.175.32.243
+178.175.32.244
 178.175.32.246
 178.175.32.248
 178.175.32.249
@@ -206653,6 +206861,7 @@
 178.175.33.186
 178.175.33.192
 178.175.33.193
+178.175.33.196
 178.175.33.198
 178.175.33.2
 178.175.33.202
@@ -206678,6 +206887,7 @@
 178.175.33.241
 178.175.33.242
 178.175.33.244
+178.175.33.245
 178.175.33.246
 178.175.33.255
 178.175.33.26
@@ -206896,6 +207106,7 @@
 178.175.35.85
 178.175.35.86
 178.175.35.89
+178.175.35.91
 178.175.35.92
 178.175.35.93
 178.175.35.96
@@ -206978,6 +207189,7 @@
 178.175.36.37
 178.175.36.46
 178.175.36.47
+178.175.36.5
 178.175.36.51
 178.175.36.52
 178.175.36.56
@@ -207096,6 +207308,7 @@
 178.175.37.67
 178.175.37.68
 178.175.37.70
+178.175.37.71
 178.175.37.74
 178.175.37.75
 178.175.37.76
@@ -207215,6 +207428,7 @@
 178.175.39.106
 178.175.39.107
 178.175.39.11
+178.175.39.110
 178.175.39.112
 178.175.39.113
 178.175.39.121
@@ -207285,6 +207499,7 @@
 178.175.39.57
 178.175.39.58
 178.175.39.61
+178.175.39.63
 178.175.39.71
 178.175.39.74
 178.175.39.76
@@ -207532,6 +207747,7 @@
 178.175.41.217
 178.175.41.221
 178.175.41.223
+178.175.41.224
 178.175.41.225
 178.175.41.229
 178.175.41.23
@@ -207620,9 +207836,11 @@
 178.175.42.228
 178.175.42.234
 178.175.42.235
+178.175.42.240
 178.175.42.243
 178.175.42.245
 178.175.42.247
+178.175.42.25
 178.175.42.253
 178.175.42.254
 178.175.42.255
@@ -207800,6 +208018,7 @@
 178.175.44.178
 178.175.44.179
 178.175.44.186
+178.175.44.188
 178.175.44.19
 178.175.44.191
 178.175.44.194
@@ -207928,6 +208147,7 @@
 178.175.45.241
 178.175.45.244
 178.175.45.246
+178.175.45.25
 178.175.45.250
 178.175.45.252
 178.175.45.253
@@ -208286,6 +208506,7 @@
 178.175.49.163
 178.175.49.166
 178.175.49.169
+178.175.49.177
 178.175.49.18
 178.175.49.180
 178.175.49.185
@@ -208299,6 +208520,7 @@
 178.175.49.208
 178.175.49.21
 178.175.49.213
+178.175.49.214
 178.175.49.215
 178.175.49.219
 178.175.49.221
@@ -208316,6 +208538,7 @@
 178.175.49.247
 178.175.49.248
 178.175.49.251
+178.175.49.252
 178.175.49.253
 178.175.49.3
 178.175.49.31
@@ -208425,6 +208648,7 @@
 178.175.5.68
 178.175.5.70
 178.175.5.71
+178.175.5.79
 178.175.5.84
 178.175.5.85
 178.175.5.88
@@ -208456,6 +208680,7 @@
 178.175.50.151
 178.175.50.152
 178.175.50.165
+178.175.50.168
 178.175.50.169
 178.175.50.173
 178.175.50.174
@@ -208493,6 +208718,7 @@
 178.175.50.27
 178.175.50.28
 178.175.50.3
+178.175.50.32
 178.175.50.33
 178.175.50.38
 178.175.50.40
@@ -208637,6 +208863,7 @@
 178.175.52.140
 178.175.52.141
 178.175.52.142
+178.175.52.146
 178.175.52.149
 178.175.52.15
 178.175.52.153
@@ -208658,6 +208885,7 @@
 178.175.52.200
 178.175.52.205
 178.175.52.206
+178.175.52.21
 178.175.52.211
 178.175.52.212
 178.175.52.216
@@ -208827,6 +209055,7 @@
 178.175.54.141
 178.175.54.142
 178.175.54.147
+178.175.54.15
 178.175.54.150
 178.175.54.151
 178.175.54.154
@@ -208834,6 +209063,7 @@
 178.175.54.162
 178.175.54.163
 178.175.54.165
+178.175.54.167
 178.175.54.172
 178.175.54.173
 178.175.54.178
@@ -209065,6 +209295,7 @@
 178.175.56.44
 178.175.56.48
 178.175.56.50
+178.175.56.52
 178.175.56.54
 178.175.56.55
 178.175.56.57
@@ -209100,6 +209331,7 @@
 178.175.57.119
 178.175.57.12
 178.175.57.121
+178.175.57.124
 178.175.57.126
 178.175.57.127
 178.175.57.129
@@ -209184,6 +209416,7 @@
 178.175.57.94
 178.175.57.95
 178.175.57.96
+178.175.57.99
 178.175.58.100
 178.175.58.101
 178.175.58.105
@@ -209325,6 +209558,7 @@
 178.175.59.237
 178.175.59.238
 178.175.59.239
+178.175.59.241
 178.175.59.243
 178.175.59.244
 178.175.59.245
@@ -209533,6 +209767,7 @@
 178.175.60.7
 178.175.60.70
 178.175.60.75
+178.175.60.76
 178.175.60.79
 178.175.60.8
 178.175.60.80
@@ -209623,6 +209858,7 @@
 178.175.61.9
 178.175.61.90
 178.175.61.91
+178.175.61.95
 178.175.61.96
 178.175.61.97
 178.175.62.1
@@ -209638,6 +209874,7 @@
 178.175.62.122
 178.175.62.123
 178.175.62.128
+178.175.62.141
 178.175.62.143
 178.175.62.150
 178.175.62.151
@@ -209776,6 +210013,7 @@
 178.175.63.227
 178.175.63.228
 178.175.63.229
+178.175.63.230
 178.175.63.231
 178.175.63.235
 178.175.63.239
@@ -209801,6 +210039,7 @@
 178.175.63.75
 178.175.63.76
 178.175.63.77
+178.175.63.78
 178.175.63.80
 178.175.63.87
 178.175.63.88
@@ -209834,6 +210073,7 @@
 178.175.64.149
 178.175.64.151
 178.175.64.154
+178.175.64.155
 178.175.64.156
 178.175.64.158
 178.175.64.163
@@ -209954,6 +210194,7 @@
 178.175.65.181
 178.175.65.184
 178.175.65.186
+178.175.65.19
 178.175.65.192
 178.175.65.193
 178.175.65.194
@@ -210198,6 +210439,7 @@
 178.175.67.48
 178.175.67.51
 178.175.67.54
+178.175.67.55
 178.175.67.59
 178.175.67.6
 178.175.67.60
@@ -210234,6 +210476,7 @@
 178.175.68.113
 178.175.68.114
 178.175.68.115
+178.175.68.116
 178.175.68.121
 178.175.68.124
 178.175.68.125
@@ -210908,6 +211151,7 @@
 178.175.73.72
 178.175.73.76
 178.175.73.77
+178.175.73.78
 178.175.73.86
 178.175.73.88
 178.175.73.89
@@ -210967,6 +211211,7 @@
 178.175.74.201
 178.175.74.203
 178.175.74.204
+178.175.74.205
 178.175.74.206
 178.175.74.207
 178.175.74.21
@@ -210984,6 +211229,7 @@
 178.175.74.237
 178.175.74.238
 178.175.74.241
+178.175.74.247
 178.175.74.251
 178.175.74.253
 178.175.74.30
@@ -211177,6 +211423,7 @@
 178.175.76.240
 178.175.76.241
 178.175.76.244
+178.175.76.246
 178.175.76.248
 178.175.76.27
 178.175.76.29
@@ -211256,6 +211503,7 @@
 178.175.77.242
 178.175.77.244
 178.175.77.246
+178.175.77.248
 178.175.77.250
 178.175.77.251
 178.175.77.252
@@ -211263,6 +211511,7 @@
 178.175.77.31
 178.175.77.32
 178.175.77.33
+178.175.77.34
 178.175.77.37
 178.175.77.38
 178.175.77.40
@@ -211363,6 +211612,7 @@
 178.175.78.48
 178.175.78.50
 178.175.78.51
+178.175.78.57
 178.175.78.58
 178.175.78.60
 178.175.78.64
@@ -211515,6 +211765,7 @@
 178.175.8.217
 178.175.8.223
 178.175.8.225
+178.175.8.227
 178.175.8.233
 178.175.8.238
 178.175.8.24
@@ -211531,6 +211782,7 @@
 178.175.8.60
 178.175.8.61
 178.175.8.63
+178.175.8.64
 178.175.8.67
 178.175.8.69
 178.175.8.72
@@ -211646,6 +211898,7 @@
 178.175.80.82
 178.175.80.86
 178.175.80.87
+178.175.80.89
 178.175.80.90
 178.175.80.91
 178.175.80.92
@@ -211697,6 +211950,7 @@
 178.175.81.185
 178.175.81.186
 178.175.81.189
+178.175.81.19
 178.175.81.192
 178.175.81.194
 178.175.81.197
@@ -211811,6 +212065,7 @@
 178.175.82.224
 178.175.82.226
 178.175.82.228
+178.175.82.23
 178.175.82.230
 178.175.82.233
 178.175.82.235
@@ -211872,11 +212127,13 @@
 178.175.83.125
 178.175.83.130
 178.175.83.133
+178.175.83.136
 178.175.83.137
 178.175.83.138
 178.175.83.139
 178.175.83.141
 178.175.83.143
+178.175.83.144
 178.175.83.145
 178.175.83.147
 178.175.83.15
@@ -211993,6 +212250,7 @@
 178.175.84.158
 178.175.84.159
 178.175.84.16
+178.175.84.17
 178.175.84.170
 178.175.84.178
 178.175.84.180
@@ -212446,10 +212704,12 @@
 178.175.88.230
 178.175.88.236
 178.175.88.237
+178.175.88.24
 178.175.88.241
 178.175.88.242
 178.175.88.243
 178.175.88.246
+178.175.88.248
 178.175.88.251
 178.175.88.253
 178.175.88.254
@@ -212550,6 +212810,7 @@
 178.175.89.25
 178.175.89.253
 178.175.89.28
+178.175.89.30
 178.175.89.31
 178.175.89.33
 178.175.89.37
@@ -212687,6 +212948,7 @@
 178.175.90.177
 178.175.90.178
 178.175.90.179
+178.175.90.185
 178.175.90.186
 178.175.90.187
 178.175.90.188
@@ -212741,6 +213003,7 @@
 178.175.90.79
 178.175.90.8
 178.175.90.80
+178.175.90.81
 178.175.90.85
 178.175.90.89
 178.175.90.90
@@ -212933,6 +213196,7 @@
 178.175.92.42
 178.175.92.43
 178.175.92.45
+178.175.92.48
 178.175.92.51
 178.175.92.54
 178.175.92.61
@@ -212993,6 +213257,7 @@
 178.175.93.196
 178.175.93.197
 178.175.93.198
+178.175.93.199
 178.175.93.200
 178.175.93.202
 178.175.93.203
@@ -213184,6 +213449,7 @@
 178.175.95.154
 178.175.95.156
 178.175.95.158
+178.175.95.163
 178.175.95.164
 178.175.95.165
 178.175.95.166
@@ -213285,6 +213551,7 @@
 178.175.96.169
 178.175.96.180
 178.175.96.181
+178.175.96.187
 178.175.96.189
 178.175.96.192
 178.175.96.195
@@ -213336,6 +213603,7 @@
 178.175.96.70
 178.175.96.75
 178.175.96.8
+178.175.96.81
 178.175.96.82
 178.175.96.88
 178.175.96.95
@@ -213404,6 +213672,7 @@
 178.175.97.219
 178.175.97.220
 178.175.97.224
+178.175.97.225
 178.175.97.23
 178.175.97.230
 178.175.97.231
@@ -213468,6 +213737,7 @@
 178.175.98.205
 178.175.98.206
 178.175.98.207
+178.175.98.216
 178.175.98.217
 178.175.98.221
 178.175.98.224
@@ -214138,6 +214408,7 @@
 178.95.195.240
 178.95.197.16
 178.95.197.55
+178.95.197.91
 178.95.198.146
 178.95.199.144
 178.95.199.175
@@ -214459,6 +214730,7 @@
 179.42.107.127
 179.42.107.128
 179.42.107.137
+179.42.107.139
 179.42.107.141
 179.42.107.144
 179.42.107.149
@@ -215824,6 +216096,7 @@
 180.188.224.104
 180.188.236.174
 180.188.236.247
+180.188.236.32
 180.188.236.9
 180.188.241.111
 180.188.241.115
@@ -216008,6 +216281,7 @@
 180.253.17.128
 180.253.191.125
 180.253.27.248
+180.253.99.109
 180.254.167.231
 180.254.241.245
 180.254.53.113
@@ -217186,6 +217460,7 @@
 182.112.28.104
 182.112.28.108
 182.112.28.116
+182.112.28.118
 182.112.28.122
 182.112.28.123
 182.112.28.13
@@ -217420,6 +217695,7 @@
 182.112.34.187
 182.112.34.20
 182.112.34.202
+182.112.34.220
 182.112.34.233
 182.112.34.25
 182.112.34.34
@@ -219673,6 +219949,7 @@
 182.113.238.135
 182.113.238.136
 182.113.238.165
+182.113.238.197
 182.113.238.199
 182.113.238.20
 182.113.238.28
@@ -219867,6 +220144,7 @@
 182.113.29.230
 182.113.29.241
 182.113.29.245
+182.113.29.28
 182.113.29.44
 182.113.29.46
 182.113.29.54
@@ -221878,6 +222156,7 @@
 182.114.76.254
 182.114.76.39
 182.114.76.41
+182.114.76.42
 182.114.76.50
 182.114.76.67
 182.114.76.81
@@ -223928,6 +224207,7 @@
 182.116.116.61
 182.116.116.64
 182.116.116.68
+182.116.116.70
 182.116.116.73
 182.116.116.75
 182.116.116.76
@@ -224104,6 +224384,7 @@
 182.116.119.53
 182.116.119.56
 182.116.119.59
+182.116.119.66
 182.116.119.68
 182.116.119.7
 182.116.119.74
@@ -224290,6 +224571,7 @@
 182.116.36.149
 182.116.36.15
 182.116.36.174
+182.116.36.175
 182.116.36.180
 182.116.36.195
 182.116.36.199
@@ -226600,6 +226882,7 @@
 182.117.13.21
 182.117.13.32
 182.117.13.4
+182.117.13.57
 182.117.13.71
 182.117.13.73
 182.117.13.75
@@ -229968,6 +230251,7 @@
 182.118.164.227
 182.118.164.248
 182.118.165.190
+182.118.166.128
 182.118.166.153
 182.118.166.36
 182.118.166.82
@@ -230711,6 +230995,7 @@
 182.119.15.63
 182.119.15.68
 182.119.15.70
+182.119.15.78
 182.119.15.81
 182.119.15.86
 182.119.15.91
@@ -230971,6 +231256,7 @@
 182.119.166.4
 182.119.166.64
 182.119.166.72
+182.119.166.76
 182.119.166.84
 182.119.166.9
 182.119.166.94
@@ -231136,6 +231422,7 @@
 182.119.179.130
 182.119.179.169
 182.119.179.17
+182.119.179.193
 182.119.179.199
 182.119.179.202
 182.119.179.230
@@ -231514,6 +231801,7 @@
 182.119.196.160
 182.119.196.182
 182.119.196.190
+182.119.197.123
 182.119.199.158
 182.119.199.85
 182.119.2.110
@@ -231614,6 +231902,7 @@
 182.119.202.159
 182.119.202.170
 182.119.202.179
+182.119.202.180
 182.119.202.189
 182.119.202.20
 182.119.202.201
@@ -231814,6 +232103,7 @@
 182.119.21.39
 182.119.21.46
 182.119.21.54
+182.119.21.68
 182.119.21.76
 182.119.21.79
 182.119.21.81
@@ -233457,6 +233747,7 @@
 182.119.88.4
 182.119.88.54
 182.119.88.88
+182.119.89.107
 182.119.89.11
 182.119.89.123
 182.119.89.126
@@ -236307,6 +236598,7 @@
 182.121.15.199
 182.121.15.203
 182.121.15.219
+182.121.15.223
 182.121.15.227
 182.121.15.237
 182.121.15.252
@@ -238187,6 +238479,7 @@
 182.121.254.117
 182.121.254.127
 182.121.254.132
+182.121.254.147
 182.121.254.15
 182.121.254.152
 182.121.254.198
@@ -239233,6 +239526,7 @@
 182.121.54.8
 182.121.54.81
 182.121.54.95
+182.121.55.106
 182.121.55.109
 182.121.55.112
 182.121.55.122
@@ -241953,6 +242247,7 @@
 182.123.241.130
 182.123.241.172
 182.123.241.173
+182.123.241.195
 182.123.241.200
 182.123.241.214
 182.123.241.23
@@ -242763,6 +243058,7 @@
 182.124.200.94
 182.124.201.176
 182.124.201.186
+182.124.201.207
 182.124.201.222
 182.124.202.211
 182.124.202.241
@@ -244284,6 +244580,7 @@
 182.126.123.185
 182.126.123.188
 182.126.123.189
+182.126.123.19
 182.126.123.191
 182.126.123.193
 182.126.123.199
@@ -246545,6 +246842,7 @@
 182.127.106.176
 182.127.106.216
 182.127.106.217
+182.127.106.43
 182.127.106.5
 182.127.106.53
 182.127.106.57
@@ -249991,6 +250289,7 @@
 182.127.93.229
 182.127.93.230
 182.127.93.35
+182.127.93.38
 182.127.93.39
 182.127.93.4
 182.127.93.42
@@ -250438,6 +250737,7 @@
 182.245.26.132
 182.245.26.171
 182.245.27.165
+182.245.28.162
 182.245.28.80
 182.245.34.249
 182.245.34.32
@@ -251103,6 +251403,7 @@
 182.56.192.77
 182.56.193.147
 182.56.193.161
+182.56.193.251
 182.56.193.26
 182.56.193.39
 182.56.193.46
@@ -255721,6 +256022,7 @@
 182.59.222.42
 182.59.222.60
 182.59.222.96
+182.59.223.113
 182.59.223.124
 182.59.223.127
 182.59.223.131
@@ -255912,6 +256214,7 @@
 182.59.235.100
 182.59.235.107
 182.59.235.121
+182.59.235.150
 182.59.235.151
 182.59.235.157
 182.59.235.164
@@ -258270,6 +258573,7 @@
 183.185.113.113
 183.185.115.92
 183.185.125.227
+183.185.162.225
 183.185.168.107
 183.185.168.165
 183.185.169.102
@@ -258664,6 +258968,7 @@
 183.188.90.55
 183.188.91.12
 183.188.92.208
+183.188.93.116
 183.188.93.21
 183.188.94.13
 183.188.94.195
@@ -262173,6 +262478,7 @@
 186.33.112.208
 186.33.112.209
 186.33.112.210
+186.33.112.211
 186.33.112.214
 186.33.112.216
 186.33.112.218
@@ -262260,6 +262566,7 @@
 186.33.112.95
 186.33.112.96
 186.33.112.97
+186.33.113.137
 186.33.113.2
 186.33.113.241
 186.33.113.5
@@ -263542,6 +263849,7 @@
 188.116.36.88
 188.119.112.125
 188.119.120.135
+188.119.45.194
 188.119.45.205
 188.119.49.1
 188.119.58.176
@@ -265886,6 +266194,7 @@
 190.72.32.132
 190.72.62.232
 190.73.101.231
+190.73.12.149
 190.73.71.174
 190.74.22.100
 190.75.113.109
@@ -267082,6 +267391,7 @@
 193.38.55.126
 193.38.55.59
 193.38.55.73
+193.38.55.9
 193.39.185.202
 193.39.185.207
 193.39.185.214
@@ -269227,6 +269537,7 @@
 2.68.190.234
 2.68.192.214
 2.68.234.169
+2.68.59.23
 2.68.78.147
 2.82.200.218
 2.82.28.27
@@ -270500,6 +270811,7 @@
 202.164.139.120
 202.164.139.121
 202.164.139.123
+202.164.139.124
 202.164.139.125
 202.164.139.127
 202.164.139.128
@@ -270594,6 +270906,7 @@
 202.164.139.243
 202.164.139.246
 202.164.139.247
+202.164.139.248
 202.164.139.249
 202.164.139.25
 202.164.139.252
@@ -274937,6 +275250,7 @@
 209.133.223.130
 209.14.30.109
 209.14.30.121
+209.14.30.132
 209.14.30.135
 209.14.30.136
 209.14.30.156
@@ -274948,6 +275262,7 @@
 209.14.30.205
 209.14.30.30
 209.14.30.54
+209.14.31.111
 209.14.31.125
 209.14.31.162
 209.14.31.163
@@ -277664,6 +277979,7 @@
 218.32.118.1
 218.32.118.185
 218.32.124.170
+218.32.96.158
 218.32.98.172
 218.35.198.109
 218.35.205.235
@@ -277762,6 +278078,7 @@
 218.57.107.48
 218.57.109.101
 218.57.109.155
+218.57.109.48
 218.57.109.58
 218.57.115.102
 218.57.115.124
@@ -279308,6 +279625,7 @@
 219.154.116.154
 219.154.116.156
 219.154.116.166
+219.154.116.168
 219.154.116.17
 219.154.116.171
 219.154.116.185
@@ -279961,6 +280279,7 @@
 219.154.142.196
 219.154.142.210
 219.154.142.239
+219.154.142.35
 219.154.142.4
 219.154.142.41
 219.154.142.43
@@ -280096,6 +280415,7 @@
 219.154.176.189
 219.154.176.24
 219.154.177.205
+219.154.178.138
 219.154.178.175
 219.154.178.69
 219.154.178.72
@@ -280304,6 +280624,7 @@
 219.154.41.137
 219.154.41.183
 219.154.41.31
+219.154.41.36
 219.154.41.51
 219.154.42.109
 219.154.42.121
@@ -280613,6 +280934,7 @@
 219.155.11.212
 219.155.11.220
 219.155.11.240
+219.155.11.252
 219.155.11.28
 219.155.11.36
 219.155.11.41
@@ -281251,6 +281573,7 @@
 219.155.209.230
 219.155.209.232
 219.155.209.25
+219.155.209.253
 219.155.209.35
 219.155.209.54
 219.155.209.74
@@ -282623,6 +282946,7 @@
 219.155.86.128
 219.155.86.136
 219.155.86.145
+219.155.86.156
 219.155.86.17
 219.155.86.182
 219.155.86.191
@@ -283453,6 +283777,7 @@
 219.156.175.190
 219.156.175.225
 219.156.176.129
+219.156.176.153
 219.156.176.184
 219.156.176.20
 219.156.176.64
@@ -283463,6 +283788,7 @@
 219.156.177.212
 219.156.177.232
 219.156.177.71
+219.156.178.130
 219.156.178.133
 219.156.178.137
 219.156.178.179
@@ -284113,6 +284439,7 @@
 219.156.65.250
 219.156.65.251
 219.156.65.27
+219.156.65.47
 219.156.65.48
 219.156.65.70
 219.156.65.71
@@ -285777,6 +286104,7 @@
 219.157.214.216
 219.157.214.22
 219.157.214.221
+219.157.214.235
 219.157.214.236
 219.157.214.24
 219.157.214.31
@@ -289584,6 +289912,7 @@
 221.13.191.75
 221.13.191.91
 221.13.208.118
+221.13.208.159
 221.13.208.8
 221.13.210.251
 221.13.211.121
@@ -290333,6 +290662,7 @@
 221.14.184.24
 221.14.184.32
 221.14.184.76
+221.14.185.105
 221.14.185.112
 221.14.185.157
 221.14.185.4
@@ -290454,6 +290784,7 @@
 221.14.46.48
 221.14.47.162
 221.14.47.182
+221.14.47.189
 221.14.47.46
 221.14.47.77
 221.14.47.82
@@ -290462,6 +290793,7 @@
 221.14.56.169
 221.14.56.252
 221.14.56.67
+221.14.57.175
 221.14.57.62
 221.14.58.27
 221.14.58.5
@@ -290613,6 +290945,7 @@
 221.15.111.49
 221.15.111.82
 221.15.111.96
+221.15.112.103
 221.15.112.186
 221.15.112.203
 221.15.112.220
@@ -291254,6 +291587,7 @@
 221.15.155.179
 221.15.155.180
 221.15.155.184
+221.15.155.186
 221.15.155.194
 221.15.155.197
 221.15.155.199
@@ -291989,6 +292323,7 @@
 221.15.190.179
 221.15.190.18
 221.15.190.188
+221.15.190.2
 221.15.190.232
 221.15.190.234
 221.15.190.247
@@ -294268,6 +294603,7 @@
 221.201.54.42
 221.201.54.97
 221.202.232.175
+221.202.232.230
 221.202.232.5
 221.202.234.170
 221.202.235.198
@@ -294562,6 +294898,7 @@
 221.214.249.112
 221.214.249.181
 221.214.249.199
+221.214.251.109
 221.214.251.162
 221.214.251.91
 221.214.254.15
@@ -296321,6 +296658,7 @@
 222.136.76.154
 222.136.76.84
 222.136.77.141
+222.136.77.190
 222.136.77.3
 222.136.77.91
 222.136.78.29
@@ -297708,6 +298046,7 @@
 222.137.161.73
 222.137.161.8
 222.137.161.85
+222.137.161.88
 222.137.161.91
 222.137.161.95
 222.137.161.96
@@ -298884,6 +299223,7 @@
 222.137.220.204
 222.137.220.207
 222.137.220.212
+222.137.220.215
 222.137.220.219
 222.137.220.226
 222.137.220.244
@@ -299093,6 +299433,7 @@
 222.137.237.181
 222.137.237.187
 222.137.237.190
+222.137.237.203
 222.137.237.208
 222.137.237.212
 222.137.237.217
@@ -299575,6 +299916,7 @@
 222.137.53.125
 222.137.53.191
 222.137.53.192
+222.137.53.193
 222.137.53.229
 222.137.53.242
 222.137.53.255
@@ -300487,6 +300829,7 @@
 222.138.118.186
 222.138.118.190
 222.138.118.191
+222.138.118.192
 222.138.118.195
 222.138.118.196
 222.138.118.2
@@ -301349,6 +301692,7 @@
 222.138.183.111
 222.138.183.116
 222.138.183.117
+222.138.183.120
 222.138.183.123
 222.138.183.126
 222.138.183.129
@@ -301741,6 +302085,7 @@
 222.138.213.192
 222.138.213.202
 222.138.213.219
+222.138.213.235
 222.138.213.239
 222.138.213.245
 222.138.213.31
@@ -302370,6 +302715,7 @@
 222.138.50.32
 222.138.50.50
 222.138.50.75
+222.138.51.203
 222.138.51.69
 222.138.52.108
 222.138.52.200
@@ -302620,6 +302966,7 @@
 222.139.106.121
 222.139.106.154
 222.139.106.230
+222.139.106.55
 222.139.107.10
 222.139.107.113
 222.139.107.137
@@ -304146,6 +304493,7 @@
 222.140.179.11
 222.140.179.120
 222.140.179.14
+222.140.179.142
 222.140.179.16
 222.140.179.168
 222.140.179.178
@@ -304385,6 +304733,7 @@
 222.140.207.76
 222.140.207.85
 222.140.208.132
+222.140.208.18
 222.140.208.205
 222.140.208.219
 222.140.208.45
@@ -304705,6 +305054,7 @@
 222.141.101.240
 222.141.101.251
 222.141.101.254
+222.141.101.39
 222.141.101.55
 222.141.101.87
 222.141.101.92
@@ -305728,6 +306078,7 @@
 222.141.40.47
 222.141.40.58
 222.141.40.65
+222.141.40.69
 222.141.40.7
 222.141.40.73
 222.141.40.75
@@ -308016,6 +308367,7 @@
 222.81.155.83
 222.81.155.88
 222.81.156.100
+222.81.156.229
 222.81.157.146
 222.81.157.148
 222.81.157.177
@@ -309507,6 +309859,7 @@
 27.153.140.109
 27.153.141.43
 27.153.141.80
+27.153.142.115
 27.153.142.228
 27.153.142.44
 27.153.143.113
@@ -313504,6 +313857,7 @@
 27.208.200.128
 27.208.200.67
 27.208.201.212
+27.208.202.165
 27.208.202.25
 27.208.203.172
 27.208.205.119
@@ -313554,6 +313908,7 @@
 27.208.55.230
 27.208.55.65
 27.208.63.93
+27.208.70.115
 27.208.70.207
 27.208.72.67
 27.208.76.142
@@ -314609,6 +314964,7 @@
 27.213.165.198
 27.213.166.136
 27.213.166.174
+27.213.166.50
 27.213.167.154
 27.213.167.175
 27.213.167.180
@@ -315333,6 +315689,7 @@
 27.215.253.149
 27.215.254.134
 27.215.255.209
+27.215.27.143
 27.215.28.105
 27.215.28.45
 27.215.3.1
@@ -319711,6 +320068,7 @@
 27.41.159.205
 27.41.159.216
 27.41.159.26
+27.41.159.28
 27.41.159.33
 27.41.159.58
 27.41.159.76
@@ -320460,6 +320818,7 @@
 27.41.37.128
 27.41.37.131
 27.41.37.133
+27.41.37.155
 27.41.37.171
 27.41.37.180
 27.41.37.187
@@ -320608,6 +320967,7 @@
 27.41.89.195
 27.41.89.50
 27.41.89.89
+27.41.9.105
 27.41.9.113
 27.41.9.130
 27.41.9.135
@@ -320660,6 +321020,7 @@
 27.41.97.172
 27.41.97.191
 27.41.97.2
+27.41.97.36
 27.41.97.40
 27.41.97.6
 27.41.97.94
@@ -320694,10 +321055,12 @@
 27.43.105.64
 27.43.106.242
 27.43.107.181
+27.43.108.78
 27.43.109.21
 27.43.110.101
 27.43.110.185
 27.43.110.198
+27.43.111.161
 27.43.111.217
 27.43.111.46
 27.43.115.108
@@ -320709,6 +321072,7 @@
 27.43.116.9
 27.43.116.96
 27.43.117.15
+27.43.117.66
 27.43.117.89
 27.43.118.111
 27.43.118.150
@@ -320840,6 +321204,7 @@
 27.46.22.67
 27.46.22.83
 27.46.22.9
+27.46.23.10
 27.46.23.123
 27.46.23.181
 27.46.23.188
@@ -320885,6 +321250,7 @@
 27.46.44.233
 27.46.44.235
 27.46.44.237
+27.46.44.239
 27.46.44.246
 27.46.44.254
 27.46.44.31
@@ -320944,6 +321310,7 @@
 27.46.45.7
 27.46.45.82
 27.46.45.85
+27.46.45.86
 27.46.45.88
 27.46.45.89
 27.46.45.90
@@ -322364,6 +322731,7 @@
 27.5.30.70
 27.5.30.71
 27.5.30.72
+27.5.30.79
 27.5.30.81
 27.5.30.82
 27.5.30.87
@@ -322823,6 +323191,7 @@
 27.5.36.221
 27.5.36.222
 27.5.36.230
+27.5.36.232
 27.5.36.233
 27.5.36.234
 27.5.36.238
@@ -323338,6 +323707,7 @@
 27.5.41.143
 27.5.41.144
 27.5.41.145
+27.5.41.146
 27.5.41.148
 27.5.41.149
 27.5.41.155
@@ -325853,6 +326223,7 @@
 27.6.122.19
 27.6.122.192
 27.6.122.193
+27.6.122.194
 27.6.122.197
 27.6.122.2
 27.6.122.202
@@ -331355,6 +331726,7 @@
 27.6.240.156
 27.6.240.161
 27.6.240.169
+27.6.240.171
 27.6.240.175
 27.6.240.181
 27.6.240.183
@@ -331576,6 +331948,7 @@
 27.6.243.113
 27.6.243.117
 27.6.243.12
+27.6.243.122
 27.6.243.126
 27.6.243.127
 27.6.243.128
@@ -332265,6 +332638,7 @@
 27.6.34.217
 27.6.34.60
 27.6.38.222
+27.6.38.96
 27.6.4.101
 27.6.4.102
 27.6.4.106
@@ -344723,6 +345097,7 @@
 36.251.18.2
 36.251.18.40
 36.251.18.44
+36.251.18.63
 36.251.19.213
 36.251.19.231
 36.251.19.249
@@ -345327,6 +345702,7 @@
 36.42.107.77
 36.42.107.99
 36.43.10.121
+36.43.11.16
 36.43.11.211
 36.43.12.163
 36.43.64.10
@@ -345464,6 +345840,7 @@
 36.81.158.24
 36.81.187.39
 36.81.209.186
+36.81.23.38
 36.81.230.140
 36.81.31.124
 36.82.179.161
@@ -348935,6 +349312,7 @@
 39.77.44.29
 39.77.44.32
 39.77.46.7
+39.77.48.213
 39.77.49.13
 39.77.5.113
 39.77.5.214
@@ -349364,6 +349742,7 @@
 39.79.162.176
 39.79.163.104
 39.79.163.173
+39.79.163.188
 39.79.163.252
 39.79.163.96
 39.79.164.165
@@ -349828,6 +350207,7 @@
 39.80.35.201
 39.80.36.151
 39.80.36.64
+39.80.37.182
 39.80.38.117
 39.80.38.27
 39.80.39.207
@@ -353512,6 +353892,7 @@
 42.224.122.174
 42.224.122.176
 42.224.122.182
+42.224.122.183
 42.224.122.186
 42.224.122.19
 42.224.122.191
@@ -355134,6 +355515,7 @@
 42.224.188.115
 42.224.188.137
 42.224.188.176
+42.224.188.223
 42.224.188.241
 42.224.188.250
 42.224.188.85
@@ -355141,6 +355523,7 @@
 42.224.189.121
 42.224.189.153
 42.224.189.208
+42.224.189.79
 42.224.189.88
 42.224.189.89
 42.224.189.90
@@ -356184,6 +356567,7 @@
 42.224.249.178
 42.224.249.18
 42.224.249.182
+42.224.249.188
 42.224.249.190
 42.224.249.195
 42.224.249.208
@@ -356630,6 +357014,7 @@
 42.224.3.171
 42.224.3.179
 42.224.3.180
+42.224.3.187
 42.224.3.192
 42.224.3.205
 42.224.3.206
@@ -357346,6 +357731,7 @@
 42.224.52.56
 42.224.52.58
 42.224.52.8
+42.224.52.81
 42.224.52.97
 42.224.53.120
 42.224.53.130
@@ -357487,6 +357873,7 @@
 42.224.59.245
 42.224.59.247
 42.224.59.249
+42.224.59.251
 42.224.59.68
 42.224.59.73
 42.224.59.74
@@ -357866,6 +358253,7 @@
 42.224.68.67
 42.224.68.69
 42.224.68.70
+42.224.68.72
 42.224.68.74
 42.224.68.78
 42.224.68.79
@@ -361728,6 +362116,7 @@
 42.228.196.177
 42.228.196.193
 42.228.196.218
+42.228.196.68
 42.228.196.89
 42.228.197.136
 42.228.197.142
@@ -366572,6 +366961,7 @@
 42.230.46.198
 42.230.46.231
 42.230.46.246
+42.230.46.55
 42.230.46.70
 42.230.46.9
 42.230.46.93
@@ -368997,6 +369387,7 @@
 42.231.95.195
 42.231.95.210
 42.231.95.230
+42.231.95.247
 42.231.95.99
 42.231.96.105
 42.231.96.176
@@ -369933,6 +370324,7 @@
 42.232.45.85
 42.232.46.1
 42.232.46.129
+42.232.46.169
 42.232.46.73
 42.232.46.86
 42.232.47.212
@@ -370629,6 +371021,7 @@
 42.233.159.141
 42.233.159.168
 42.233.159.19
+42.233.159.21
 42.233.159.223
 42.233.159.228
 42.233.159.230
@@ -372152,6 +372545,7 @@
 42.234.246.77
 42.234.247.171
 42.234.247.4
+42.234.247.41
 42.234.247.44
 42.234.247.55
 42.234.247.57
@@ -375440,6 +375834,7 @@
 42.235.81.88
 42.235.82.0
 42.235.82.108
+42.235.82.112
 42.235.82.118
 42.235.82.129
 42.235.82.141
@@ -375470,6 +375865,7 @@
 42.235.82.44
 42.235.82.45
 42.235.82.46
+42.235.82.52
 42.235.82.53
 42.235.82.54
 42.235.82.60
@@ -375660,6 +376056,7 @@
 42.235.86.87
 42.235.86.95
 42.235.87.1
+42.235.87.100
 42.235.87.102
 42.235.87.103
 42.235.87.121
@@ -376845,6 +377242,7 @@
 42.237.14.202
 42.237.14.74
 42.237.14.8
+42.237.142.157
 42.237.15.110
 42.237.15.142
 42.237.15.153
@@ -376954,6 +377352,7 @@
 42.237.24.108
 42.237.24.129
 42.237.24.14
+42.237.24.151
 42.237.24.166
 42.237.24.220
 42.237.24.23
@@ -377206,6 +377605,7 @@
 42.237.60.219
 42.237.60.254
 42.237.60.42
+42.237.60.73
 42.237.61.107
 42.237.61.152
 42.237.61.246
@@ -377835,6 +378235,7 @@
 42.238.227.72
 42.238.227.86
 42.238.227.95
+42.238.228.0
 42.238.228.122
 42.238.228.132
 42.238.228.220
@@ -378023,6 +378424,7 @@
 42.238.250.202
 42.238.250.246
 42.238.250.248
+42.238.250.56
 42.238.251.226
 42.238.251.47
 42.238.251.61
@@ -378539,6 +378941,7 @@
 42.239.154.85
 42.239.155.124
 42.239.155.143
+42.239.155.147
 42.239.155.158
 42.239.155.159
 42.239.155.165
@@ -378807,6 +379210,7 @@
 42.239.201.20
 42.239.201.86
 42.239.202.100
+42.239.202.121
 42.239.202.145
 42.239.202.227
 42.239.202.229
@@ -378901,6 +379305,7 @@
 42.239.217.21
 42.239.217.228
 42.239.217.56
+42.239.218.137
 42.239.218.141
 42.239.218.157
 42.239.218.63
@@ -381158,6 +381563,7 @@
 45.176.108.154
 45.176.108.157
 45.176.108.161
+45.176.108.164
 45.176.108.168
 45.176.108.170
 45.176.108.18
@@ -386294,6 +386700,7 @@
 5.39.218.162
 5.39.219.130
 5.39.223.68
+5.42.37.74
 5.42.48.223
 5.42.82.17
 5.42.92.195
@@ -387047,6 +387454,7 @@
 58.11.78.109
 58.114.245.23
 58.114.246.26
+58.115.108.164
 58.115.160.50
 58.115.162.92
 58.115.166.148
@@ -387716,6 +388124,7 @@
 58.248.116.190
 58.248.116.199
 58.248.116.2
+58.248.116.21
 58.248.116.210
 58.248.116.216
 58.248.116.222
@@ -387746,6 +388155,7 @@
 58.248.117.218
 58.248.117.226
 58.248.117.233
+58.248.117.238
 58.248.117.244
 58.248.117.253
 58.248.117.4
@@ -387902,6 +388312,7 @@
 58.248.142.11
 58.248.142.111
 58.248.142.116
+58.248.142.132
 58.248.142.137
 58.248.142.138
 58.248.142.148
@@ -387927,6 +388338,7 @@
 58.248.142.239
 58.248.142.24
 58.248.142.4
+58.248.142.5
 58.248.142.53
 58.248.142.64
 58.248.142.67
@@ -388059,6 +388471,7 @@
 58.248.147.159
 58.248.147.179
 58.248.147.182
+58.248.147.196
 58.248.147.208
 58.248.147.224
 58.248.147.226
@@ -388161,6 +388574,7 @@
 58.248.151.247
 58.248.151.248
 58.248.151.25
+58.248.151.33
 58.248.151.4
 58.248.151.48
 58.248.151.6
@@ -388254,6 +388668,7 @@
 58.248.74.230
 58.248.74.236
 58.248.74.24
+58.248.74.240
 58.248.74.241
 58.248.74.246
 58.248.74.41
@@ -388933,6 +389348,7 @@
 58.249.72.49
 58.249.72.67
 58.249.72.69
+58.249.72.88
 58.249.72.95
 58.249.72.98
 58.249.73.1
@@ -388989,6 +389405,7 @@
 58.249.74.222
 58.249.74.227
 58.249.74.235
+58.249.74.243
 58.249.74.245
 58.249.74.248
 58.249.74.35
@@ -389014,6 +389431,7 @@
 58.249.75.194
 58.249.75.20
 58.249.75.209
+58.249.75.213
 58.249.75.214
 58.249.75.218
 58.249.75.233
@@ -389186,6 +389604,7 @@
 58.249.80.242
 58.249.80.245
 58.249.80.246
+58.249.80.25
 58.249.80.37
 58.249.80.38
 58.249.80.46
@@ -389471,6 +389890,7 @@
 58.249.89.143
 58.249.89.15
 58.249.89.157
+58.249.89.158
 58.249.89.160
 58.249.89.162
 58.249.89.167
@@ -389879,6 +390299,7 @@
 58.255.140.125
 58.255.140.146
 58.255.140.149
+58.255.140.150
 58.255.140.156
 58.255.140.190
 58.255.140.21
@@ -390454,6 +390875,7 @@
 59.127.10.103
 59.127.108.38
 59.127.109.11
+59.127.11.50
 59.127.124.161
 59.127.125.164
 59.127.130.170
@@ -395290,6 +395712,7 @@
 59.92.176.201
 59.92.176.202
 59.92.176.209
+59.92.176.21
 59.92.176.218
 59.92.176.221
 59.92.176.222
@@ -395299,6 +395722,7 @@
 59.92.176.233
 59.92.176.235
 59.92.176.236
+59.92.176.24
 59.92.176.243
 59.92.176.244
 59.92.176.245
@@ -395313,6 +395737,7 @@
 59.92.176.40
 59.92.176.41
 59.92.176.44
+59.92.176.45
 59.92.176.47
 59.92.176.55
 59.92.176.56
@@ -395520,7 +395945,9 @@
 59.92.179.114
 59.92.179.115
 59.92.179.119
+59.92.179.12
 59.92.179.123
+59.92.179.124
 59.92.179.125
 59.92.179.13
 59.92.179.14
@@ -395593,6 +396020,7 @@
 59.92.18.145
 59.92.18.152
 59.92.18.155
+59.92.18.156
 59.92.18.159
 59.92.18.161
 59.92.18.170
@@ -395916,6 +396344,7 @@
 59.92.181.221
 59.92.181.222
 59.92.181.223
+59.92.181.224
 59.92.181.225
 59.92.181.226
 59.92.181.227
@@ -396039,6 +396468,7 @@
 59.92.182.138
 59.92.182.14
 59.92.182.140
+59.92.182.141
 59.92.182.144
 59.92.182.145
 59.92.182.147
@@ -396401,6 +396831,7 @@
 59.92.19.211
 59.92.19.212
 59.92.19.229
+59.92.19.230
 59.92.19.235
 59.92.19.24
 59.92.19.244
@@ -397730,6 +398161,7 @@
 59.93.19.99
 59.93.20.0
 59.93.20.1
+59.93.20.104
 59.93.20.106
 59.93.20.107
 59.93.20.110
@@ -397805,6 +398237,7 @@
 59.93.21.111
 59.93.21.115
 59.93.21.117
+59.93.21.119
 59.93.21.121
 59.93.21.126
 59.93.21.127
@@ -400772,6 +401205,7 @@
 59.96.37.177
 59.96.37.179
 59.96.37.180
+59.96.37.181
 59.96.37.182
 59.96.37.183
 59.96.37.185
@@ -400848,6 +401282,7 @@
 59.96.37.34
 59.96.37.35
 59.96.37.37
+59.96.37.38
 59.96.37.39
 59.96.37.4
 59.96.37.40
@@ -401234,6 +401669,7 @@
 59.96.39.241
 59.96.39.242
 59.96.39.243
+59.96.39.244
 59.96.39.246
 59.96.39.247
 59.96.39.248
@@ -403659,6 +404095,7 @@
 59.99.139.184
 59.99.139.186
 59.99.139.189
+59.99.139.19
 59.99.139.190
 59.99.139.191
 59.99.139.192
@@ -403713,6 +404150,7 @@
 59.99.139.64
 59.99.139.66
 59.99.139.68
+59.99.139.71
 59.99.139.73
 59.99.139.76
 59.99.139.78
@@ -404006,6 +404444,7 @@
 59.99.142.157
 59.99.142.158
 59.99.142.159
+59.99.142.163
 59.99.142.164
 59.99.142.165
 59.99.142.167
@@ -404108,6 +404547,7 @@
 59.99.143.112
 59.99.143.113
 59.99.143.114
+59.99.143.115
 59.99.143.117
 59.99.143.119
 59.99.143.120
@@ -404405,6 +404845,7 @@
 59.99.190.18
 59.99.190.182
 59.99.190.187
+59.99.190.189
 59.99.190.190
 59.99.190.191
 59.99.190.192
@@ -405237,6 +405678,7 @@
 59.99.44.123
 59.99.44.124
 59.99.44.125
+59.99.44.126
 59.99.44.129
 59.99.44.131
 59.99.44.132
@@ -405431,6 +405873,7 @@
 59.99.45.153
 59.99.45.154
 59.99.45.155
+59.99.45.156
 59.99.45.158
 59.99.45.16
 59.99.45.160
@@ -405607,6 +406050,7 @@
 59.99.46.166
 59.99.46.167
 59.99.46.168
+59.99.46.170
 59.99.46.171
 59.99.46.172
 59.99.46.174
@@ -405614,6 +406058,7 @@
 59.99.46.176
 59.99.46.177
 59.99.46.18
+59.99.46.180
 59.99.46.181
 59.99.46.182
 59.99.46.183
@@ -406566,6 +407011,7 @@
 59.99.95.161
 59.99.95.162
 59.99.95.164
+59.99.95.166
 59.99.95.167
 59.99.95.168
 59.99.95.169
@@ -407890,6 +408336,7 @@
 60.212.11.156
 60.212.110.19
 60.212.110.3
+60.212.111.39
 60.212.117.125
 60.212.117.206
 60.212.117.51
@@ -408256,6 +408703,7 @@
 60.214.217.79
 60.214.217.82
 60.214.217.85
+60.214.217.96
 60.214.218.136
 60.214.218.192
 60.214.218.196
@@ -408348,6 +408796,7 @@
 60.214.32.138
 60.214.32.150
 60.214.32.151
+60.214.32.17
 60.214.32.236
 60.214.32.243
 60.214.32.244
@@ -418531,6 +418980,7 @@
 61.128.83.148
 61.128.88.38
 61.129.101.57
+61.130.195.121
 61.130.195.172
 61.130.198.170
 61.130.224.119
@@ -421041,6 +421491,7 @@
 61.3.151.37
 61.3.151.38
 61.3.151.56
+61.3.151.60
 61.3.151.66
 61.3.151.70
 61.3.151.84
@@ -421318,6 +421769,7 @@
 61.52.103.2
 61.52.103.20
 61.52.103.21
+61.52.103.217
 61.52.103.220
 61.52.103.228
 61.52.103.229
@@ -421356,6 +421808,7 @@
 61.52.103.91
 61.52.103.93
 61.52.103.99
+61.52.109.9
 61.52.11.12
 61.52.11.15
 61.52.11.2
@@ -421707,6 +422160,7 @@
 61.52.166.218
 61.52.167.246
 61.52.167.249
+61.52.167.66
 61.52.167.89
 61.52.168.106
 61.52.168.121
@@ -422546,6 +423000,7 @@
 61.52.211.31
 61.52.211.38
 61.52.211.59
+61.52.211.61
 61.52.211.75
 61.52.211.76
 61.52.211.77
@@ -423196,6 +423651,7 @@
 61.52.30.159
 61.52.30.160
 61.52.30.161
+61.52.30.172
 61.52.30.174
 61.52.30.176
 61.52.30.178
@@ -423442,6 +423898,7 @@
 61.52.4.127
 61.52.4.138
 61.52.4.151
+61.52.4.214
 61.52.4.220
 61.52.4.59
 61.52.4.81
@@ -423495,6 +423952,7 @@
 61.52.42.112
 61.52.42.134
 61.52.42.138
+61.52.42.174
 61.52.42.192
 61.52.42.196
 61.52.42.20
@@ -424969,6 +425427,7 @@
 61.52.98.210
 61.52.98.214
 61.52.98.215
+61.52.98.22
 61.52.98.220
 61.52.98.231
 61.52.98.244
@@ -429536,6 +429995,7 @@
 62.76.5.154
 62.77.210.124
 62.78.131.240
+62.78.82.93
 62.80.167.71
 62.80.231.196
 62.80.235.224
@@ -430370,6 +430830,7 @@
 68.183.24.160
 68.183.24.34
 68.183.25.231
+68.183.25.71
 68.183.26.100
 68.183.26.166
 68.183.26.74
@@ -430501,6 +430962,7 @@
 68.99.179.195
 68.99.179.89
 68.99.180.30
+68468438438.xyz
 68h7.com
 69.10.193.239
 69.10.35.44
@@ -431556,6 +432018,7 @@
 77.43.248.83
 77.43.250.181
 77.43.250.205
+77.43.250.246
 77.43.251.170
 77.43.251.196
 77.43.251.77
@@ -431657,6 +432120,7 @@
 77.49.200.235
 77.51.189.86
 77.52.180.138
+77.53.144.46
 77.53.145.33
 77.53.2.182
 77.53.246.179
@@ -437960,6 +438424,7 @@
 999.buzz
 999.co.id
 999.rajaojek.com
+999080321newfolder1002002131-service1002.space
 999102com.cn
 99bkx.com
 99centsdigitals.com
@@ -439457,6 +439922,7 @@ adventuredsocks.com
 adventureexplorer.in
 adventurehr.com
 adventureitdate.com
+adventureits.com
 adventuremania.com
 adventurersafaris.com
 adventuresofarchibald.com
@@ -440485,6 +440951,7 @@ akasyahediyelik.com
 akatanomastos.net
 akatlot.com
 akatsolution.net
+akauk09.top
 akaunting.redocom.com
 akawork.io
 akbaara.com
@@ -440568,6 +441035,7 @@ akouzelis-patra.gr
 akowa.projet-test.com
 akowalska.ecrm.pl
 akpeugono.com
+akpgi08.top
 akpp-service.top
 akppservis30.ru
 akprokonaija.com
@@ -452520,6 +452988,7 @@ camelliia.com
 camelmorocco.com
 camelotbrasil.com
 camelotorganics.com
+cameltrektours.com
 camenisch-software.ch
 camera.risami.net
 camera88.vn
@@ -462541,6 +463010,7 @@ dl-45538429.onedrives-en-live.com
 dl-675423.store-downloads.com
 dl-80076342.md-downloads.com
 dl-97674424.md-downloads.com
+dl-link.link
 dl-link.live
 dl-link.network
 dl-rw.com
@@ -464212,6 +464682,7 @@ duck.org
 duckhouse.org
 duckiesplumbing.com.au
 duckpvp.xyz
+duckrambo.com
 ducks.org.tw
 ducontcl.esy.es
 ducro.nl
@@ -471406,6 +471877,7 @@ freedomlifestyleprogram.com
 freedomsec.com.br
 freedomsolutionsuk.co.uk
 freedomtoshine.co
+freedomwellnesstherapy.com
 freedownloadbravebrowser.com
 freeeeweb-com.umbler.net
 freeezguru.com
@@ -479361,6 +479833,7 @@ iapp-hml.adttemp.com.br
 iappco.ir
 iar.webprojemiz.com
 iarpp.ro
+iasdcentralbucaramanga.com
 iasgoogle.com
 iashelpdesk.in
 iasira.dm.files.1drv.com
@@ -481665,6 +482138,7 @@ investicon.in
 investigadoresforenses-abcjuris.com
 investigatorsnorthwest.co.uk
 investime.info
+investinae.com
 investingbazar.com
 investingpivot.co.uk
 investinscs.com
@@ -483888,6 +484362,7 @@ joespoolandspaservice.com
 joeundrosky.com
 joezer-online.com
 jofox.nl
+jofre.eu
 jogaae.jfoaigh.com
 joghataisalam.ir
 joghatay.ir
@@ -488332,7 +488807,6 @@ laparomc.com
 laparoscopysales.com
 lapartenza-khl.com
 lapc.com.pk
-lapcare.com
 lapcentervn.xyz
 lapchallenge.co.uk
 lapelimmortelle.com.au
@@ -489398,7 +489872,6 @@ lgjmcaz.cn
 lglab.co.uk
 lgmi.org.uk
 lgonlinecenter.com
-lgpass.com
 lgrp35.vatelstudents.fr
 lgs.ec
 lgservis.net
@@ -496756,7 +497229,6 @@ moitruongtunglam.com
 mojang.com.br
 mojehaftom.com
 mojewnetrza.pl
-mojno--vse.ru
 mojo-studios.co.uk
 mojorockstar.com
 mojstudent.net
@@ -497283,7 +497755,6 @@ motus.co.rs
 motzadministraties.nl
 mouas.xyz
 mouaysha.com
-moufed.com
 moulin-de-la-hunelle.be
 mouni11.xyz
 mounicmadiraju.com
@@ -498591,6 +499062,7 @@ mytelegramapi.ml
 mytemplate.ro
 mytempucheck.com
 mytest.alessioatzeni.com
+mytestingserver.ml
 mytestwp.cf
 mytex.pe
 mythelxis.gr
@@ -500783,6 +501255,7 @@ no18balloonroom.co.uk
 no1angelsescort.com
 no1spinningfields.90degrees.digital
 no1websitedesigner.com
+no2politics.com
 no70.fun
 noabuseshere.top
 noach.nl
@@ -502206,6 +502679,7 @@ okz.wloclawek.pl
 ol.cognitiononline.in
 olacabattachment.com
 oladi.sulinet.hu
+olafyoutrue.xyz
 olahnyomda.hu
 olairdryport.com
 olalekan419.000webhostapp.com
@@ -503336,6 +503810,7 @@ ostappapa.ru
 ostappnp.myjino.ru
 ostaz.ml
 osteklenie-balkonov.tomsk.ru
+ostemeda.lt
 osteoliv.com
 osteopatasitgesblog.es
 osteopathin-husum.de
@@ -505735,6 +506210,7 @@ physicaltrainernearme.com
 physicianmedical-legalconsulting.com
 physicscafe.com.sg
 physio-bo.de
+physio-svdh.ch
 physio-veda.de
 physionize.com
 physiotherapeutinnen.at
@@ -509836,6 +510312,7 @@ radioinspiraciontv.com
 radiolajee.com
 radioland.eu
 radiolavariada.net
+radiolevi.ro
 radiomaismg.com.br
 radiomaxima.cl
 radiomega-hit.com
@@ -513098,6 +513575,7 @@ s-tech.hu
 s-vrach.com.ua
 s-zone.uz
 s.51shijuan.com
+s.lletlee.com
 s.oooooooooo.ga
 s.put.re
 s.thechinesemuslim.com
@@ -515241,6 +515719,7 @@ seiomon.eu
 seioodsoi.club
 seis.me
 seismophonic.com
+seitaiken.net
 seitenstreifen.ch
 seivenco.com
 seiz-ib.de
@@ -529701,7 +530180,6 @@ url-update.com
 url-validation-clients.com
 url.246546.com
 url.57569.fr.snd52.ch
-url.sg
 url3.mailanyone.net
 url5459.41southbar.com
 url675.textilmallorca.com
diff --git a/urlhaus-filter-hosts-online.txt b/urlhaus-filter-hosts-online.txt
index f80e3351..6cf30e3a 100644
--- a/urlhaus-filter-hosts-online.txt
+++ b/urlhaus-filter-hosts-online.txt
@@ -1,5 +1,5 @@
 # Title: Online Malicious Hosts Blocklist
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -13,11 +13,13 @@
 0.0.0.0 20.dbstrony.pl
 0.0.0.0 21robo.com
 0.0.0.0 24.dbstrony.pl
+0.0.0.0 32792.prolocksmithwinterpark.com
 0.0.0.0 360.lcy2zzx.pw
 0.0.0.0 360down7.miiyun.cn
+0.0.0.0 68468438438.xyz
 0.0.0.0 8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com
+0.0.0.0 87du.vip
 0.0.0.0 8poieq.bn.files.1drv.com
-0.0.0.0 99centsdigitals.com
 0.0.0.0 abcd.bg
 0.0.0.0 abclicks.in
 0.0.0.0 abissnet.net
@@ -25,6 +27,7 @@
 0.0.0.0 absoftechworld.com
 0.0.0.0 absupplies.co.uk
 0.0.0.0 abyssos.eu
+0.0.0.0 academyshademani.com
 0.0.0.0 acbick.com
 0.0.0.0 accounts.thesmarttechhub.com
 0.0.0.0 aceeprc.com.aceeprc.com
@@ -53,7 +56,9 @@
 0.0.0.0 aiqtest.com
 0.0.0.0 ajpharmaholding.com
 0.0.0.0 ajstudiollc.com
+0.0.0.0 akauk09.top
 0.0.0.0 akivj07.top
+0.0.0.0 akpgi08.top
 0.0.0.0 al-wahd.com
 0.0.0.0 alasdemariposas.org
 0.0.0.0 alemelektronik.com
@@ -87,6 +92,7 @@
 0.0.0.0 api.cstdevs.com
 0.0.0.0 api.quocbao.biz
 0.0.0.0 api.sampy.io
+0.0.0.0 aplicativoparasindicato.com.br
 0.0.0.0 apoolcondo.com
 0.0.0.0 app.adsensearticle.com
 0.0.0.0 app.explicitsurveys.co.uk
@@ -94,7 +100,6 @@
 0.0.0.0 apps.saintsoporte.com
 0.0.0.0 aqv.news
 0.0.0.0 areyoulivingwell.com
-0.0.0.0 arsapetrolab.com
 0.0.0.0 artedibujoyarquitectura.com
 0.0.0.0 ask-regard.call-save.biz
 0.0.0.0 atfile.com
@@ -105,10 +110,8 @@
 0.0.0.0 atteuqpotentialunlimited.com
 0.0.0.0 augustair.com
 0.0.0.0 aulist.com
-0.0.0.0 australiafashions.com
 0.0.0.0 automaticrefreshments.com
 0.0.0.0 avadhanagames.com
-0.0.0.0 avissrilanka.com
 0.0.0.0 ayamallah.com
 0.0.0.0 azmeasurement.com
 0.0.0.0 azraktours.com
@@ -146,12 +149,12 @@
 0.0.0.0 blog.oyinblogs.com
 0.0.0.0 blog.takbelit.com
 0.0.0.0 bmlifestyle.co.uk
-0.0.0.0 bnrbook.com
 0.0.0.0 bnrnews.id
 0.0.0.0 bodenstein.co.za
 0.0.0.0 booksearch.com
 0.0.0.0 bounces.mi-fs.com
 0.0.0.0 bpo.correct.go.th
+0.0.0.0 bradleyinstitute.co.za
 0.0.0.0 brandtrust.com.pk
 0.0.0.0 brendanquine.com
 0.0.0.0 brideofmessiah.com
@@ -162,8 +165,6 @@
 0.0.0.0 browardinsurancemiami.solucioneslink.com
 0.0.0.0 bt2.elin.co.za
 0.0.0.0 btdapi.robotake.com
-0.0.0.0 bucrinsuranlceonlines.com
-0.0.0.0 buenavista.co
 0.0.0.0 buigiaphat.com.vn
 0.0.0.0 bullseyemedia.in
 0.0.0.0 busandvanrentalmalaysia.com
@@ -188,6 +189,7 @@
 0.0.0.0 ccauthority.net
 0.0.0.0 cdaonline.com.ar
 0.0.0.0 cec.asso.ac-amiens.fr
+0.0.0.0 cecra.cl
 0.0.0.0 cellas.sk
 0.0.0.0 cendekiabinaaksara.com
 0.0.0.0 cespol-bote.com.mx
@@ -195,8 +197,6 @@
 0.0.0.0 ch.rmu.ac.th
 0.0.0.0 changematterscounselling.com
 0.0.0.0 chardhamdodham.com
-0.0.0.0 cheacrilnsurances.com
-0.0.0.0 chealablilitycarinsurances.com
 0.0.0.0 chezalice.co.za
 0.0.0.0 childselect.com
 0.0.0.0 chinhdropfile.myvnc.com
@@ -216,11 +216,9 @@
 0.0.0.0 constructoralyon.com
 0.0.0.0 consulateins.solucioneslink.com
 0.0.0.0 contributeindustry.com
-0.0.0.0 controladoradeplagasmm.com
 0.0.0.0 controleautomacao.com.br
 0.0.0.0 copelandscapes.com
 0.0.0.0 coulsongraphics.com
-0.0.0.0 coutler.newreadermedia.net
 0.0.0.0 covid19.cyberschool.or.id
 0.0.0.0 cr-sq.com
 0.0.0.0 craftnesia.id
@@ -272,14 +270,14 @@
 0.0.0.0 destinymc.co.za
 0.0.0.0 detorre.es
 0.0.0.0 dev-interestingtech.pantheonsite.io
-0.0.0.0 dev.sayse-tienda.com
 0.0.0.0 dev.sebpo.net
+0.0.0.0 dezcom.com
 0.0.0.0 dfcf.91756.cn
-0.0.0.0 dfsfcsfcdsfsdvcfsvcscv.com
 0.0.0.0 diamantenegro.mi-fs.com
 0.0.0.0 dienmayminhhung.com
 0.0.0.0 digilib.dianhusada.ac.id
 0.0.0.0 djking.f3322.net
+0.0.0.0 dl-link.link
 0.0.0.0 dl.1003b.56a.com
 0.0.0.0 dl.198424.com
 0.0.0.0 dl.installcdn-aws.com
@@ -302,7 +300,6 @@
 0.0.0.0 dovberger.com
 0.0.0.0 down.flash-plays.com
 0.0.0.0 down.pcclear.com
-0.0.0.0 down.udashi.com
 0.0.0.0 down.webbora.com
 0.0.0.0 down1.arpun.com
 0.0.0.0 download.caihong.com
@@ -322,6 +319,7 @@
 0.0.0.0 dsenterprize.co.za
 0.0.0.0 dsspainting.com
 0.0.0.0 du-wizards.com
+0.0.0.0 duckrambo.com
 0.0.0.0 duque.guantanameratravel.com
 0.0.0.0 dutapp.wisolve.co.za
 0.0.0.0 duvalcharter.dekitout.com
@@ -332,7 +330,6 @@
 0.0.0.0 ebruyatkin.com
 0.0.0.0 econews.treegle.org
 0.0.0.0 efficientegroup.com
-0.0.0.0 elliot.newreadermedia.net
 0.0.0.0 en.baoend.com
 0.0.0.0 enc-tech.com
 0.0.0.0 endurotanzania.co.tz
@@ -348,7 +345,6 @@
 0.0.0.0 exilum.com
 0.0.0.0 exitoalfaomega.co
 0.0.0.0 extrovertoffers.com
-0.0.0.0 f1sol.com
 0.0.0.0 familydentist.site
 0.0.0.0 farmaciasdrogaminas.com.br
 0.0.0.0 fate3.xyz
@@ -359,6 +355,7 @@
 0.0.0.0 files.martellexpress.us
 0.0.0.0 final.makkahkmcc.com
 0.0.0.0 fineartgallerym.com
+0.0.0.0 fixauto.illumetechnology.com
 0.0.0.0 fkd.derpcity.ru
 0.0.0.0 flintspin.com
 0.0.0.0 flyingbuddhadesign.com
@@ -368,7 +365,6 @@
 0.0.0.0 footweardirect.elin.co.za
 0.0.0.0 forum.mdb.nu
 0.0.0.0 fotoobjetivo.com
-0.0.0.0 foundationrepairhoustontx.net
 0.0.0.0 foxeps.com.br
 0.0.0.0 freecnetdownload.com
 0.0.0.0 freedombookshop.tickme.lk
@@ -390,7 +386,6 @@
 0.0.0.0 ghislain.dartois.pagesperso-orange.fr
 0.0.0.0 giadungg7.com
 0.0.0.0 giddos.ga
-0.0.0.0 gilliem.com
 0.0.0.0 girotexuniformes.com
 0.0.0.0 giteletropical.com
 0.0.0.0 globaltask.ar
@@ -406,6 +401,7 @@
 0.0.0.0 goldcupmortgage.com
 0.0.0.0 golden-memories-funerals.yourpageserver.com
 0.0.0.0 goldmen.in
+0.0.0.0 gracejukes.com
 0.0.0.0 grupoinmare.com
 0.0.0.0 gruposelt.000webhostapp.com
 0.0.0.0 gs.monerorx.com
@@ -416,6 +412,7 @@
 0.0.0.0 harshraval.in
 0.0.0.0 hd11315.com
 0.0.0.0 hdkamera2003.hu
+0.0.0.0 hdrest.fastlinktz.com
 0.0.0.0 hds.sz4h.com
 0.0.0.0 healthy20.net
 0.0.0.0 heavymaq.cl
@@ -436,7 +433,6 @@
 0.0.0.0 homefindersolutions.com
 0.0.0.0 hongluosi.com
 0.0.0.0 hookedupboatclub.com
-0.0.0.0 hostelkielce.com
 0.0.0.0 hostzaa.com
 0.0.0.0 houstonshutters.site
 0.0.0.0 hr2019.vrcom7.com
@@ -455,7 +451,6 @@
 0.0.0.0 iesanjosemonitos.edu.co
 0.0.0.0 ikexpert.com
 0.0.0.0 ilrafrica.com
-0.0.0.0 images.jermiau.com
 0.0.0.0 imbueautoworx.co.za
 0.0.0.0 incodimsa.com
 0.0.0.0 incrediblepixels.com
@@ -473,8 +468,10 @@
 0.0.0.0 intuitiveideas.com.my
 0.0.0.0 inversiones.arrayanfinanciero.cl
 0.0.0.0 invest.xpcorporative.com.br
+0.0.0.0 investinae.com
 0.0.0.0 ipmes.ma
 0.0.0.0 iremart.es
+0.0.0.0 iris101.co.uk
 0.0.0.0 isaac.mikhailmotoringschool.com
 0.0.0.0 iscamenabe.com
 0.0.0.0 ismf.com.ng
@@ -485,7 +482,6 @@
 0.0.0.0 it123.ru
 0.0.0.0 itc-demo.softgig.co.ke
 0.0.0.0 itconsultus.com.co
-0.0.0.0 jamesjorgensen.newreadermedia.net
 0.0.0.0 jamiekaylive.com
 0.0.0.0 jamshed.pk
 0.0.0.0 jansen-heesch.nl
@@ -493,7 +489,6 @@
 0.0.0.0 jay.diamondrelationscrm.us
 0.0.0.0 jebs.net.au
 0.0.0.0 jeffdahlke.com
-0.0.0.0 jewsjuice.com
 0.0.0.0 jhayesconsulting.com
 0.0.0.0 jiaoyuzixun.cn
 0.0.0.0 jing-da.com.tw
@@ -508,14 +503,11 @@
 0.0.0.0 jpwoodfordco.com
 0.0.0.0 jumpmanualjacobhiller.com
 0.0.0.0 jupiter.toxsl.in
-0.0.0.0 jurgensen.newreadermedia.net
 0.0.0.0 justinscott.com.au
-0.0.0.0 kaizenjanitorial.com
 0.0.0.0 kalawatihomes.com
 0.0.0.0 kalpataru-elitus-mulund.thakkers.in
 0.0.0.0 karer.by
 0.0.0.0 katanvetov.co.il
-0.0.0.0 kbdom.com
 0.0.0.0 kensingtondriving.com
 0.0.0.0 kevinjewelry.com.co
 0.0.0.0 keywatch.yourpageserver.com
@@ -553,7 +545,6 @@
 0.0.0.0 lifebeam.elin.co.za
 0.0.0.0 lindnerelektroanlagen.de
 0.0.0.0 linkintec.cn
-0.0.0.0 litroxlitro.com
 0.0.0.0 livetrack.in
 0.0.0.0 lloydsindian.co.uk
 0.0.0.0 lm.stagingarea.co.za
@@ -567,11 +558,8 @@
 0.0.0.0 logotypfabriken.se
 0.0.0.0 lotix.de
 0.0.0.0 lotusanddragonfly.com
-0.0.0.0 lp.carrduci.com
 0.0.0.0 lp.definerisco.com
 0.0.0.0 lp.difusodesign.com
-0.0.0.0 lp.juancamilogarciareyes.com
-0.0.0.0 lp.tecnimasdecolombia.com.co
 0.0.0.0 ltc.typoten.com
 0.0.0.0 luckybrownie.com
 0.0.0.0 luminouspneuma.com
@@ -601,6 +589,7 @@
 0.0.0.0 materialescantu.com
 0.0.0.0 matruchhaya.co.in
 0.0.0.0 mattysplayground.com
+0.0.0.0 maxiquim.cl
 0.0.0.0 maxtox.com.pk
 0.0.0.0 mbgrm.com
 0.0.0.0 mbsolutions.ge
@@ -610,6 +599,7 @@
 0.0.0.0 mediamaster.co.za
 0.0.0.0 medianews.ge
 0.0.0.0 medistaffconsulting.com
+0.0.0.0 meditreat.itwebservice.in
 0.0.0.0 meeweb.com
 0.0.0.0 megamart.afnan-amc.com
 0.0.0.0 merbay.ru
@@ -680,7 +670,6 @@
 0.0.0.0 nikanpolimer.ir
 0.0.0.0 nilehouse.co.ug
 0.0.0.0 nilinkeji.com
-0.0.0.0 nisacooks.com
 0.0.0.0 njtiledesigncenter.com
 0.0.0.0 nobius.org
 0.0.0.0 nocalnoodle.elin.co.za
@@ -695,7 +684,6 @@
 0.0.0.0 nyeh2o.com.au
 0.0.0.0 oakleyandfriends.co.uk
 0.0.0.0 obseques-conseils.com
-0.0.0.0 ocean.tecnasulstore.com.br
 0.0.0.0 ohe.ie
 0.0.0.0 ohsewgorgeous.co.uk
 0.0.0.0 oknoplastik.sk
@@ -746,7 +734,6 @@
 0.0.0.0 payments.atifsiddiqui.me
 0.0.0.0 pcsoori.com
 0.0.0.0 pd.oceaniarp.net
-0.0.0.0 perpus.onlineman7-jombang.sch.id
 0.0.0.0 perpustekim.untirta.ac.id
 0.0.0.0 petercollie.com
 0.0.0.0 ph4s.ru
@@ -767,6 +754,7 @@
 0.0.0.0 poulman.panagiotopoulos-tours.gr
 0.0.0.0 ppdb.smk-ciptaskill.sch.id
 0.0.0.0 pptvideotemplates.com
+0.0.0.0 prestasicash.com.ar
 0.0.0.0 prestigehomeautomation.net
 0.0.0.0 prishaartcreations.com
 0.0.0.0 production.sparshims.com
@@ -780,7 +768,6 @@
 0.0.0.0 prosyarmakassar.com
 0.0.0.0 provence.elin.co.za
 0.0.0.0 prueba.danielluza.com
-0.0.0.0 ptpmeccatronica.eu
 0.0.0.0 pujashoppe.in
 0.0.0.0 punchdialogues.com
 0.0.0.0 punjabdevelopersassociation.com.pk
@@ -832,7 +819,6 @@
 0.0.0.0 rsgym.net
 0.0.0.0 rubazar.pro
 0.0.0.0 rubycityvietnam.com
-0.0.0.0 ruch.newreadermedia.net
 0.0.0.0 ruisgood.ru
 0.0.0.0 ruwadalkuwait.com
 0.0.0.0 rydchile.cl
@@ -866,6 +852,7 @@
 0.0.0.0 serendibsourcing.com
 0.0.0.0 servicemhkd.myvnc.com
 0.0.0.0 servicemhkd80.myvnc.com
+0.0.0.0 serviciovirtual.com.ar
 0.0.0.0 seyranikenger.com.tr
 0.0.0.0 sgessy.com.br
 0.0.0.0 shaheentbfoundation.com
@@ -880,7 +867,6 @@
 0.0.0.0 shopsofe.com
 0.0.0.0 shrushtiinfotech.com
 0.0.0.0 sibernetix.fr
-0.0.0.0 siddharthpanditpautra.com
 0.0.0.0 sige.brisainformatica.com.br
 0.0.0.0 signatureads.co.in
 0.0.0.0 siili.net
@@ -931,7 +917,8 @@
 0.0.0.0 statsres.com
 0.0.0.0 statssound.com
 0.0.0.0 statsspot.com
-0.0.0.0 stattilion.bar
+0.0.0.0 statsvilla.com
+0.0.0.0 stemschool.net
 0.0.0.0 stiepancasetia.ac.id
 0.0.0.0 stott-thompson.co.uk
 0.0.0.0 stratexec.co.za
@@ -943,13 +930,13 @@
 0.0.0.0 supermercadostia.com
 0.0.0.0 support-4-free.com
 0.0.0.0 support.clz.kr
+0.0.0.0 supportit.online
 0.0.0.0 sw.yourpageserver.com
 0.0.0.0 sweaty.dk
 0.0.0.0 sweet-diet.com
 0.0.0.0 swentsai.com
 0.0.0.0 swiftlogisticseg.com
 0.0.0.0 swwbia.com
-0.0.0.0 syedpro.dezinetimes.com
 0.0.0.0 syracusecoffee.com
 0.0.0.0 sys.pbmadu.co.id
 0.0.0.0 sytraders.co
@@ -963,6 +950,7 @@
 0.0.0.0 tapalkoedacoffee.com
 0.0.0.0 tarravalleyfoods.com.au
 0.0.0.0 taurus.ug
+0.0.0.0 tavo.cl
 0.0.0.0 taxicabsrilanka.com
 0.0.0.0 taxpos.com
 0.0.0.0 tc.snpsresidential.com
@@ -983,6 +971,7 @@
 0.0.0.0 test.letraele.es
 0.0.0.0 test.typoten.com
 0.0.0.0 test.wanepghana.org
+0.0.0.0 test1.asistencia247.com
 0.0.0.0 test1.milenial.id
 0.0.0.0 test1.tenplusone.my
 0.0.0.0 test2.basis-web.com
@@ -1049,7 +1038,7 @@
 0.0.0.0 unisoftcc.com
 0.0.0.0 unyazitelecom.com
 0.0.0.0 upcbpta.com
-0.0.0.0 urbane.dezinetimes.com
+0.0.0.0 urbantrapfest.cl
 0.0.0.0 useformoney.000webhostapp.com
 0.0.0.0 usmadetshirts.com
 0.0.0.0 uss.ac.th
@@ -1058,7 +1047,6 @@
 0.0.0.0 vcah.co.uk
 0.0.0.0 vegadelcasero.cl
 0.0.0.0 vendas.lidiacarmeli.com.br
-0.0.0.0 verify.aicosoft.com
 0.0.0.0 vfocus.net
 0.0.0.0 vidmattic.com
 0.0.0.0 vienen.gblix.srv.br
@@ -1076,6 +1064,7 @@
 0.0.0.0 vokasi.ub.ac.id
 0.0.0.0 vologroup.com.br
 0.0.0.0 voteyouramerica.dekitout.com
+0.0.0.0 vpinversiones.cl
 0.0.0.0 vstsample.com
 0.0.0.0 vtube.fadlymotivator.com
 0.0.0.0 vvsskmodinationalschool.com
@@ -1130,6 +1119,5 @@
 0.0.0.0 yskadvisors.com
 0.0.0.0 yummyyogaudaipur.com
 0.0.0.0 yzkzixun.com
-0.0.0.0 zakra.tecnasulstore.com.br
 0.0.0.0 zytrox.tk
 0.0.0.0 zz.690tx.com
diff --git a/urlhaus-filter-hosts.txt b/urlhaus-filter-hosts.txt
index cabda5b1..e89d0ff7 100644
--- a/urlhaus-filter-hosts.txt
+++ b/urlhaus-filter-hosts.txt
@@ -1,5 +1,5 @@
 # Title: Malicious Hosts Blocklist
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1453,6 +1453,7 @@
 0.0.0.0 67373.vip
 0.0.0.0 67lget9865181258.freebackup.fun
 0.0.0.0 67ms.top
+0.0.0.0 68468438438.xyz
 0.0.0.0 68h7.com
 0.0.0.0 695c0lock1.com
 0.0.0.0 69market2.com
@@ -1775,6 +1776,7 @@
 0.0.0.0 999.buzz
 0.0.0.0 999.co.id
 0.0.0.0 999.rajaojek.com
+0.0.0.0 999080321newfolder1002002131-service1002.space
 0.0.0.0 999102com.cn
 0.0.0.0 99bkx.com
 0.0.0.0 99centsdigitals.com
@@ -3272,6 +3274,7 @@
 0.0.0.0 adventureexplorer.in
 0.0.0.0 adventurehr.com
 0.0.0.0 adventureitdate.com
+0.0.0.0 adventureits.com
 0.0.0.0 adventuremania.com
 0.0.0.0 adventurersafaris.com
 0.0.0.0 adventuresofarchibald.com
@@ -4300,6 +4303,7 @@
 0.0.0.0 akatanomastos.net
 0.0.0.0 akatlot.com
 0.0.0.0 akatsolution.net
+0.0.0.0 akauk09.top
 0.0.0.0 akaunting.redocom.com
 0.0.0.0 akawork.io
 0.0.0.0 akbaara.com
@@ -4383,6 +4387,7 @@
 0.0.0.0 akowa.projet-test.com
 0.0.0.0 akowalska.ecrm.pl
 0.0.0.0 akpeugono.com
+0.0.0.0 akpgi08.top
 0.0.0.0 akpp-service.top
 0.0.0.0 akppservis30.ru
 0.0.0.0 akprokonaija.com
@@ -16335,6 +16340,7 @@
 0.0.0.0 camelmorocco.com
 0.0.0.0 camelotbrasil.com
 0.0.0.0 camelotorganics.com
+0.0.0.0 cameltrektours.com
 0.0.0.0 camenisch-software.ch
 0.0.0.0 camera.risami.net
 0.0.0.0 camera88.vn
@@ -26356,6 +26362,7 @@
 0.0.0.0 dl-675423.store-downloads.com
 0.0.0.0 dl-80076342.md-downloads.com
 0.0.0.0 dl-97674424.md-downloads.com
+0.0.0.0 dl-link.link
 0.0.0.0 dl-link.live
 0.0.0.0 dl-link.network
 0.0.0.0 dl-rw.com
@@ -28027,6 +28034,7 @@
 0.0.0.0 duckhouse.org
 0.0.0.0 duckiesplumbing.com.au
 0.0.0.0 duckpvp.xyz
+0.0.0.0 duckrambo.com
 0.0.0.0 ducks.org.tw
 0.0.0.0 ducontcl.esy.es
 0.0.0.0 ducro.nl
@@ -35221,6 +35229,7 @@
 0.0.0.0 freedomsec.com.br
 0.0.0.0 freedomsolutionsuk.co.uk
 0.0.0.0 freedomtoshine.co
+0.0.0.0 freedomwellnesstherapy.com
 0.0.0.0 freedownloadbravebrowser.com
 0.0.0.0 freeeeweb-com.umbler.net
 0.0.0.0 freeezguru.com
@@ -43176,6 +43185,7 @@
 0.0.0.0 iappco.ir
 0.0.0.0 iar.webprojemiz.com
 0.0.0.0 iarpp.ro
+0.0.0.0 iasdcentralbucaramanga.com
 0.0.0.0 iasgoogle.com
 0.0.0.0 iashelpdesk.in
 0.0.0.0 iasira.dm.files.1drv.com
@@ -45480,6 +45490,7 @@
 0.0.0.0 investigadoresforenses-abcjuris.com
 0.0.0.0 investigatorsnorthwest.co.uk
 0.0.0.0 investime.info
+0.0.0.0 investinae.com
 0.0.0.0 investingbazar.com
 0.0.0.0 investingpivot.co.uk
 0.0.0.0 investinscs.com
@@ -47703,6 +47714,7 @@
 0.0.0.0 joeundrosky.com
 0.0.0.0 joezer-online.com
 0.0.0.0 jofox.nl
+0.0.0.0 jofre.eu
 0.0.0.0 jogaae.jfoaigh.com
 0.0.0.0 joghataisalam.ir
 0.0.0.0 joghatay.ir
@@ -52147,7 +52159,6 @@
 0.0.0.0 laparoscopysales.com
 0.0.0.0 lapartenza-khl.com
 0.0.0.0 lapc.com.pk
-0.0.0.0 lapcare.com
 0.0.0.0 lapcentervn.xyz
 0.0.0.0 lapchallenge.co.uk
 0.0.0.0 lapelimmortelle.com.au
@@ -53213,7 +53224,6 @@
 0.0.0.0 lglab.co.uk
 0.0.0.0 lgmi.org.uk
 0.0.0.0 lgonlinecenter.com
-0.0.0.0 lgpass.com
 0.0.0.0 lgrp35.vatelstudents.fr
 0.0.0.0 lgs.ec
 0.0.0.0 lgservis.net
@@ -60571,7 +60581,6 @@
 0.0.0.0 mojang.com.br
 0.0.0.0 mojehaftom.com
 0.0.0.0 mojewnetrza.pl
-0.0.0.0 mojno--vse.ru
 0.0.0.0 mojo-studios.co.uk
 0.0.0.0 mojorockstar.com
 0.0.0.0 mojstudent.net
@@ -61098,7 +61107,6 @@
 0.0.0.0 motzadministraties.nl
 0.0.0.0 mouas.xyz
 0.0.0.0 mouaysha.com
-0.0.0.0 moufed.com
 0.0.0.0 moulin-de-la-hunelle.be
 0.0.0.0 mouni11.xyz
 0.0.0.0 mounicmadiraju.com
@@ -62406,6 +62414,7 @@
 0.0.0.0 mytemplate.ro
 0.0.0.0 mytempucheck.com
 0.0.0.0 mytest.alessioatzeni.com
+0.0.0.0 mytestingserver.ml
 0.0.0.0 mytestwp.cf
 0.0.0.0 mytex.pe
 0.0.0.0 mythelxis.gr
@@ -64598,6 +64607,7 @@
 0.0.0.0 no1angelsescort.com
 0.0.0.0 no1spinningfields.90degrees.digital
 0.0.0.0 no1websitedesigner.com
+0.0.0.0 no2politics.com
 0.0.0.0 no70.fun
 0.0.0.0 noabuseshere.top
 0.0.0.0 noach.nl
@@ -66021,6 +66031,7 @@
 0.0.0.0 ol.cognitiononline.in
 0.0.0.0 olacabattachment.com
 0.0.0.0 oladi.sulinet.hu
+0.0.0.0 olafyoutrue.xyz
 0.0.0.0 olahnyomda.hu
 0.0.0.0 olairdryport.com
 0.0.0.0 olalekan419.000webhostapp.com
@@ -67151,6 +67162,7 @@
 0.0.0.0 ostappnp.myjino.ru
 0.0.0.0 ostaz.ml
 0.0.0.0 osteklenie-balkonov.tomsk.ru
+0.0.0.0 ostemeda.lt
 0.0.0.0 osteoliv.com
 0.0.0.0 osteopatasitgesblog.es
 0.0.0.0 osteopathin-husum.de
@@ -69550,6 +69562,7 @@
 0.0.0.0 physicianmedical-legalconsulting.com
 0.0.0.0 physicscafe.com.sg
 0.0.0.0 physio-bo.de
+0.0.0.0 physio-svdh.ch
 0.0.0.0 physio-veda.de
 0.0.0.0 physionize.com
 0.0.0.0 physiotherapeutinnen.at
@@ -73651,6 +73664,7 @@
 0.0.0.0 radiolajee.com
 0.0.0.0 radioland.eu
 0.0.0.0 radiolavariada.net
+0.0.0.0 radiolevi.ro
 0.0.0.0 radiomaismg.com.br
 0.0.0.0 radiomaxima.cl
 0.0.0.0 radiomega-hit.com
@@ -76913,6 +76927,7 @@
 0.0.0.0 s-vrach.com.ua
 0.0.0.0 s-zone.uz
 0.0.0.0 s.51shijuan.com
+0.0.0.0 s.lletlee.com
 0.0.0.0 s.oooooooooo.ga
 0.0.0.0 s.put.re
 0.0.0.0 s.thechinesemuslim.com
@@ -79056,6 +79071,7 @@
 0.0.0.0 seioodsoi.club
 0.0.0.0 seis.me
 0.0.0.0 seismophonic.com
+0.0.0.0 seitaiken.net
 0.0.0.0 seitenstreifen.ch
 0.0.0.0 seivenco.com
 0.0.0.0 seiz-ib.de
@@ -93513,7 +93529,6 @@
 0.0.0.0 url-validation-clients.com
 0.0.0.0 url.246546.com
 0.0.0.0 url.57569.fr.snd52.ch
-0.0.0.0 url.sg
 0.0.0.0 url3.mailanyone.net
 0.0.0.0 url5459.41southbar.com
 0.0.0.0 url675.textilmallorca.com
diff --git a/urlhaus-filter-online.tpl b/urlhaus-filter-online.tpl
index 15214a8e..4ff3a2c1 100644
--- a/urlhaus-filter-online.tpl
+++ b/urlhaus-filter-online.tpl
@@ -1,6 +1,6 @@
 msFilterList
 # Title: Online Malicious Hosts Blocklist (IE)
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -16,11 +16,13 @@ msFilterList
 -d 20.dbstrony.pl
 -d 21robo.com
 -d 24.dbstrony.pl
+-d 32792.prolocksmithwinterpark.com
 -d 360.lcy2zzx.pw
 -d 360down7.miiyun.cn
+-d 68468438438.xyz
 -d 8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com
+-d 87du.vip
 -d 8poieq.bn.files.1drv.com
--d 99centsdigitals.com
 -d abcd.bg
 -d abclicks.in
 -d abissnet.net
@@ -28,6 +30,7 @@ msFilterList
 -d absoftechworld.com
 -d absupplies.co.uk
 -d abyssos.eu
+-d academyshademani.com
 -d acbick.com
 -d accounts.thesmarttechhub.com
 -d aceeprc.com.aceeprc.com
@@ -56,7 +59,9 @@ msFilterList
 -d aiqtest.com
 -d ajpharmaholding.com
 -d ajstudiollc.com
+-d akauk09.top
 -d akivj07.top
+-d akpgi08.top
 -d al-wahd.com
 -d alasdemariposas.org
 -d alemelektronik.com
@@ -90,6 +95,7 @@ msFilterList
 -d api.cstdevs.com
 -d api.quocbao.biz
 -d api.sampy.io
+-d aplicativoparasindicato.com.br
 -d apoolcondo.com
 -d app.adsensearticle.com
 -d app.explicitsurveys.co.uk
@@ -97,7 +103,6 @@ msFilterList
 -d apps.saintsoporte.com
 -d aqv.news
 -d areyoulivingwell.com
--d arsapetrolab.com
 -d artedibujoyarquitectura.com
 -d ask-regard.call-save.biz
 -d atfile.com
@@ -108,10 +113,8 @@ msFilterList
 -d atteuqpotentialunlimited.com
 -d augustair.com
 -d aulist.com
--d australiafashions.com
 -d automaticrefreshments.com
 -d avadhanagames.com
--d avissrilanka.com
 -d ayamallah.com
 -d azmeasurement.com
 -d azraktours.com
@@ -149,12 +152,12 @@ msFilterList
 -d blog.oyinblogs.com
 -d blog.takbelit.com
 -d bmlifestyle.co.uk
--d bnrbook.com
 -d bnrnews.id
 -d bodenstein.co.za
 -d booksearch.com
 -d bounces.mi-fs.com
 -d bpo.correct.go.th
+-d bradleyinstitute.co.za
 -d brandtrust.com.pk
 -d brendanquine.com
 -d brideofmessiah.com
@@ -165,8 +168,6 @@ msFilterList
 -d browardinsurancemiami.solucioneslink.com
 -d bt2.elin.co.za
 -d btdapi.robotake.com
--d bucrinsuranlceonlines.com
--d buenavista.co
 -d buigiaphat.com.vn
 -d bullseyemedia.in
 -d busandvanrentalmalaysia.com
@@ -191,6 +192,7 @@ msFilterList
 -d ccauthority.net
 -d cdaonline.com.ar
 -d cec.asso.ac-amiens.fr
+-d cecra.cl
 -d cellas.sk
 -d cendekiabinaaksara.com
 -d cespol-bote.com.mx
@@ -198,8 +200,6 @@ msFilterList
 -d ch.rmu.ac.th
 -d changematterscounselling.com
 -d chardhamdodham.com
--d cheacrilnsurances.com
--d chealablilitycarinsurances.com
 -d chezalice.co.za
 -d childselect.com
 -d chinhdropfile.myvnc.com
@@ -219,11 +219,9 @@ msFilterList
 -d constructoralyon.com
 -d consulateins.solucioneslink.com
 -d contributeindustry.com
--d controladoradeplagasmm.com
 -d controleautomacao.com.br
 -d copelandscapes.com
 -d coulsongraphics.com
--d coutler.newreadermedia.net
 -d covid19.cyberschool.or.id
 -d cr-sq.com
 -d craftnesia.id
@@ -275,14 +273,14 @@ msFilterList
 -d destinymc.co.za
 -d detorre.es
 -d dev-interestingtech.pantheonsite.io
--d dev.sayse-tienda.com
 -d dev.sebpo.net
+-d dezcom.com
 -d dfcf.91756.cn
--d dfsfcsfcdsfsdvcfsvcscv.com
 -d diamantenegro.mi-fs.com
 -d dienmayminhhung.com
 -d digilib.dianhusada.ac.id
 -d djking.f3322.net
+-d dl-link.link
 -d dl.1003b.56a.com
 -d dl.198424.com
 -d dl.installcdn-aws.com
@@ -305,7 +303,6 @@ msFilterList
 -d dovberger.com
 -d down.flash-plays.com
 -d down.pcclear.com
--d down.udashi.com
 -d down.webbora.com
 -d down1.arpun.com
 -d download.caihong.com
@@ -325,6 +322,7 @@ msFilterList
 -d dsenterprize.co.za
 -d dsspainting.com
 -d du-wizards.com
+-d duckrambo.com
 -d duque.guantanameratravel.com
 -d dutapp.wisolve.co.za
 -d duvalcharter.dekitout.com
@@ -335,7 +333,6 @@ msFilterList
 -d ebruyatkin.com
 -d econews.treegle.org
 -d efficientegroup.com
--d elliot.newreadermedia.net
 -d en.baoend.com
 -d enc-tech.com
 -d endurotanzania.co.tz
@@ -351,7 +348,6 @@ msFilterList
 -d exilum.com
 -d exitoalfaomega.co
 -d extrovertoffers.com
--d f1sol.com
 -d familydentist.site
 -d farmaciasdrogaminas.com.br
 -d fate3.xyz
@@ -362,6 +358,7 @@ msFilterList
 -d files.martellexpress.us
 -d final.makkahkmcc.com
 -d fineartgallerym.com
+-d fixauto.illumetechnology.com
 -d fkd.derpcity.ru
 -d flintspin.com
 -d flyingbuddhadesign.com
@@ -371,7 +368,6 @@ msFilterList
 -d footweardirect.elin.co.za
 -d forum.mdb.nu
 -d fotoobjetivo.com
--d foundationrepairhoustontx.net
 -d foxeps.com.br
 -d freecnetdownload.com
 -d freedombookshop.tickme.lk
@@ -393,7 +389,6 @@ msFilterList
 -d ghislain.dartois.pagesperso-orange.fr
 -d giadungg7.com
 -d giddos.ga
--d gilliem.com
 -d girotexuniformes.com
 -d giteletropical.com
 -d globaltask.ar
@@ -409,6 +404,7 @@ msFilterList
 -d goldcupmortgage.com
 -d golden-memories-funerals.yourpageserver.com
 -d goldmen.in
+-d gracejukes.com
 -d grupoinmare.com
 -d gruposelt.000webhostapp.com
 -d gs.monerorx.com
@@ -419,6 +415,7 @@ msFilterList
 -d harshraval.in
 -d hd11315.com
 -d hdkamera2003.hu
+-d hdrest.fastlinktz.com
 -d hds.sz4h.com
 -d healthy20.net
 -d heavymaq.cl
@@ -439,7 +436,6 @@ msFilterList
 -d homefindersolutions.com
 -d hongluosi.com
 -d hookedupboatclub.com
--d hostelkielce.com
 -d hostzaa.com
 -d houstonshutters.site
 -d hr2019.vrcom7.com
@@ -458,7 +454,6 @@ msFilterList
 -d iesanjosemonitos.edu.co
 -d ikexpert.com
 -d ilrafrica.com
--d images.jermiau.com
 -d imbueautoworx.co.za
 -d incodimsa.com
 -d incrediblepixels.com
@@ -476,8 +471,10 @@ msFilterList
 -d intuitiveideas.com.my
 -d inversiones.arrayanfinanciero.cl
 -d invest.xpcorporative.com.br
+-d investinae.com
 -d ipmes.ma
 -d iremart.es
+-d iris101.co.uk
 -d isaac.mikhailmotoringschool.com
 -d iscamenabe.com
 -d ismf.com.ng
@@ -488,7 +485,6 @@ msFilterList
 -d it123.ru
 -d itc-demo.softgig.co.ke
 -d itconsultus.com.co
--d jamesjorgensen.newreadermedia.net
 -d jamiekaylive.com
 -d jamshed.pk
 -d jansen-heesch.nl
@@ -496,7 +492,6 @@ msFilterList
 -d jay.diamondrelationscrm.us
 -d jebs.net.au
 -d jeffdahlke.com
--d jewsjuice.com
 -d jhayesconsulting.com
 -d jiaoyuzixun.cn
 -d jing-da.com.tw
@@ -511,14 +506,11 @@ msFilterList
 -d jpwoodfordco.com
 -d jumpmanualjacobhiller.com
 -d jupiter.toxsl.in
--d jurgensen.newreadermedia.net
 -d justinscott.com.au
--d kaizenjanitorial.com
 -d kalawatihomes.com
 -d kalpataru-elitus-mulund.thakkers.in
 -d karer.by
 -d katanvetov.co.il
--d kbdom.com
 -d kensingtondriving.com
 -d kevinjewelry.com.co
 -d keywatch.yourpageserver.com
@@ -556,7 +548,6 @@ msFilterList
 -d lifebeam.elin.co.za
 -d lindnerelektroanlagen.de
 -d linkintec.cn
--d litroxlitro.com
 -d livetrack.in
 -d lloydsindian.co.uk
 -d lm.stagingarea.co.za
@@ -570,11 +561,8 @@ msFilterList
 -d logotypfabriken.se
 -d lotix.de
 -d lotusanddragonfly.com
--d lp.carrduci.com
 -d lp.definerisco.com
 -d lp.difusodesign.com
--d lp.juancamilogarciareyes.com
--d lp.tecnimasdecolombia.com.co
 -d ltc.typoten.com
 -d luckybrownie.com
 -d luminouspneuma.com
@@ -604,6 +592,7 @@ msFilterList
 -d materialescantu.com
 -d matruchhaya.co.in
 -d mattysplayground.com
+-d maxiquim.cl
 -d maxtox.com.pk
 -d mbgrm.com
 -d mbsolutions.ge
@@ -613,6 +602,7 @@ msFilterList
 -d mediamaster.co.za
 -d medianews.ge
 -d medistaffconsulting.com
+-d meditreat.itwebservice.in
 -d meeweb.com
 -d megamart.afnan-amc.com
 -d merbay.ru
@@ -683,7 +673,6 @@ msFilterList
 -d nikanpolimer.ir
 -d nilehouse.co.ug
 -d nilinkeji.com
--d nisacooks.com
 -d njtiledesigncenter.com
 -d nobius.org
 -d nocalnoodle.elin.co.za
@@ -698,7 +687,6 @@ msFilterList
 -d nyeh2o.com.au
 -d oakleyandfriends.co.uk
 -d obseques-conseils.com
--d ocean.tecnasulstore.com.br
 -d ohe.ie
 -d ohsewgorgeous.co.uk
 -d oknoplastik.sk
@@ -749,7 +737,6 @@ msFilterList
 -d payments.atifsiddiqui.me
 -d pcsoori.com
 -d pd.oceaniarp.net
--d perpus.onlineman7-jombang.sch.id
 -d perpustekim.untirta.ac.id
 -d petercollie.com
 -d ph4s.ru
@@ -770,6 +757,7 @@ msFilterList
 -d poulman.panagiotopoulos-tours.gr
 -d ppdb.smk-ciptaskill.sch.id
 -d pptvideotemplates.com
+-d prestasicash.com.ar
 -d prestigehomeautomation.net
 -d prishaartcreations.com
 -d production.sparshims.com
@@ -783,7 +771,6 @@ msFilterList
 -d prosyarmakassar.com
 -d provence.elin.co.za
 -d prueba.danielluza.com
--d ptpmeccatronica.eu
 -d pujashoppe.in
 -d punchdialogues.com
 -d punjabdevelopersassociation.com.pk
@@ -835,7 +822,6 @@ msFilterList
 -d rsgym.net
 -d rubazar.pro
 -d rubycityvietnam.com
--d ruch.newreadermedia.net
 -d ruisgood.ru
 -d ruwadalkuwait.com
 -d rydchile.cl
@@ -869,6 +855,7 @@ msFilterList
 -d serendibsourcing.com
 -d servicemhkd.myvnc.com
 -d servicemhkd80.myvnc.com
+-d serviciovirtual.com.ar
 -d seyranikenger.com.tr
 -d sgessy.com.br
 -d shaheentbfoundation.com
@@ -883,7 +870,6 @@ msFilterList
 -d shopsofe.com
 -d shrushtiinfotech.com
 -d sibernetix.fr
--d siddharthpanditpautra.com
 -d sige.brisainformatica.com.br
 -d signatureads.co.in
 -d siili.net
@@ -934,7 +920,8 @@ msFilterList
 -d statsres.com
 -d statssound.com
 -d statsspot.com
--d stattilion.bar
+-d statsvilla.com
+-d stemschool.net
 -d stiepancasetia.ac.id
 -d stott-thompson.co.uk
 -d stratexec.co.za
@@ -946,13 +933,13 @@ msFilterList
 -d supermercadostia.com
 -d support-4-free.com
 -d support.clz.kr
+-d supportit.online
 -d sw.yourpageserver.com
 -d sweaty.dk
 -d sweet-diet.com
 -d swentsai.com
 -d swiftlogisticseg.com
 -d swwbia.com
--d syedpro.dezinetimes.com
 -d syracusecoffee.com
 -d sys.pbmadu.co.id
 -d sytraders.co
@@ -966,6 +953,7 @@ msFilterList
 -d tapalkoedacoffee.com
 -d tarravalleyfoods.com.au
 -d taurus.ug
+-d tavo.cl
 -d taxicabsrilanka.com
 -d taxpos.com
 -d tc.snpsresidential.com
@@ -986,6 +974,7 @@ msFilterList
 -d test.letraele.es
 -d test.typoten.com
 -d test.wanepghana.org
+-d test1.asistencia247.com
 -d test1.milenial.id
 -d test1.tenplusone.my
 -d test2.basis-web.com
@@ -1052,7 +1041,7 @@ msFilterList
 -d unisoftcc.com
 -d unyazitelecom.com
 -d upcbpta.com
--d urbane.dezinetimes.com
+-d urbantrapfest.cl
 -d useformoney.000webhostapp.com
 -d usmadetshirts.com
 -d uss.ac.th
@@ -1061,7 +1050,6 @@ msFilterList
 -d vcah.co.uk
 -d vegadelcasero.cl
 -d vendas.lidiacarmeli.com.br
--d verify.aicosoft.com
 -d vfocus.net
 -d vidmattic.com
 -d vienen.gblix.srv.br
@@ -1079,6 +1067,7 @@ msFilterList
 -d vokasi.ub.ac.id
 -d vologroup.com.br
 -d voteyouramerica.dekitout.com
+-d vpinversiones.cl
 -d vstsample.com
 -d vtube.fadlymotivator.com
 -d vvsskmodinationalschool.com
@@ -1133,6 +1122,5 @@ msFilterList
 -d yskadvisors.com
 -d yummyyogaudaipur.com
 -d yzkzixun.com
--d zakra.tecnasulstore.com.br
 -d zytrox.tk
 -d zz.690tx.com
diff --git a/urlhaus-filter-online.txt b/urlhaus-filter-online.txt
index 42693ea2..6ee5af7e 100644
--- a/urlhaus-filter-online.txt
+++ b/urlhaus-filter-online.txt
@@ -1,5 +1,5 @@
 ! Title: Online Malicious URL Blocklist
-! Updated: Sat, 27 Mar 2021 12:12:22 UTC
+! Updated: Sun, 28 Mar 2021 00:12:34 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -7,19 +7,20 @@
 0-24bpautomentes.hu
 0cl.sldov.ru
 1.11.234.99
+1.186.151.219
 1.222.140.251
-1.222.166.69
 1.222.196.60
 1.245.4.163
 1.246.222.107
 1.246.222.109
 1.246.222.113
 1.246.222.127
-1.246.222.134
+1.246.222.14
 1.246.222.153
 1.246.222.16
 1.246.222.165
 1.246.222.228
+1.246.222.232
 1.246.222.234
 1.246.222.237
 1.246.222.245
@@ -33,6 +34,7 @@
 1.246.222.69
 1.246.222.8
 1.246.222.80
+1.246.222.94
 1.246.222.98
 1.246.223.10
 1.246.223.103
@@ -48,9 +50,9 @@
 1.246.223.32
 1.246.223.35
 1.246.223.4
-1.246.223.48
 1.246.223.49
 1.246.223.54
+1.246.223.58
 1.246.223.59
 1.246.223.6
 1.246.223.61
@@ -70,7 +72,6 @@
 100.8.77.4
 1008691.com
 101.108.130.108
-101.109.246.33
 101.16.183.179
 101.16.98.170
 101.229.85.127
@@ -83,35 +84,40 @@
 101.30.38.204
 101.64.119.250
 101.64.161.70
+101.66.81.70
 101.75.157.99
 102.130.115.14
 102.141.240.139
 103.107.113.22
 103.124.104.118
 103.125.218.107
+103.126.35.40
 103.139.89.205
 103.141.138.12
 103.145.13.24
 103.146.174.208
+103.153.92.76
 103.156.221.66
 103.159.155.214
 103.16.145.25
 103.207.1.146
+103.214.191.141
 103.217.215.21
 103.224.200.40
 103.238.228.3
 103.238.228.4
 103.240.249.121
+103.245.49.180
 103.4.117.26
 103.66.78.171
 103.79.112.254
-103.82.145.111
 103.82.98.170
 103.84.240.130
 103.84.240.228
 103.84.241.123
 103.84.241.94
 103.91.245.12
+103.91.245.14
 103.91.245.16
 103.91.245.17
 103.91.245.19
@@ -123,6 +129,9 @@
 103.91.245.36
 103.91.245.41
 103.91.245.46
+103.91.245.49
+103.91.245.54
+103.91.245.58
 103.92.25.90
 103.92.25.95
 104.184.75.123
@@ -155,7 +164,6 @@
 109.124.90.229
 109.233.196.232
 109.235.7.228
-109.248.58.238
 109.86.85.253
 109.95.200.102
 109.95.200.230
@@ -181,14 +189,12 @@
 110.255.101.184
 110.255.167.147
 110.35.145.127
-110.35.208.21
+110.35.209.175
 110.35.221.77
-110.35.223.92
-110.35.225.24
-110.35.233.147
 110.35.235.57
 110.35.4.2
 110fss.net
+111.118.111.207
 111.118.88.61
 111.119.245.114
 111.125.67.125
@@ -228,17 +234,15 @@
 111.38.26.243
 111.38.8.81
 111.61.52.53
-112.105.117.227
-112.111.100.236
 112.111.108.184
 112.111.31.175
 112.122.62.224
-112.123.200.47
+112.122.63.70
 112.132.134.106
 112.132.147.102
 112.159.108.96
+112.167.165.139
 112.170.124.75
-112.170.219.168
 112.170.233.9
 112.186.210.211
 112.186.96.252
@@ -250,10 +254,8 @@
 112.225.52.145
 112.225.82.4
 112.226.118.229
-112.226.176.167
 112.226.195.104
 112.226.202.111
-112.226.205.96
 112.226.67.193
 112.226.92.34
 112.228.180.95
@@ -263,7 +265,6 @@
 112.229.188.28
 112.229.199.19
 112.230.251.85
-112.234.121.107
 112.234.134.244
 112.234.16.252
 112.234.194.178
@@ -293,18 +294,21 @@
 112.242.106.228
 112.242.18.128
 112.242.2.247
+112.242.97.131
 112.243.115.183
 112.245.12.89
+112.245.178.153
 112.245.5.141
 112.245.8.24
 112.246.162.50
 112.246.180.49
 112.247.100.14
-112.247.14.135
+112.247.16.222
 112.247.161.45
 112.247.191.118
 112.247.214.146
 112.247.240.226
+112.247.25.42
 112.247.81.173
 112.247.82.122
 112.248.148.90
@@ -329,6 +333,8 @@
 112.252.239.103
 112.252.245.249
 112.252.46.212
+112.254.128.160
+112.254.188.228
 112.254.208.123
 112.254.32.5
 112.255.127.212
@@ -344,7 +350,6 @@
 112.27.124.113
 112.27.124.117
 112.27.124.119
-112.27.124.120
 112.27.124.122
 112.27.124.124
 112.27.124.127
@@ -356,7 +361,6 @@
 112.27.124.136
 112.27.124.138
 112.27.124.139
-112.27.124.140
 112.27.124.142
 112.27.124.143
 112.27.124.146
@@ -372,6 +376,7 @@
 112.27.124.168
 112.27.124.171
 112.27.124.172
+112.27.124.174
 112.27.124.175
 112.27.124.176
 112.27.124.178
@@ -390,16 +395,19 @@
 112.27.88.116
 112.27.91.212
 112.27.91.247
+112.30.1.133
 112.30.1.149
 112.30.1.150
 112.30.1.158
-112.30.1.159
+112.30.1.164
 112.30.1.168
 112.30.1.177
 112.30.1.178
 112.30.1.181
+112.30.1.182
 112.30.1.188
 112.30.1.190
+112.30.1.194
 112.30.1.197
 112.30.1.211
 112.30.1.219
@@ -414,15 +422,15 @@
 112.30.1.90
 112.30.1.91
 112.30.100.228
-112.30.110.27
 112.30.110.30
 112.30.110.31
+112.30.110.36
 112.30.110.37
 112.30.110.38
 112.30.110.41
 112.30.110.42
 112.30.110.43
-112.30.110.45
+112.30.110.51
 112.30.110.52
 112.30.110.57
 112.30.110.58
@@ -438,6 +446,7 @@
 112.30.4.136
 112.30.4.37
 112.30.4.52
+112.30.4.53
 112.30.4.57
 112.30.4.61
 112.30.4.70
@@ -447,6 +456,7 @@
 112.31.176.16
 112.31.211.135
 112.31.82.160
+112.31.87.98
 112.53.224.79
 112.65.53.175
 112.72.153.37
@@ -455,6 +465,8 @@
 112.72.162.53
 112.72.176.112
 112.72.176.84
+112.72.226.202
+112.72.231.35
 112.78.45.158
 112.80.118.16
 112.80.127.91
@@ -473,31 +485,24 @@
 112.9.140.247
 112.91.219.195
 112.93.29.211
-112.95.80.165
 113.0.74.25
 113.11.95.254
 113.110.204.254
-113.110.243.79
-113.116.150.147
-113.116.176.26
-113.116.44.33
-113.116.89.82
 113.118.13.194
-113.118.133.113
-113.118.250.227
-113.118.6.104
+113.118.159.178
+113.119.37.141
 113.122.238.68
 113.122.59.84
 113.161.58.249
 113.172.250.35
 113.189.243.248
+113.193.29.42
 113.194.133.9
 113.194.135.154
 113.195.163.26
 113.195.166.46
 113.195.168.190
 113.201.219.47
-113.225.171.27
 113.226.42.250
 113.227.128.9
 113.227.169.170
@@ -505,28 +510,22 @@
 113.227.35.229
 113.231.211.131
 113.231.93.142
-113.232.211.182
+113.232.156.157
 113.234.224.130
 113.235.116.209
 113.253.144.141
 113.254.169.251
 113.59.128.133
-113.59.133.16
-113.59.144.42
 113.59.154.21
 113.59.191.47
 113.61.204.205
 113.86.204.13
 113.87.203.239
-113.87.227.222
-113.88.100.120
-113.88.104.194
-113.88.111.36
-113.88.209.47
 113.88.232.36
 113.88.38.232
+113.88.39.21
+113.90.27.218
 113.92.93.208
-114.199.204.37
 114.199.253.235
 114.224.203.128
 114.226.100.56
@@ -537,7 +536,6 @@
 114.229.52.14
 114.234.189.154
 114.235.115.236
-114.30.54.64
 114.79.161.94
 114.79.172.42
 115.165.216.112
@@ -545,45 +543,49 @@
 115.193.83.0
 115.201.38.185
 115.201.98.176
+115.205.197.221
 115.208.97.42
 115.209.234.226
 115.223.159.80
 115.229.250.130
-115.23.88.135
 115.42.47.36
 115.48.163.47
 115.48.179.43
 115.48.188.17
-115.48.200.115
-115.48.49.84
+115.48.201.26
+115.48.41.101
 115.49.124.80
 115.49.158.175
+115.49.24.63
 115.49.36.220
-115.49.43.52
-115.49.80.117
-115.49.96.88
-115.50.15.24
+115.49.79.131
+115.50.1.41
+115.50.168.160
+115.50.171.192
+115.50.175.205
 115.50.19.136
 115.50.20.73
 115.50.206.128
-115.50.226.30
-115.50.228.168
+115.50.211.74
 115.50.238.227
 115.50.239.77
-115.50.240.72
+115.50.242.7
+115.50.247.46
 115.50.61.82
+115.50.79.78
 115.50.91.30
 115.50.96.254
-115.51.104.85
-115.51.106.209
+115.51.7.254
 115.52.17.196
+115.52.172.72
 115.53.200.130
 115.53.224.134
 115.53.234.210
-115.53.238.224
+115.53.58.228
+115.54.113.49
 115.54.123.147
-115.54.70.108
-115.55.105.154
+115.54.158.251
+115.55.127.0
 115.55.144.42
 115.55.145.147
 115.55.157.96
@@ -591,64 +593,67 @@
 115.55.158.250
 115.55.161.38
 115.55.179.168
+115.55.198.105
 115.55.206.35
 115.55.206.78
 115.55.26.94
 115.55.42.200
+115.55.52.17
 115.56.111.63
 115.56.114.17
-115.56.132.61
+115.56.131.150
 115.56.133.96
 115.56.134.79
+115.56.135.255
 115.56.137.48
 115.56.139.122
-115.56.143.241
+115.56.142.45
 115.56.145.102
 115.56.148.22
+115.56.150.149
 115.56.151.65
 115.56.151.68
 115.56.154.147
-115.56.175.2
+115.56.155.50
 115.56.189.162
+115.56.31.11
 115.56.31.54
 115.56.98.205
 115.56.99.235
 115.58.132.199
 115.58.134.143
-115.58.161.17
+115.58.86.217
 115.58.90.143
+115.58.91.65
 115.59.198.69
-115.59.209.196
 115.59.212.193
 115.59.214.107
 115.59.228.237
-115.59.235.229
 115.59.253.202
 115.59.57.171
 115.59.82.123
-115.61.102.110
+115.61.103.197
+115.61.112.159
 115.61.118.201
 115.61.118.90
-115.61.139.74
-115.62.152.207
+115.61.158.98
 115.62.155.83
+115.62.171.143
 115.62.26.39
+115.63.131.173
 115.63.139.175
 115.63.141.147
 115.63.180.149
 115.63.189.77
 115.63.21.130
-115.63.37.6
 115.63.53.188
 115.73.3.11
 115.75.217.79
 115.78.133.146
 115.92.174.231
-115.96.61.246
-115.97.136.10
+115.97.139.32
 116.124.219.2
 116.149.243.14
-116.2.100.221
 116.206.164.46
 116.207.71.237
 116.211.100.26
@@ -656,22 +661,27 @@
 116.212.142.215
 116.30.4.2
 116.30.95.156
-116.72.51.230
-116.73.222.118
-116.75.199.105
-116.75.212.119
+116.72.28.239
+116.73.52.125
+116.74.101.150
+116.74.17.122
+116.75.193.33
+116.75.198.85
+116.75.212.81
 116.76.114.71
+116.9.43.220
 117.11.234.35
 117.12.48.157
 117.156.69.22
-117.192.224.103
-117.192.225.161
-117.192.225.195
-117.192.227.137
-117.194.160.78
-117.194.163.210
-117.194.166.103
-117.194.166.20
+117.194.148.198
+117.194.160.203
+117.194.164.123
+117.194.167.131
+117.196.48.148
+117.196.48.181
+117.196.50.154
+117.196.50.239
+117.196.50.76
 117.20.204.138
 117.20.204.5
 117.20.210.52
@@ -679,43 +689,17 @@
 117.20.243.40
 117.200.76.54
 117.200.76.60
-117.202.67.238
-117.202.67.246
-117.202.67.4
-117.202.70.96
-117.202.71.179
-117.207.5.156
-117.208.134.226
-117.208.134.64
-117.213.11.104
-117.213.14.17
-117.213.14.30
-117.213.14.62
-117.213.15.179
-117.213.43.219
-117.213.44.116
-117.213.46.160
-117.213.47.183
-117.213.8.163
-117.215.248.14
-117.215.251.253
-117.222.160.108
-117.222.162.50
-117.222.164.19
-117.222.164.21
-117.222.169.141
-117.222.172.16
-117.222.174.16
+117.202.67.92
+117.208.132.10
+117.208.132.45
+117.213.44.102
+117.222.161.42
+117.222.164.100
+117.222.164.189
+117.222.173.218
+117.222.175.120
 117.241.64.105
-117.241.67.141
-117.242.208.153
-117.242.208.95
-117.247.200.129
-117.247.202.150
-117.247.203.156
-117.247.204.118
-117.247.204.66
-117.251.60.194
+117.248.62.29
 117.26.235.164
 117.27.10.73
 117.60.204.190
@@ -727,7 +711,8 @@
 117.91.240.50
 117.93.115.242
 117.93.79.40
-118.172.80.79
+118.114.84.237
+118.172.176.41
 118.176.104.35
 118.176.157.64
 118.176.7.132
@@ -749,10 +734,8 @@
 118.250.51.192
 118.42.125.246
 118.43.180.33
-118.68.245.69
 118.70.83.140
 118.75.120.136
-118.75.200.198
 118.75.240.136
 118.75.240.239
 118.75.50.253
@@ -763,23 +746,21 @@
 118.79.218.157
 118.79.50.203
 118.79.58.82
+118.79.96.11
 118.83.79.43
-118.91.24.27
+118.91.41.135
 118.99.179.164
 118.99.183.235
 118.99.239.217
 119.100.40.250
 119.108.251.176
-119.109.34.245
 119.112.22.58
-119.112.27.20
 119.115.247.23
+119.118.150.84
+119.119.176.198
 119.119.52.202
-119.123.125.139
-119.123.216.42
-119.123.218.76
-119.123.221.158
-119.123.237.218
+119.123.173.95
+119.123.175.210
 119.14.143.145
 119.147.213.57
 119.162.109.111
@@ -837,7 +818,6 @@
 119.189.227.244
 119.190.211.99
 119.190.234.181
-119.190.240.238
 119.191.150.85
 119.191.187.206
 119.191.215.221
@@ -849,13 +829,12 @@
 119.251.12.85
 119.251.14.251
 119.56.131.155
+119.56.140.73
 119.56.143.46
 119.56.143.71
-119.56.144.75
 119.56.148.115
 119.56.155.57
 119.56.172.28
-119.56.195.90
 119.96.37.55
 119.96.70.116
 119.99.188.187
@@ -870,6 +849,7 @@
 12.207.39.227
 120.12.153.54
 120.12.212.5
+120.12.231.61
 120.142.222.22
 120.150.213.110
 120.151.248.134
@@ -892,6 +872,7 @@
 120.193.91.201
 120.193.91.202
 120.193.91.204
+120.193.91.205
 120.193.91.207
 120.193.91.208
 120.193.91.212
@@ -913,31 +894,28 @@
 120.5.15.95
 120.50.66.60
 120.50.93.115
+120.57.214.228
 120.57.98.208
 120.6.141.142
+120.6.241.130
 120.6.8.11
 120.69.131.51
 120.7.75.99
 120.7.90.104
 120.83.189.232
 120.85.165.112
-120.85.169.113
-120.85.170.109
-120.85.173.234
 120.85.185.141
-120.85.236.95
+120.85.196.211
+120.85.208.107
 120.85.238.10
-120.85.238.244
 120.9.32.51
 121.100.114.164
 121.100.96.8
 121.121.44.222
 121.123.53.25
 121.127.155.220
-121.136.249.5
 121.141.11.56
 121.15.142.137
-121.151.78.190
 121.159.22.144
 121.17.103.176
 121.170.234.142
@@ -955,32 +933,25 @@
 121.25.101.86
 121.254.43.215
 121.254.76.17
-121.61.101.93
 121.61.102.1
 121.61.107.189
 121.61.97.195
 121.61.98.151
 121.88.99.236
 122.100.150.204
-122.137.52.122
 122.160.147.53
 122.176.44.34
 122.188.86.225
-122.190.19.204
-122.192.190.203
 122.199.66.28
 122.199.72.23
 122.199.79.27
 122.202.37.85
 122.202.41.23
 122.252.199.3
-122.252.250.22
 122.254.183.207
 122.254.29.37
 122.254.33.214
 123.0.240.58
-123.10.131.225
-123.10.41.32
 123.10.83.136
 123.11.11.207
 123.11.4.168
@@ -993,16 +964,19 @@
 123.110.19.248
 123.110.200.98
 123.110.238.188
-123.12.7.82
+123.12.189.247
+123.12.225.70
+123.12.235.159
+123.12.243.85
 123.128.128.205
 123.128.133.91
 123.128.177.161
 123.129.84.36
 123.129.88.123
-123.13.44.60
 123.130.202.8
 123.130.208.52
 123.130.23.110
+123.130.27.19
 123.130.37.182
 123.130.61.210
 123.130.77.225
@@ -1014,16 +988,19 @@
 123.133.98.135
 123.134.14.130
 123.134.50.186
-123.135.157.193
 123.135.39.36
 123.135.71.150
-123.14.172.149
-123.14.86.82
+123.14.127.238
+123.14.173.199
+123.14.249.33
+123.14.34.240
+123.14.37.32
+123.14.50.214
 123.14.93.154
 123.144.211.86
 123.152.42.4
-123.152.43.21
 123.153.80.178
+123.154.116.116
 123.154.236.114
 123.154.94.1
 123.155.118.36
@@ -1060,22 +1037,23 @@
 123.28.217.23
 123.4.11.40
 123.4.166.2
-123.4.176.22
 123.4.177.93
-123.4.193.171
+123.4.194.152
 123.4.209.154
 123.4.241.118
+123.4.45.31
 123.4.76.117
 123.4.83.66
 123.4.85.149
-123.5.123.60
 123.5.143.203
 123.5.146.238
 123.5.190.167
 123.5.5.242
 123.5.8.211
 123.8.56.94
+123.8.71.27
 123.9.194.169
+123.9.240.115
 123.9.245.207
 124.105.105.222
 124.129.162.169
@@ -1087,7 +1065,9 @@
 124.131.130.95
 124.131.131.71
 124.131.136.75
+124.131.137.147
 124.131.151.135
+124.131.24.185
 124.131.26.243
 124.131.26.78
 124.131.41.48
@@ -1111,7 +1091,6 @@
 124.199.56.198
 124.226.24.117
 124.230.174.233
-124.234.6.130
 124.254.254.61
 124.5.92.20
 124.6.0.4
@@ -1119,8 +1098,8 @@
 124.7.254.85
 124.80.46.73
 124.91.237.147
+124.92.135.37
 124.93.94.207
-124.95.17.41
 125.105.219.169
 125.126.69.95
 125.128.28.161
@@ -1131,65 +1110,64 @@
 125.36.148.42
 125.40.1.127
 125.40.113.66
-125.40.160.116
-125.40.17.14
-125.40.237.130
 125.40.25.140
 125.40.65.120
 125.40.73.6
 125.40.74.153
 125.40.75.22
+125.41.141.41
+125.41.164.60
+125.41.185.186
+125.41.196.114
 125.41.208.139
-125.41.244.43
 125.41.6.192
 125.41.7.204
 125.41.74.22
 125.41.96.238
 125.41.96.33
+125.41.97.231
 125.41.97.81
 125.42.107.136
 125.42.124.114
-125.42.98.24
-125.42.98.35
 125.43.112.123
 125.43.112.182
 125.43.133.130
 125.43.167.192
-125.43.2.169
-125.43.21.157
 125.43.215.244
-125.43.26.36
 125.43.33.20
-125.43.37.138
 125.43.53.50
 125.43.53.9
+125.43.6.186
 125.43.60.218
-125.43.73.19
-125.43.92.62
+125.43.63.47
 125.44.10.125
 125.44.107.182
 125.44.175.118
 125.44.198.62
+125.44.208.152
 125.44.212.131
-125.44.243.220
-125.44.31.79
+125.44.227.51
+125.44.70.64
 125.44.8.227
 125.45.153.91
+125.45.43.63
 125.45.55.146
-125.46.138.117
+125.46.166.112
 125.46.166.125
 125.46.205.88
 125.46.206.160
 125.46.217.52
 125.46.241.237
+125.47.125.16
 125.47.241.188
 125.47.245.200
+125.47.248.131
 125.47.250.98
-125.47.252.106
-125.47.254.154
 125.47.254.44
 125.47.28.18
+125.47.38.142
 125.47.45.218
+125.47.47.212
 125.47.57.80
 125.47.91.51
 125.79.192.197
@@ -1202,12 +1180,13 @@
 139.159.226.180
 139.170.173.198
 139.170.174.162
+139.213.97.191
 139.216.102.151
 139.227.46.137
 14.102.17.222
 14.102.97.204
+14.109.126.96
 14.136.80.242
-14.138.109.129
 14.138.109.26
 14.138.8.215
 14.138.8.51
@@ -1225,27 +1204,25 @@
 14.55.29.2
 14.98.184.178
 140.237.30.113
+140.237.30.172
 140.237.5.43
+140.240.151.177
 142.11.216.5
 142.177.56.127
 146.71.79.230
 148.69.108.177
 149.20.176.179
-149.255.15.112
 149.255.15.134
+149.255.15.172
 149.255.15.180
 149.255.15.182
 149.255.15.184
-149.255.15.191
 149.255.15.213
-149.255.15.235
-149.255.15.27
 149.255.15.43
 149.255.15.87
 149.255.15.99
 149.3.124.194
-149.3.36.210
-149.3.85.55
+149.3.73.210
 150.116.207.99
 151.177.163.87
 151.33.230.191
@@ -1258,7 +1235,6 @@
 153.34.135.92
 153.34.23.76
 153.34.29.28
-153.35.111.46
 153.35.27.49
 153.36.126.35
 158.101.165.14
@@ -1269,27 +1245,28 @@
 162.191.205.175
 162.194.28.60
 162.209.98.174
-163.125.125.6
-163.125.157.64
+162.212.203.250
 163.125.18.93
 163.125.193.148
-163.125.195.248
-163.125.200.199
+163.125.200.118
+163.125.200.242
 163.125.202.193
-163.125.202.195
-163.125.202.21
+163.125.202.255
+163.125.202.87
 163.125.203.198
+163.125.203.236
 163.125.204.156
-163.125.204.244
 163.125.204.34
-163.125.207.61
-163.125.243.131
+163.125.206.16
 163.125.255.165
 163.204.208.169
+163.204.211.136
 163.204.211.228
 163.204.211.58
 163.53.206.228
 165.90.16.5
+168.194.146.145
+168.205.223.254
 168.90.204.207
 170.81.238.178
 171.113.36.216
@@ -1303,11 +1280,13 @@
 171.120.125.147
 171.121.6.162
 171.123.134.239
+171.125.122.91
 171.125.242.71
 171.125.30.233
 171.125.30.93
 171.125.64.223
 171.125.65.22
+171.125.65.89
 171.125.75.68
 171.126.70.133
 171.223.72.123
@@ -1321,7 +1300,6 @@
 171.36.249.91
 171.38.145.146
 171.38.148.69
-171.38.217.222
 171.38.219.189
 171.38.223.110
 171.38.223.213
@@ -1353,12 +1331,13 @@
 175.145.200.216
 175.146.17.227
 175.150.168.92
-175.153.144.2
 175.162.137.166
 175.162.195.27
 175.162.69.13
+175.164.61.215
 175.165.90.198
 175.168.139.182
+175.169.13.182
 175.17.90.14
 175.174.93.57
 175.199.33.139
@@ -1375,10 +1354,8 @@
 176.111.174.67
 176.113.161.104
 176.113.161.113
-176.113.161.120
 176.113.161.128
-176.113.161.138
-176.113.161.59
+176.113.161.60
 176.113.161.65
 176.113.161.66
 176.113.161.76
@@ -1392,37 +1369,36 @@
 176.123.7.127
 176.123.9.243
 176.124.7.225
+176.221.251.238
 176.240.40.142
 176.240.84.106
 177.11.92.78
 177.131.226.235
 177.229.64.218
-177.44.61.243
-177.86.235.143
+177.54.82.154
 178.124.182.187
-178.141.125.98
+178.134.185.112
 178.141.25.82
+178.141.44.152
 178.141.45.2
 178.141.57.166
 178.150.174.65
 178.151.143.2
 178.165.122.141
 178.175.0.140
-178.175.0.42
-178.175.0.47
 178.175.1.139
-178.175.1.143
 178.175.1.153
+178.175.1.176
 178.175.1.182
-178.175.1.224
 178.175.1.244
-178.175.1.247
 178.175.1.249
 178.175.1.250
 178.175.1.252
+178.175.1.44
 178.175.1.80
-178.175.1.99
-178.175.10.102
+178.175.10.104
+178.175.10.121
+178.175.10.178
 178.175.10.34
 178.175.10.42
 178.175.10.71
@@ -1430,118 +1406,117 @@
 178.175.100.110
 178.175.100.129
 178.175.100.180
-178.175.100.187
-178.175.100.190
+178.175.100.191
 178.175.100.218
 178.175.100.34
 178.175.100.4
-178.175.100.87
+178.175.100.52
 178.175.101.110
-178.175.101.243
+178.175.101.173
+178.175.101.191
 178.175.102.134
-178.175.102.152
-178.175.102.190
+178.175.102.14
 178.175.102.221
-178.175.102.228
 178.175.102.245
 178.175.102.35
 178.175.102.53
 178.175.103.172
-178.175.103.195
+178.175.103.24
+178.175.103.246
 178.175.103.27
 178.175.104.106
 178.175.104.110
 178.175.104.120
 178.175.104.140
+178.175.104.151
 178.175.104.155
 178.175.104.16
-178.175.104.169
-178.175.104.183
-178.175.104.196
+178.175.104.199
 178.175.104.206
+178.175.104.239
 178.175.104.49
+178.175.105.122
 178.175.105.125
 178.175.105.146
 178.175.105.197
 178.175.105.217
-178.175.105.220
+178.175.105.240
 178.175.105.245
+178.175.105.248
 178.175.106.104
 178.175.106.106
 178.175.106.118
+178.175.106.149
 178.175.106.18
 178.175.106.193
+178.175.106.36
 178.175.106.37
 178.175.106.77
+178.175.106.83
 178.175.107.0
 178.175.107.133
 178.175.107.149
 178.175.107.240
 178.175.107.245
 178.175.107.83
+178.175.108.65
 178.175.108.87
 178.175.108.94
 178.175.109.132
 178.175.109.140
+178.175.109.227
 178.175.109.37
 178.175.109.77
-178.175.11.109
+178.175.11.155
 178.175.11.165
 178.175.11.176
-178.175.11.184
 178.175.11.204
+178.175.11.241
 178.175.11.57
 178.175.11.6
 178.175.110.155
 178.175.110.169
+178.175.110.194
 178.175.110.197
 178.175.110.198
 178.175.110.221
-178.175.110.250
 178.175.111.105
 178.175.111.159
 178.175.111.187
 178.175.111.190
-178.175.111.203
+178.175.111.195
 178.175.111.206
-178.175.111.36
 178.175.111.98
 178.175.112.139
 178.175.112.147
 178.175.112.159
 178.175.112.4
 178.175.112.46
-178.175.112.59
-178.175.112.66
 178.175.112.85
-178.175.113.174
 178.175.114.200
 178.175.114.254
-178.175.114.29
-178.175.114.51
 178.175.114.55
 178.175.114.63
 178.175.114.90
 178.175.114.99
-178.175.115.138
+178.175.115.147
+178.175.115.175
 178.175.115.206
 178.175.115.208
+178.175.115.88
+178.175.116.101
+178.175.116.170
 178.175.116.188
-178.175.116.200
 178.175.116.227
 178.175.116.48
 178.175.116.64
-178.175.117.209
-178.175.117.215
+178.175.117.12
 178.175.117.39
-178.175.117.51
 178.175.118.112
 178.175.118.113
-178.175.118.165
 178.175.118.192
 178.175.118.198
 178.175.118.47
-178.175.118.60
 178.175.119.215
 178.175.119.237
 178.175.119.26
@@ -1553,53 +1528,45 @@
 178.175.12.40
 178.175.12.53
 178.175.12.70
+178.175.12.93
 178.175.12.97
-178.175.120.133
-178.175.120.162
 178.175.120.184
-178.175.120.196
 178.175.120.203
 178.175.120.231
 178.175.120.4
+178.175.120.5
+178.175.121.104
 178.175.121.116
-178.175.121.122
 178.175.121.123
 178.175.121.155
-178.175.121.190
+178.175.121.19
+178.175.121.192
+178.175.121.193
 178.175.121.229
-178.175.121.63
-178.175.121.83
-178.175.122.123
-178.175.122.130
-178.175.122.168
+178.175.122.199
 178.175.122.201
+178.175.122.208
 178.175.122.217
 178.175.122.245
 178.175.122.26
 178.175.122.28
 178.175.123.191
-178.175.123.196
 178.175.123.2
+178.175.123.26
 178.175.123.30
-178.175.123.40
 178.175.123.56
 178.175.123.7
 178.175.123.90
 178.175.124.109
 178.175.124.122
-178.175.124.131
 178.175.124.197
 178.175.124.4
 178.175.124.79
 178.175.124.89
-178.175.124.9
 178.175.125.14
 178.175.125.153
-178.175.125.174
-178.175.125.227
-178.175.125.39
+178.175.125.56
 178.175.126.167
-178.175.126.171
 178.175.126.220
 178.175.126.222
 178.175.126.237
@@ -1608,27 +1575,26 @@
 178.175.126.83
 178.175.126.93
 178.175.127.10
-178.175.127.119
 178.175.127.122
 178.175.127.15
 178.175.127.159
 178.175.127.166
+178.175.127.168
 178.175.127.176
+178.175.127.219
 178.175.127.230
 178.175.127.231
 178.175.127.236
-178.175.127.237
+178.175.127.43
 178.175.127.63
 178.175.127.64
 178.175.127.75
-178.175.13.1
-178.175.13.157
+178.175.127.97
 178.175.13.19
 178.175.13.220
 178.175.13.237
-178.175.13.250
+178.175.14.131
 178.175.14.178
-178.175.14.185
 178.175.14.230
 178.175.14.60
 178.175.14.69
@@ -1636,11 +1602,9 @@
 178.175.15.199
 178.175.15.215
 178.175.15.217
-178.175.15.253
 178.175.15.35
 178.175.15.45
 178.175.15.5
-178.175.15.85
 178.175.16.1
 178.175.16.108
 178.175.16.114
@@ -1648,11 +1612,11 @@
 178.175.16.179
 178.175.16.221
 178.175.16.49
-178.175.16.59
 178.175.16.73
 178.175.16.97
+178.175.17.118
 178.175.17.245
-178.175.18.93
+178.175.17.66
 178.175.19.163
 178.175.19.174
 178.175.19.229
@@ -1660,6 +1624,7 @@
 178.175.2.108
 178.175.2.110
 178.175.2.123
+178.175.2.186
 178.175.2.188
 178.175.2.237
 178.175.2.41
@@ -1668,22 +1633,21 @@
 178.175.2.54
 178.175.20.117
 178.175.20.170
-178.175.20.225
 178.175.20.237
 178.175.20.24
 178.175.20.70
+178.175.20.97
 178.175.21.149
-178.175.21.170
 178.175.21.184
 178.175.21.233
 178.175.21.238
+178.175.21.28
 178.175.21.76
 178.175.21.8
 178.175.22.110
 178.175.22.147
 178.175.22.237
 178.175.22.247
-178.175.23.102
 178.175.23.156
 178.175.23.228
 178.175.23.250
@@ -1693,24 +1657,22 @@
 178.175.24.171
 178.175.24.172
 178.175.24.177
-178.175.24.216
+178.175.24.198
 178.175.24.218
 178.175.24.238
 178.175.24.243
 178.175.24.77
 178.175.25.113
 178.175.25.117
-178.175.25.169
+178.175.25.148
 178.175.25.177
 178.175.25.28
 178.175.25.46
 178.175.25.56
-178.175.25.64
 178.175.25.75
 178.175.25.77
 178.175.26.112
 178.175.26.116
-178.175.26.164
 178.175.26.165
 178.175.26.209
 178.175.26.215
@@ -1719,7 +1681,7 @@
 178.175.26.246
 178.175.26.34
 178.175.27.106
-178.175.27.122
+178.175.27.137
 178.175.27.138
 178.175.27.14
 178.175.27.167
@@ -1727,43 +1689,50 @@
 178.175.27.177
 178.175.27.179
 178.175.27.199
-178.175.27.202
 178.175.27.215
 178.175.27.225
 178.175.27.233
 178.175.27.239
+178.175.27.244
 178.175.27.32
 178.175.27.37
 178.175.27.46
 178.175.27.48
-178.175.27.68
 178.175.27.69
 178.175.28.102
 178.175.28.199
+178.175.28.200
+178.175.28.51
+178.175.28.69
 178.175.29.16
 178.175.29.173
 178.175.29.174
 178.175.29.2
 178.175.29.201
 178.175.29.207
+178.175.29.208
 178.175.29.220
+178.175.29.7
 178.175.3.116
-178.175.3.130
 178.175.3.166
 178.175.3.172
 178.175.3.190
 178.175.3.196
 178.175.3.214
+178.175.3.66
+178.175.3.87
 178.175.30.0
 178.175.30.135
 178.175.30.213
-178.175.30.252
 178.175.30.70
 178.175.30.93
 178.175.30.96
 178.175.31.171
 178.175.31.251
+178.175.31.252
 178.175.31.6
+178.175.31.99
+178.175.32.14
 178.175.32.197
 178.175.32.198
 178.175.32.2
@@ -1771,36 +1740,38 @@
 178.175.32.211
 178.175.32.229
 178.175.32.243
+178.175.32.244
 178.175.32.89
-178.175.32.95
 178.175.33.112
 178.175.33.141
 178.175.33.162
 178.175.33.173
 178.175.33.181
-178.175.33.2
+178.175.33.196
 178.175.33.208
+178.175.33.21
 178.175.33.215
 178.175.33.228
 178.175.33.234
+178.175.33.245
 178.175.33.26
-178.175.33.28
-178.175.33.63
 178.175.34.1
 178.175.34.2
 178.175.34.200
-178.175.34.243
-178.175.35.144
+178.175.34.53
 178.175.35.21
 178.175.35.38
 178.175.35.83
+178.175.35.91
 178.175.36.0
 178.175.36.127
 178.175.36.129
+178.175.36.184
 178.175.36.218
 178.175.36.231
 178.175.36.245
 178.175.36.33
+178.175.36.5
 178.175.37.107
 178.175.37.135
 178.175.37.153
@@ -1809,25 +1780,26 @@
 178.175.37.38
 178.175.37.56
 178.175.37.6
+178.175.37.71
 178.175.37.81
 178.175.37.83
 178.175.38.1
 178.175.38.132
-178.175.38.141
 178.175.38.165
-178.175.38.191
-178.175.38.28
 178.175.38.98
+178.175.39.110
+178.175.39.129
 178.175.39.158
 178.175.39.245
 178.175.39.57
+178.175.39.63
 178.175.4.144
+178.175.4.192
 178.175.4.219
-178.175.4.222
 178.175.4.231
+178.175.4.233
 178.175.4.95
 178.175.40.155
-178.175.40.166
 178.175.40.226
 178.175.40.228
 178.175.40.41
@@ -1837,12 +1809,14 @@
 178.175.41.203
 178.175.41.34
 178.175.42.171
+178.175.42.228
+178.175.42.240
+178.175.42.25
 178.175.43.1
 178.175.43.106
 178.175.43.121
 178.175.43.138
 178.175.43.147
-178.175.43.217
 178.175.43.30
 178.175.43.33
 178.175.43.69
@@ -1850,7 +1824,6 @@
 178.175.44.134
 178.175.44.143
 178.175.44.155
-178.175.44.186
 178.175.44.197
 178.175.44.217
 178.175.44.22
@@ -1859,11 +1832,9 @@
 178.175.44.89
 178.175.44.90
 178.175.44.95
-178.175.44.96
-178.175.45.191
 178.175.45.205
+178.175.45.25
 178.175.45.6
-178.175.45.87
 178.175.46.119
 178.175.46.187
 178.175.46.224
@@ -1871,28 +1842,34 @@
 178.175.47.11
 178.175.47.141
 178.175.47.151
+178.175.47.16
 178.175.47.168
 178.175.47.245
 178.175.48.110
 178.175.48.168
 178.175.49.139
+178.175.49.214
 178.175.49.247
+178.175.49.252
 178.175.49.3
 178.175.5.17
 178.175.5.51
+178.175.5.79
 178.175.50.131
+178.175.50.168
 178.175.50.177
 178.175.50.22
 178.175.50.236
 178.175.50.237
-178.175.50.27
+178.175.50.32
 178.175.51.137
 178.175.51.160
 178.175.51.202
 178.175.51.66
+178.175.52.146
 178.175.52.161
+178.175.52.21
 178.175.52.212
-178.175.52.71
 178.175.52.94
 178.175.53.135
 178.175.53.151
@@ -1903,16 +1880,16 @@
 178.175.53.56
 178.175.53.58
 178.175.53.79
+178.175.54.15
 178.175.54.158
 178.175.54.163
+178.175.54.167
 178.175.54.205
-178.175.54.214
 178.175.54.225
 178.175.54.64
 178.175.55.103
 178.175.55.14
 178.175.55.163
-178.175.55.181
 178.175.55.25
 178.175.55.29
 178.175.55.38
@@ -1922,122 +1899,114 @@
 178.175.56.103
 178.175.56.11
 178.175.56.120
-178.175.56.18
-178.175.56.196
 178.175.56.24
 178.175.56.252
 178.175.56.33
 178.175.56.37
 178.175.56.50
+178.175.56.52
 178.175.56.54
 178.175.56.72
 178.175.56.75
 178.175.57.10
 178.175.57.141
 178.175.57.179
+178.175.57.99
 178.175.58.28
-178.175.58.29
 178.175.58.74
 178.175.58.79
 178.175.59.161
+178.175.59.241
 178.175.59.33
-178.175.59.47
 178.175.59.54
 178.175.6.134
 178.175.6.157
 178.175.6.189
+178.175.6.89
 178.175.60.209
 178.175.60.212
-178.175.60.251
+178.175.60.76
 178.175.61.156
 178.175.61.163
 178.175.61.17
 178.175.61.171
+178.175.61.178
 178.175.61.219
 178.175.61.237
+178.175.61.95
 178.175.62.111
 178.175.62.115
+178.175.62.141
 178.175.62.166
 178.175.62.168
-178.175.62.208
 178.175.62.42
 178.175.62.43
 178.175.62.70
 178.175.62.8
 178.175.62.84
-178.175.63.167
+178.175.63.192
 178.175.63.21
-178.175.63.73
+178.175.63.230
+178.175.63.78
 178.175.63.96
 178.175.64.12
+178.175.64.155
 178.175.64.156
 178.175.64.158
 178.175.64.187
+178.175.64.190
 178.175.64.22
-178.175.64.30
-178.175.64.50
-178.175.65.115
+178.175.64.231
+178.175.65.19
 178.175.65.202
 178.175.65.236
-178.175.66.105
-178.175.66.123
 178.175.66.186
 178.175.66.192
 178.175.66.199
 178.175.66.211
 178.175.66.228
-178.175.66.43
 178.175.66.54
 178.175.66.93
 178.175.67.0
 178.175.67.36
 178.175.67.51
-178.175.67.8
+178.175.67.55
 178.175.67.81
 178.175.67.83
 178.175.67.89
-178.175.68.109
+178.175.68.116
 178.175.68.44
 178.175.68.66
 178.175.68.85
 178.175.69.111
-178.175.69.112
 178.175.69.119
 178.175.69.128
 178.175.69.18
-178.175.69.4
-178.175.69.96
 178.175.7.6
 178.175.7.60
 178.175.7.71
+178.175.70.10
 178.175.70.109
-178.175.70.12
-178.175.70.147
-178.175.70.18
 178.175.70.196
 178.175.70.218
 178.175.70.246
-178.175.70.38
 178.175.70.5
 178.175.70.50
-178.175.70.64
 178.175.70.71
 178.175.70.83
-178.175.71.202
+178.175.70.93
+178.175.71.160
 178.175.71.45
-178.175.71.55
 178.175.71.84
 178.175.72.108
-178.175.72.13
 178.175.72.222
 178.175.72.30
 178.175.72.37
-178.175.73.127
-178.175.73.77
+178.175.72.47
 178.175.73.96
 178.175.74.182
+178.175.74.205
 178.175.74.48
-178.175.75.130
 178.175.75.181
 178.175.75.19
 178.175.75.84
@@ -2049,97 +2018,101 @@
 178.175.76.217
 178.175.76.83
 178.175.76.9
+178.175.77.248
+178.175.77.34
 178.175.77.46
 178.175.77.47
-178.175.77.71
-178.175.78.118
 178.175.78.198
 178.175.78.243
-178.175.78.46
+178.175.78.57
 178.175.78.97
 178.175.79.17
 178.175.79.244
 178.175.79.247
 178.175.79.69
 178.175.8.100
+178.175.8.227
+178.175.8.64
 178.175.80.100
-178.175.80.114
 178.175.80.129
-178.175.80.17
+178.175.80.197
 178.175.80.20
-178.175.80.35
 178.175.80.41
 178.175.80.61
+178.175.80.68
 178.175.80.79
 178.175.80.86
-178.175.81.17
+178.175.80.89
+178.175.81.19
 178.175.81.192
 178.175.81.226
 178.175.81.232
 178.175.81.244
 178.175.81.253
-178.175.81.50
-178.175.82.137
-178.175.82.32
+178.175.82.23
+178.175.82.73
+178.175.83.144
 178.175.83.2
+178.175.83.20
 178.175.83.247
 178.175.84.102
-178.175.84.109
 178.175.84.159
+178.175.84.17
 178.175.84.215
+178.175.84.28
 178.175.84.42
 178.175.85.153
 178.175.85.183
 178.175.85.23
-178.175.85.55
+178.175.85.230
 178.175.85.57
 178.175.86.119
+178.175.86.122
 178.175.86.36
 178.175.86.59
 178.175.87.126
 178.175.87.139
 178.175.87.144
 178.175.87.253
-178.175.87.68
-178.175.88.127
-178.175.88.140
+178.175.88.160
 178.175.88.166
 178.175.88.181
 178.175.88.182
+178.175.88.24
+178.175.88.248
 178.175.88.69
 178.175.89.157
 178.175.89.169
-178.175.89.24
+178.175.89.30
 178.175.9.125
 178.175.9.139
 178.175.9.175
 178.175.9.179
-178.175.9.183
 178.175.9.198
 178.175.9.210
 178.175.9.215
 178.175.9.225
+178.175.9.64
 178.175.9.84
 178.175.9.95
 178.175.90.122
 178.175.90.167
 178.175.90.172
+178.175.90.185
 178.175.90.21
-178.175.90.212
-178.175.90.244
 178.175.90.4
 178.175.90.74
+178.175.90.81
+178.175.90.90
 178.175.91.108
 178.175.91.13
 178.175.91.15
 178.175.91.244
 178.175.91.253
-178.175.91.40
 178.175.91.96
-178.175.92.128
 178.175.92.132
-178.175.92.141
 178.175.92.186
+178.175.92.200
 178.175.92.215
 178.175.92.231
 178.175.92.253
@@ -2148,37 +2121,32 @@
 178.175.93.143
 178.175.93.150
 178.175.93.159
-178.175.93.34
-178.175.93.45
+178.175.93.199
+178.175.93.44
 178.175.93.62
-178.175.93.93
 178.175.94.195
 178.175.94.200
+178.175.94.27
 178.175.94.40
 178.175.94.55
+178.175.95.116
 178.175.95.141
+178.175.95.163
 178.175.95.17
 178.175.95.227
-178.175.95.237
 178.175.95.4
 178.175.95.56
-178.175.96.169
-178.175.96.192
-178.175.97.1
+178.175.96.81
 178.175.97.128
 178.175.97.135
-178.175.97.143
-178.175.97.78
+178.175.98.216
 178.175.98.228
 178.175.98.254
 178.175.98.29
-178.175.98.36
+178.175.98.44
 178.175.98.68
 178.175.99.123
 178.175.99.130
-178.175.99.22
-178.175.99.45
-178.175.99.88
 178.175.99.91
 178.19.183.14
 178.205.101.33
@@ -2193,6 +2161,7 @@
 178.95.136.35
 179.159.58.134
 179.4.187.39
+179.42.107.139
 179.43.157.173
 179.60.84.7
 179.99.210.161
@@ -2205,7 +2174,6 @@
 180.125.44.194
 180.157.66.204
 180.175.236.209
-180.175.93.52
 180.176.105.41
 180.176.110.243
 180.176.165.230
@@ -2216,6 +2184,7 @@
 180.177.242.73
 180.218.5.171
 180.248.80.38
+180.253.99.109
 180.66.111.36
 180.66.53.93
 180.94.170.166
@@ -2226,123 +2195,131 @@
 181.193.107.10
 181.199.170.222
 181.199.170.230
-181.199.170.240
 181.210.45.42
 181.215.47.82
 181.224.242.131
 181.49.236.4
 181.49.59.162
+182.112.28.118
+182.112.34.220
 182.112.43.249
 182.112.52.131
+182.113.238.197
+182.113.29.28
+182.114.105.40
 182.114.111.64
-182.114.24.20
-182.114.49.104
 182.114.64.27
+182.114.76.42
 182.114.79.103
 182.114.83.88
 182.114.92.90
 182.114.93.96
-182.116.101.82
-182.116.103.234
 182.116.104.106
-182.116.108.180
+182.116.105.208
 182.116.108.244
+182.116.116.70
 182.116.118.250
+182.116.119.66
+182.116.36.175
 182.116.60.73
 182.116.61.252
 182.116.80.107
 182.116.94.196
 182.116.99.150
+182.117.13.57
 182.117.15.172
 182.117.25.120
 182.117.26.235
 182.117.29.220
 182.117.39.51
 182.117.43.27
+182.117.49.127
 182.118.146.181
+182.118.166.128
 182.119.100.135
 182.119.109.173
 182.119.118.218
 182.119.14.252
+182.119.15.78
 182.119.166.208
-182.119.176.209
+182.119.166.76
+182.119.179.193
+182.119.197.123
+182.119.202.180
+182.119.21.68
 182.119.211.69
 182.119.214.120
 182.119.221.141
-182.119.225.30
+182.119.226.84
 182.119.255.115
 182.119.7.54
+182.119.89.107
 182.120.16.22
 182.120.16.46
-182.120.33.117
 182.120.37.251
 182.120.43.0
-182.121.11.43
 182.121.129.163
-182.121.130.67
-182.121.133.46
 182.121.134.70
-182.121.158.141
+182.121.15.223
+182.121.157.35
 182.121.205.201
 182.121.205.237
 182.121.207.195
-182.121.40.234
-182.121.50.111
+182.121.254.147
+182.121.55.106
 182.121.66.189
 182.121.9.117
 182.121.94.13
-182.122.181.105
 182.122.202.18
 182.123.203.21
 182.123.211.239
+182.123.241.195
 182.124.123.107
 182.124.177.48
 182.124.19.87
+182.124.201.207
 182.124.88.122
 182.126.113.127
-182.126.120.66
+182.126.123.19
 182.126.126.203
 182.126.127.254
-182.126.181.121
-182.126.52.233
 182.126.67.24
-182.126.80.108
 182.126.83.79
 182.126.88.138
+182.127.0.16
 182.127.103.79
 182.127.104.235
-182.127.110.147
+182.127.106.43
 182.127.152.3
 182.127.155.157
-182.127.209.26
 182.127.221.243
+182.127.93.38
 182.160.98.250
 182.172.36.164
 182.233.0.252
 182.235.252.31
 182.53.197.62
-182.58.219.8
+182.56.193.251
+182.59.235.150
 183.105.104.83
 183.105.225.154
 183.109.169.45
 183.11.238.228
 183.136.252.233
-183.150.138.131
 183.150.244.122
 183.16.208.30
 183.185.112.19
+183.185.162.225
 183.187.163.176
 183.188.151.225
 183.188.180.116
 183.188.188.186
 183.188.228.38
+183.188.93.116
 183.83.105.21
-183.83.125.235
 183.83.127.89
 183.83.26.115
-183.83.99.87
 183.92.195.140
-183.95.147.102
 183.97.22.14
 184.164.185.41
 184.175.115.10
@@ -2384,14 +2361,11 @@
 186.225.120.173
 186.232.44.86
 186.28.60.184
-186.33.112.218
-186.33.112.228
-186.33.112.66
-186.33.113.241
 186.33.113.77
 186.4.125.48
 186.73.188.132
 187.12.10.98
+187.188.124.229
 187.212.200.162
 187.233.208.103
 187.33.71.68
@@ -2399,12 +2373,12 @@
 188.10.231.246
 188.113.102.18
 188.113.81.17
+188.119.45.194
 188.13.179.87
 188.138.200.32
 188.152.41.141
 188.169.178.50
-188.169.199.59
-188.169.36.163
+188.169.179.151
 188.169.45.140
 188.242.167.159
 188.242.242.144
@@ -2438,6 +2412,7 @@
 190.216.140.123
 190.35.225.36
 190.65.206.162
+190.73.12.149
 190.92.4.231
 190.98.37.135
 190.98.37.200
@@ -2445,7 +2420,6 @@
 191.255.248.220
 192.210.175.130
 192.210.241.200
-192.227.185.106
 192.227.209.27
 192.227.220.55
 192.227.228.67
@@ -2454,6 +2428,7 @@
 192.99.240.77
 193.142.146.25
 193.228.135.144
+193.38.55.9
 193.91.131.237
 194.147.142.230
 194.15.36.167
@@ -2470,7 +2445,6 @@
 197.50.27.115
 198.23.133.218
 198.23.207.121
-198.23.213.57
 198.23.251.105
 198.251.72.110
 198.46.201.76
@@ -2482,7 +2456,9 @@
 2.45.111.158
 2.45.4.24
 2.55.125.182
+2.58.69.44
 2.83.152.16
+20.185.42.197
 20.dbstrony.pl
 200.105.167.98
 200.111.189.70
@@ -2495,17 +2471,16 @@
 201.187.102.73
 201.200.254.86
 201.203.221.20
+201.203.27.37
 201.215.84.97
 201.218.97.142
 202.107.233.41
+202.150.176.100
 202.164.153.80
 202.166.217.54
 202.169.234.22
 202.169.234.37
-202.169.234.47
 202.169.234.52
-202.169.234.55
-202.169.234.9
 202.29.95.12
 202.4.124.58
 202.51.176.114
@@ -2513,12 +2488,10 @@
 202.74.236.9
 203.109.201.243
 203.130.69.205
-203.170.115.82
 203.189.156.107
 203.204.232.18
 203.229.21.56
 203.236.190.28
-203.238.86.202
 203.70.166.107
 203.77.80.159
 203.80.119.166
@@ -2528,7 +2501,6 @@
 203.93.6.28
 204.195.116.171
 205.185.115.74
-205.185.123.217
 206.248.137.132
 206.47.41.166
 207.5.32.6
@@ -2540,6 +2512,7 @@
 210.124.149.19
 210.216.152.122
 210.216.153.142
+210.57.234.131
 210.57.234.93
 210.57.237.70
 210.57.245.109
@@ -2561,6 +2534,7 @@
 211.247.113.49
 211.247.5.96
 211.36.174.137
+211.47.102.51
 211.51.174.149
 212.122.86.105
 212.143.227.22
@@ -2575,11 +2549,11 @@
 213.149.190.193
 213.163.104.12
 213.163.104.138
-213.163.104.160
+213.163.104.7
 213.163.104.99
+213.163.113.100
 213.163.113.135
 213.163.113.225
-213.163.113.23
 213.163.113.237
 213.163.113.51
 213.163.114.155
@@ -2591,7 +2565,9 @@
 213.163.115.33
 213.163.115.71
 213.163.116.132
+213.163.116.181
 213.163.116.192
+213.163.116.197
 213.163.116.203
 213.163.116.33
 213.163.116.85
@@ -2600,21 +2576,21 @@
 213.163.117.97
 213.163.118.129
 213.163.118.144
+213.163.118.236
 213.163.118.238
-213.163.118.65
 213.163.119.24
 213.163.119.240
-213.163.126.104
 213.163.126.20
 213.163.126.243
+213.163.126.249
 213.163.126.60
 213.163.126.7
 213.163.126.84
 213.163.127.204
 213.163.127.217
+213.163.127.242
 213.163.127.46
 213.189.178.163
-213.226.140.23
 213.240.218.15
 213.249.156.189
 213.27.8.6
@@ -2642,6 +2618,7 @@
 218.35.81.81
 218.48.135.50
 218.56.93.129
+218.57.109.48
 218.57.53.55
 218.59.116.203
 218.72.198.15
@@ -2649,33 +2626,37 @@
 218.93.102.63
 218.93.102.75
 219.154.103.40
-219.154.114.132
 219.154.114.45
 219.154.115.250
+219.154.116.168
 219.154.126.205
+219.154.142.35
+219.154.143.132
 219.154.147.58
 219.154.148.116
 219.154.173.163
+219.154.178.138
+219.154.41.36
 219.155.102.14
+219.155.11.252
 219.155.113.58
 219.155.14.17
-219.155.170.22
+219.155.209.253
 219.155.24.246
 219.155.243.184
 219.155.26.204
-219.155.26.37
 219.155.29.165
 219.155.31.15
 219.155.31.67
-219.155.42.216
+219.155.86.156
 219.155.98.64
 219.156.131.116
-219.156.167.103
 219.156.17.217
+219.156.176.153
 219.156.23.29
 219.156.60.224
+219.156.65.47
 219.156.88.219
-219.156.9.32
 219.157.11.39
 219.157.146.200
 219.157.147.87
@@ -2683,8 +2664,8 @@
 219.157.178.201
 219.157.178.210
 219.157.183.29
+219.157.214.235
 219.157.223.241
-219.157.223.245
 219.157.42.228
 219.157.67.171
 219.241.6.180
@@ -2692,6 +2673,7 @@
 219.68.1.84
 219.68.163.7
 219.68.171.144
+219.68.245.63
 219.68.251.32
 219.68.5.140
 219.69.71.186
@@ -2703,21 +2685,21 @@
 220.133.30.200
 220.200.22.163
 220.71.239.115
+220.90.159.188
 221.1.162.82
 221.124.78.15
-221.14.11.33
 221.14.122.127
 221.14.165.237
+221.14.185.105
 221.14.47.162
-221.14.58.5
+221.14.47.189
+221.14.57.175
 221.15.108.55
+221.15.112.103
 221.15.125.190
-221.15.127.124
-221.15.147.220
-221.15.21.133
-221.15.212.123
+221.15.155.186
+221.15.190.2
 221.15.234.159
-221.15.236.211
 221.15.237.107
 221.15.250.213
 221.15.253.236
@@ -2731,8 +2713,10 @@
 221.196.12.96
 221.198.167.192
 221.2.190.22
+221.202.232.230
 221.214.130.147
 221.214.224.184
+221.214.251.109
 221.215.116.167
 221.215.172.207
 221.215.184.31
@@ -2757,52 +2741,50 @@
 222.135.219.29
 222.135.26.161
 222.135.67.115
-222.136.49.252
 222.136.53.227
+222.136.77.190
 222.137.101.251
 222.137.101.33
 222.137.121.127
 222.137.137.5
 222.137.138.252
 222.137.148.192
-222.137.160.202
+222.137.161.88
 222.137.172.250
 222.137.198.247
+222.137.220.215
+222.137.237.203
 222.137.239.124
 222.137.49.36
-222.137.5.150
-222.137.57.234
+222.137.53.193
 222.137.72.146
-222.137.85.26
 222.137.96.9
+222.138.118.192
 222.138.143.84
 222.138.151.100
 222.138.189.138
 222.138.201.241
-222.138.23.254
+222.138.213.235
+222.138.226.142
 222.138.96.79
-222.139.16.229
-222.140.129.239
+222.139.106.55
 222.140.162.140
 222.140.163.112
 222.140.17.245
+222.140.179.142
+222.140.208.18
 222.140.209.222
-222.140.254.11
 222.140.39.66
+222.141.101.39
 222.141.120.26
 222.141.13.77
-222.141.44.36
-222.141.73.249
+222.141.40.69
+222.141.46.119
 222.141.9.0
-222.142.162.164
 222.142.192.66
 222.142.209.231
-222.142.209.7
-222.142.245.207
 222.179.215.189
 222.185.116.233
-222.186.20.19
-222.187.184.136
 222.187.9.178
 222.211.72.66
 222.214.54.208
@@ -2811,7 +2793,7 @@
 222.238.230.7
 222.239.83.232
 222.248.64.253
-222.83.150.240
+222.81.156.229
 222.92.9.126
 222.99.171.192
 223.166.117.210
@@ -2856,7 +2838,7 @@
 27.141.218.17
 27.147.29.52
 27.147.40.128
-27.153.207.1
+27.153.142.115
 27.184.244.14
 27.184.54.199
 27.187.248.22
@@ -2864,7 +2846,6 @@
 27.193.196.190
 27.193.217.210
 27.194.149.142
-27.194.158.229
 27.194.192.66
 27.194.210.20
 27.197.17.88
@@ -2890,13 +2871,11 @@
 27.203.165.138
 27.203.175.203
 27.203.185.42
-27.203.185.48
 27.203.213.79
 27.203.246.96
 27.203.255.42
 27.203.28.115
 27.203.4.188
-27.203.54.217
 27.203.68.144
 27.203.87.75
 27.203.94.134
@@ -2920,11 +2899,10 @@
 27.208.164.18
 27.208.166.13
 27.208.201.212
-27.208.214.139
 27.208.247.130
 27.208.25.59
 27.208.34.2
-27.208.46.167
+27.208.70.115
 27.208.92.64
 27.209.160.222
 27.209.231.15
@@ -2940,6 +2918,7 @@
 27.213.109.105
 27.213.109.58
 27.213.145.221
+27.213.166.50
 27.213.167.175
 27.213.175.208
 27.213.220.5
@@ -2952,6 +2931,7 @@
 27.215.212.209
 27.215.212.80
 27.215.253.149
+27.215.27.143
 27.215.34.242
 27.215.38.119
 27.215.38.166
@@ -2966,7 +2946,6 @@
 27.216.227.95
 27.216.234.98
 27.216.46.85
-27.216.58.120
 27.216.95.56
 27.217.120.226
 27.217.133.53
@@ -3001,23 +2980,30 @@
 27.35.154.13
 27.35.212.124
 27.35.58.5
-27.41.143.46
+27.41.159.28
+27.41.37.155
+27.41.9.105
 27.41.9.44
+27.41.97.36
+27.43.108.78
+27.43.111.161
+27.43.117.66
+27.46.23.10
 27.46.44.130
-27.46.44.161
+27.46.44.153
+27.46.45.86
 27.46.46.100
 27.46.46.252
-27.5.23.215
-27.5.34.254
-27.5.46.18
-27.6.195.65
-27.6.240.125
-27.6.242.65
+27.5.23.69
+27.5.47.16
+27.6.240.171
+27.6.38.96
 31.0.98.131
 31.11.51.57
 31.13.23.180
 31.154.234.3
 31.163.191.11
+31.168.124.130
 31.168.179.83
 31.168.184.59
 31.168.191.243
@@ -3038,11 +3024,13 @@
 31.30.119.23
 32.208.157.193
 32.218.180.9
+32792.prolocksmithwinterpark.com
 35.184.169.169
 36.108.231.218
 36.250.203.246
 36.251.157.225
 36.251.18.18
+36.251.18.63
 36.251.19.88
 36.251.51.244
 36.255.90.219
@@ -3050,10 +3038,13 @@
 36.33.160.167
 36.34.150.236
 36.36.243.67
+36.43.11.16
 36.66.105.159
 36.66.111.203
 36.66.133.125
 36.66.139.36
+36.67.152.161
+36.81.23.38
 36.89.18.133
 36.96.187.93
 360.lcy2zzx.pw
@@ -3108,9 +3099,11 @@
 39.77.150.203
 39.77.197.81
 39.77.209.209
+39.77.48.213
 39.77.94.189
 39.77.95.50
 39.79.146.67
+39.79.163.188
 39.79.166.31
 39.79.218.46
 39.79.62.43
@@ -3122,6 +3115,7 @@
 39.80.205.255
 39.80.24.54
 39.80.36.151
+39.80.37.182
 39.81.251.0
 39.81.27.15
 39.81.29.231
@@ -3141,17 +3135,14 @@
 39.86.216.144
 39.86.234.187
 39.86.248.91
-39.86.60.98
 39.86.66.24
 39.86.73.100
-39.86.78.228
 39.87.63.58
 39.87.90.210
 39.87.93.109
 39.88.141.172
 39.88.155.96
 39.88.233.131
-39.88.41.73
 39.88.67.238
 39.88.72.9
 39.89.146.198
@@ -3166,66 +3157,84 @@
 41.219.185.171
 41.230.31.58
 41.72.203.82
+41.86.18.133
 41.86.18.148
-41.86.18.200
+41.86.18.157
+41.86.18.164
+41.86.18.165
 41.86.18.71
-41.86.21.23
-41.86.5.233
-41.86.5.236
+41.86.19.206
+41.86.19.80
+41.86.21.38
+41.86.21.44
+41.86.21.62
+41.86.5.142
+41.86.5.198
+41.86.5.206
 42.176.112.72
 42.177.164.171
 42.179.162.208
 42.179.163.177
 42.202.101.147
+42.224.122.183
 42.224.122.39
-42.224.169.111
 42.224.171.104
 42.224.172.125
-42.224.18.165
+42.224.188.223
+42.224.189.79
 42.224.19.55
 42.224.220.37
 42.224.233.247
 42.224.234.23
 42.224.245.91
 42.224.249.160
+42.224.249.188
+42.224.3.187
 42.224.36.220
-42.224.56.81
+42.224.52.81
+42.224.68.72
 42.224.69.11
 42.224.70.213
 42.225.120.122
 42.225.205.191
 42.225.241.5
-42.226.89.25
 42.227.194.95
 42.227.196.123
 42.227.66.88
-42.228.39.232
+42.228.196.68
 42.228.40.56
 42.228.60.114
 42.228.67.135
 42.228.68.118
 42.228.70.126
 42.228.70.231
-42.228.84.206
-42.230.153.183
-42.230.219.175
+42.230.218.252
 42.230.25.164
+42.230.46.55
 42.230.48.162
-42.231.95.195
+42.231.95.247
 42.232.102.163
-42.232.23.76
+42.232.46.169
+42.233.159.21
 42.233.78.236
-42.233.90.183
+42.234.247.41
 42.234.85.184
 42.235.23.163
-42.235.3.187
-42.235.82.129
-42.235.86.211
+42.235.67.162
+42.235.82.112
+42.235.87.100
 42.235.90.32
 42.235.95.254
 42.236.148.201
+42.237.142.157
+42.237.24.151
 42.237.252.159
+42.237.60.73
+42.238.228.0
+42.239.155.147
+42.239.202.121
 42.239.21.27
+42.239.218.137
 42.239.98.70
 42.242.200.90
 42.56.15.227
@@ -3234,6 +3243,7 @@
 42.87.29.162
 43.230.156.44
 43.241.106.183
+43.252.8.94
 45.133.1.137
 45.133.1.139
 45.133.1.242
@@ -3248,10 +3258,13 @@
 45.144.225.65
 45.148.10.47
 45.148.10.94
+45.165.215.19
 45.176.108.116
+45.176.108.164
 45.176.108.22
 45.176.108.248
 45.176.110.99
+45.176.111.119
 45.176.111.154
 45.176.111.16
 45.176.111.202
@@ -3267,10 +3280,10 @@
 45.81.235.31
 45.9.148.37
 46.151.155.218
+46.161.185.15
 46.172.75.231
 46.175.184.121
 46.182.173.246
-46.182.173.247
 46.20.63.218
 46.21.153.231
 46.214.27.4
@@ -3292,7 +3305,6 @@
 49.142.87.36
 49.143.32.36
 49.143.43.93
-49.156.35.166
 49.158.201.200
 49.159.20.121
 49.159.21.3
@@ -3303,13 +3315,14 @@
 49.68.221.252
 49.68.249.121
 49.70.15.16
+49.70.95.181
 5.146.202.18
 5.181.135.114
 5.2.70.50
+5.42.37.74
 5.53.146.179
 5.8.10.62
 50.115.174.102
-50.115.174.106
 50.121.91.255
 50.252.47.29
 51.171.146.13
@@ -3317,6 +3330,7 @@
 54.36.114.136
 54.36.180.122
 58.114.246.26
+58.115.108.164
 58.115.162.92
 58.115.174.4
 58.125.191.4
@@ -3331,7 +3345,6 @@
 58.218.67.253
 58.22.212.107
 58.226.129.29
-58.229.194.122
 58.23.245.24
 58.230.89.42
 58.238.42.192
@@ -3340,92 +3353,57 @@
 58.241.78.55
 58.243.126.133
 58.248.112.254
-58.248.140.46
+58.248.117.238
+58.248.142.5
 58.248.143.240
-58.248.144.122
-58.248.144.88
-58.248.147.235
-58.248.151.128
+58.248.144.229
+58.248.147.196
+58.248.151.33
 58.248.153.224
-58.248.76.23
+58.248.74.240
 58.248.77.38
-58.248.82.34
 58.249.12.80
 58.249.14.53
 58.249.16.173
 58.249.19.127
-58.249.23.58
-58.249.73.182
-58.249.74.197
+58.249.72.88
+58.249.74.243
 58.249.74.245
-58.249.75.107
-58.249.75.158
+58.249.75.213
 58.249.77.88
-58.249.79.62
+58.249.80.25
 58.249.82.35
-58.249.86.11
-58.249.87.54
-58.249.88.218
+58.249.87.171
+58.249.89.158
 58.252.176.71
-58.253.13.50
+58.255.133.161
+58.255.140.150
 58.48.154.143
 58.50.221.148
 58.72.165.153
 58.72.165.39
 58.76.151.189
+58.76.151.51
 58.97.206.33
 59.0.211.161
 59.102.168.189
+59.127.11.50
 59.151.202.3
 59.151.214.4
+59.151.246.125
 59.29.133.229
-59.32.97.190
-59.42.62.0
 59.45.235.176
 59.58.104.244
 59.58.117.226
 59.7.124.148
 59.8.35.22
-59.92.176.186
-59.92.18.43
-59.92.181.100
-59.92.182.21
-59.92.182.84
-59.92.218.209
-59.92.218.254
-59.93.17.66
-59.93.18.37
-59.93.22.45
-59.94.180.222
-59.94.181.124
-59.94.183.163
-59.95.174.230
-59.95.175.37
-59.96.38.154
-59.96.38.182
-59.97.168.127
-59.97.169.111
-59.97.169.173
-59.97.171.61
-59.97.172.0
-59.97.173.49
-59.97.174.151
-59.97.175.163
-59.99.136.22
-59.99.136.63
-59.99.138.83
-59.99.139.190
-59.99.141.237
-59.99.40.173
-59.99.40.27
-59.99.41.192
-59.99.44.136
-59.99.44.201
-59.99.44.5
-59.99.47.220
-59.99.47.96
-59.99.93.136
-59.99.94.181
+59.92.180.232
+59.92.217.35
+59.94.180.230
+59.96.37.181
+59.96.37.192
+59.96.39.222
+59.97.193.255
 60.13.61.12
 60.14.48.221
 60.16.247.78
@@ -3443,6 +3421,7 @@
 60.211.19.63
 60.211.6.112
 60.212.100.83
+60.212.111.39
 60.212.162.152
 60.212.202.218
 60.212.206.246
@@ -3453,6 +3432,8 @@
 60.213.162.59
 60.213.58.188
 60.213.83.55
+60.214.217.96
+60.214.32.17
 60.214.73.6
 60.214.93.166
 60.215.165.64
@@ -3466,15 +3447,15 @@
 60.25.115.48
 60.25.76.224
 60.253.15.104
-60.253.39.88
+60.253.4.72
 60.253.42.72
 60.253.51.127
-60.253.8.81
 60.26.17.221
 60.7.10.121
 60.7.8.43
 60.7.99.254
 61.102.243.124
+61.130.195.121
 61.162.169.210
 61.162.55.42
 61.163.142.96
@@ -3482,52 +3463,49 @@
 61.179.171.60
 61.179.91.194
 61.179.91.230
-61.18.112.48
 61.192.73.253
 61.213.118.28
 61.247.224.66
 61.253.94.230
-61.3.124.126
-61.3.124.8
-61.3.127.102
-61.3.149.89
+61.3.124.125
+61.3.151.60
 61.47.220.169
 61.52.103.144
+61.52.103.217
+61.52.109.9
 61.52.11.87
 61.52.159.231
+61.52.167.66
 61.52.195.226
+61.52.210.53
+61.52.211.61
 61.52.212.191
 61.52.214.11
+61.52.234.193
 61.52.237.212
 61.52.242.56
+61.52.30.172
+61.52.4.214
+61.52.42.174
 61.52.48.40
 61.52.76.72
 61.52.9.166
 61.52.9.62
+61.52.98.22
 61.52.99.161
-61.53.100.87
 61.53.102.137
 61.53.117.115
 61.53.119.161
 61.53.122.161
 61.53.123.162
 61.53.192.49
-61.53.2.35
 61.53.201.162
-61.53.54.255
-61.53.72.250
-61.53.81.18
-61.53.99.179
 61.54.103.56
 61.54.168.35
 61.54.232.45
 61.54.40.202
-61.54.58.190
 61.54.58.20
-61.54.63.23
 61.54.64.104
-61.54.76.122
-61.54.77.175
 61.56.180.67
 61.56.181.7
 61.57.96.116
@@ -3572,17 +3550,18 @@
 67.3.169.223
 67.8.138.101
 67.81.98.111
-67.82.242.243
 67.83.49.234
 67.84.138.165
 68.151.244.128
 68.174.182.226
 68.175.107.153
+68.183.25.71
 68.188.144.143
 68.204.88.29
 68.205.106.84
 68.205.119.241
 68.78.33.33
+68468438438.xyz
 69.115.37.205
 69.120.237.255
 69.123.245.151
@@ -3606,7 +3585,6 @@
 71.127.148.69
 71.146.190.91
 71.167.164.113
-71.19.150.93
 71.204.63.239
 71.29.48.164
 71.34.191.213
@@ -3624,16 +3602,17 @@
 72.214.69.226
 72.229.230.118
 72.229.35.40
+72.31.40.122
 73.204.216.103
 74.101.1.159
 74.108.224.112
+74.116.216.141
 74.194.117.165
 74.195.115.176
 74.199.84.77
 74.64.139.223
 74.75.165.81
 75.127.141.52
-75.176.213.114
 75.83.102.27
 75.99.213.61
 76.108.199.153
@@ -3648,6 +3627,7 @@
 77.71.52.220
 77.79.191.32
 77.89.203.238
+77.94.89.20
 78.186.155.18
 78.187.141.144
 78.187.240.125
@@ -3700,7 +3680,6 @@
 82.80.154.214
 82.80.187.109
 82.81.100.54
-82.81.106.65
 82.81.108.172
 82.81.131.158
 82.81.19.42
@@ -3723,9 +3702,9 @@
 84.210.219.208
 84.210.219.213
 84.212.219.127
-84.224.162.170
 84.228.50.118
 84.228.95.204
+84.238.24.35
 84.247.83.74
 84.254.39.129
 84.33.111.227
@@ -3745,6 +3724,7 @@
 85.97.195.129
 86.35.43.220
 87.61.89.40
+87du.vip
 88.119.171.253
 88.2.208.71
 88.2.219.179
@@ -3758,7 +3738,6 @@
 88.250.254.90
 89.122.183.130
 89.29.213.33
-89.34.26.165
 89.35.62.96
 89.40.85.166
 89.40.87.5
@@ -3780,7 +3759,6 @@
 92.114.191.82
 92.241.78.114
 92.27.246.202
-92.54.237.143
 92.54.237.237
 92.83.62.139
 92.85.18.138
@@ -3803,6 +3781,7 @@
 95.153.241.63
 95.154.20.231
 95.158.19.130
+95.170.113.227
 95.170.113.52
 95.170.201.34
 95.181.155.112
@@ -3812,7 +3791,6 @@
 95.9.120.40
 96.239.73.246
 96.47.147.169
-97.103.64.196
 97.68.140.254
 97.96.199.75
 98.0.210.218
@@ -3826,7 +3804,6 @@
 98.30.24.54
 99.150.245.203
 99.33.195.164
-99centsdigitals.com
 abcd.bg
 abclicks.in
 abissnet.net
@@ -3834,6 +3811,7 @@ aboveandbelow.com.au
 absoftechworld.com
 absupplies.co.uk
 abyssos.eu
+academyshademani.com
 acbick.com
 accounts.thesmarttechhub.com
 aceeprc.com.aceeprc.com
@@ -3862,7 +3840,9 @@ agmcarpetcare.co.uk
 aiqtest.com
 ajpharmaholding.com
 ajstudiollc.com
+akauk09.top
 akivj07.top
+akpgi08.top
 al-wahd.com
 alasdemariposas.org
 alemelektronik.com
@@ -3896,6 +3876,7 @@ api-ms.cobainaja.id
 api.cstdevs.com
 api.quocbao.biz
 api.sampy.io
+aplicativoparasindicato.com.br
 apoolcondo.com
 app.adsensearticle.com
 app.explicitsurveys.co.uk
@@ -3903,7 +3884,6 @@ app.prerana.info
 apps.saintsoporte.com
 aqv.news
 areyoulivingwell.com
-arsapetrolab.com
 artedibujoyarquitectura.com
 ask-regard.call-save.biz
 atfile.com
@@ -3914,10 +3894,8 @@ attach.66rpg.com
 atteuqpotentialunlimited.com
 augustair.com
 aulist.com
-australiafashions.com
 automaticrefreshments.com
 avadhanagames.com
-avissrilanka.com
 ayamallah.com
 azmeasurement.com
 azraktours.com
@@ -3955,12 +3933,12 @@ blog.callensaxen.com
 blog.oyinblogs.com
 blog.takbelit.com
 bmlifestyle.co.uk
-bnrbook.com
 bnrnews.id
 bodenstein.co.za
 booksearch.com
 bounces.mi-fs.com
 bpo.correct.go.th
+bradleyinstitute.co.za
 brandtrust.com.pk
 brendanquine.com
 brideofmessiah.com
@@ -3971,8 +3949,6 @@ brightstarshop.com
 browardinsurancemiami.solucioneslink.com
 bt2.elin.co.za
 btdapi.robotake.com
-bucrinsuranlceonlines.com
-buenavista.co
 buigiaphat.com.vn
 bullseyemedia.in
 busandvanrentalmalaysia.com
@@ -3997,6 +3973,7 @@ cazyacustomfurniture.com
 ccauthority.net
 cdaonline.com.ar
 cec.asso.ac-amiens.fr
+cecra.cl
 cellas.sk
 cendekiabinaaksara.com
 cespol-bote.com.mx
@@ -4004,8 +3981,6 @@ cfs5.tistory.com
 ch.rmu.ac.th
 changematterscounselling.com
 chardhamdodham.com
-cheacrilnsurances.com
-chealablilitycarinsurances.com
 chezalice.co.za
 childselect.com
 chinhdropfile.myvnc.com
@@ -4025,11 +4000,9 @@ config.cqhbkjzx.com
 constructoralyon.com
 consulateins.solucioneslink.com
 contributeindustry.com
-controladoradeplagasmm.com
 controleautomacao.com.br
 copelandscapes.com
 coulsongraphics.com
-coutler.newreadermedia.net
 covid19.cyberschool.or.id
 cr-sq.com
 craftnesia.id
@@ -4081,14 +4054,14 @@ despertaresi.com.br
 destinymc.co.za
 detorre.es
 dev-interestingtech.pantheonsite.io
-dev.sayse-tienda.com
 dev.sebpo.net
+dezcom.com
 dfcf.91756.cn
-dfsfcsfcdsfsdvcfsvcscv.com
 diamantenegro.mi-fs.com
 dienmayminhhung.com
 digilib.dianhusada.ac.id
 djking.f3322.net
+dl-link.link
 dl.1003b.56a.com
 dl.198424.com
 dl.installcdn-aws.com
@@ -4111,7 +4084,6 @@ dosman.pl
 dovberger.com
 down.flash-plays.com
 down.pcclear.com
-down.udashi.com
 down.webbora.com
 down1.arpun.com
 download.caihong.com
@@ -4131,6 +4103,7 @@ drsha.innovativesolutions.mobi
 dsenterprize.co.za
 dsspainting.com
 du-wizards.com
+duckrambo.com
 duque.guantanameratravel.com
 dutapp.wisolve.co.za
 duvalcharter.dekitout.com
@@ -4141,7 +4114,6 @@ e.sldov.ru
 ebruyatkin.com
 econews.treegle.org
 efficientegroup.com
-elliot.newreadermedia.net
 en.baoend.com
 enc-tech.com
 endurotanzania.co.tz
@@ -4157,7 +4129,6 @@ evidencemarketing.ca
 exilum.com
 exitoalfaomega.co
 extrovertoffers.com
-f1sol.com
 familydentist.site
 farmaciasdrogaminas.com.br
 fate3.xyz
@@ -4168,6 +4139,7 @@ fi.bonitastores.com
 files.martellexpress.us
 final.makkahkmcc.com
 fineartgallerym.com
+fixauto.illumetechnology.com
 fkd.derpcity.ru
 flintspin.com
 flyingbuddhadesign.com
@@ -4177,7 +4149,6 @@ foothills.com.br
 footweardirect.elin.co.za
 forum.mdb.nu
 fotoobjetivo.com
-foundationrepairhoustontx.net
 foxeps.com.br
 freecnetdownload.com
 freedombookshop.tickme.lk
@@ -4199,7 +4170,6 @@ ghettohub.co.za
 ghislain.dartois.pagesperso-orange.fr
 giadungg7.com
 giddos.ga
-gilliem.com
 girotexuniformes.com
 giteletropical.com
 globaltask.ar
@@ -4215,6 +4185,7 @@ goldcoastoffice365.com.au
 goldcupmortgage.com
 golden-memories-funerals.yourpageserver.com
 goldmen.in
+gracejukes.com
 grupoinmare.com
 gruposelt.000webhostapp.com
 gs.monerorx.com
@@ -4225,6 +4196,7 @@ hagebakken.no
 harshraval.in
 hd11315.com
 hdkamera2003.hu
+hdrest.fastlinktz.com
 hds.sz4h.com
 healthy20.net
 heavymaq.cl
@@ -4245,7 +4217,6 @@ hoayeuthuong-my.sharepoint.com
 homefindersolutions.com
 hongluosi.com
 hookedupboatclub.com
-hostelkielce.com
 hostzaa.com
 houstonshutters.site
 hr2019.vrcom7.com
@@ -4264,7 +4235,6 @@ idvindia.com
 iesanjosemonitos.edu.co
 ikexpert.com
 ilrafrica.com
-images.jermiau.com
 imbueautoworx.co.za
 incodimsa.com
 incrediblepixels.com
@@ -4282,8 +4252,10 @@ intersel-idf.org
 intuitiveideas.com.my
 inversiones.arrayanfinanciero.cl
 invest.xpcorporative.com.br
+investinae.com
 ipmes.ma
 iremart.es
+iris101.co.uk
 isaac.mikhailmotoringschool.com
 iscamenabe.com
 ismf.com.ng
@@ -4294,7 +4266,6 @@ isso.ps
 it123.ru
 itc-demo.softgig.co.ke
 itconsultus.com.co
-jamesjorgensen.newreadermedia.net
 jamiekaylive.com
 jamshed.pk
 jansen-heesch.nl
@@ -4302,7 +4273,6 @@ jathra.co.uk
 jay.diamondrelationscrm.us
 jebs.net.au
 jeffdahlke.com
-jewsjuice.com
 jhayesconsulting.com
 jiaoyuzixun.cn
 jing-da.com.tw
@@ -4317,14 +4287,11 @@ josuarochoa.com
 jpwoodfordco.com
 jumpmanualjacobhiller.com
 jupiter.toxsl.in
-jurgensen.newreadermedia.net
 justinscott.com.au
-kaizenjanitorial.com
 kalawatihomes.com
 kalpataru-elitus-mulund.thakkers.in
 karer.by
 katanvetov.co.il
-kbdom.com
 kensingtondriving.com
 kevinjewelry.com.co
 keywatch.yourpageserver.com
@@ -4362,7 +4329,6 @@ lidoraggiodisole.it
 lifebeam.elin.co.za
 lindnerelektroanlagen.de
 linkintec.cn
-litroxlitro.com
 livetrack.in
 lloydsindian.co.uk
 lm.stagingarea.co.za
@@ -4376,11 +4342,8 @@ login.trezor.com.stockfootagesindia.com
 logotypfabriken.se
 lotix.de
 lotusanddragonfly.com
-lp.carrduci.com
 lp.definerisco.com
 lp.difusodesign.com
-lp.juancamilogarciareyes.com
-lp.tecnimasdecolombia.com.co
 ltc.typoten.com
 luckybrownie.com
 luminouspneuma.com
@@ -4410,6 +4373,7 @@ masjidhabeebiyarazviya.mysunni.com
 materialescantu.com
 matruchhaya.co.in
 mattysplayground.com
+maxiquim.cl
 maxtox.com.pk
 mbgrm.com
 mbsolutions.ge
@@ -4419,6 +4383,7 @@ media-server.skyinternet.com.pk
 mediamaster.co.za
 medianews.ge
 medistaffconsulting.com
+meditreat.itwebservice.in
 meeweb.com
 megamart.afnan-amc.com
 merbay.ru
@@ -4489,7 +4454,6 @@ nidhi.iexist.in
 nikanpolimer.ir
 nilehouse.co.ug
 nilinkeji.com
-nisacooks.com
 njtiledesigncenter.com
 nobius.org
 nocalnoodle.elin.co.za
@@ -4504,7 +4468,6 @@ nuwagi.com
 nyeh2o.com.au
 oakleyandfriends.co.uk
 obseques-conseils.com
-ocean.tecnasulstore.com.br
 ohe.ie
 ohsewgorgeous.co.uk
 oknoplastik.sk
@@ -4555,7 +4518,6 @@ payerrealty.com
 payments.atifsiddiqui.me
 pcsoori.com
 pd.oceaniarp.net
-perpus.onlineman7-jombang.sch.id
 perpustekim.untirta.ac.id
 petercollie.com
 ph4s.ru
@@ -4576,6 +4538,7 @@ posmicrosystems.com
 poulman.panagiotopoulos-tours.gr
 ppdb.smk-ciptaskill.sch.id
 pptvideotemplates.com
+prestasicash.com.ar
 prestigehomeautomation.net
 prishaartcreations.com
 production.sparshims.com
@@ -4589,7 +4552,6 @@ prosoc.nl
 prosyarmakassar.com
 provence.elin.co.za
 prueba.danielluza.com
-ptpmeccatronica.eu
 pujashoppe.in
 punchdialogues.com
 punjabdevelopersassociation.com.pk
@@ -4641,7 +4603,6 @@ rs-toolkit.mikestclair.org
 rsgym.net
 rubazar.pro
 rubycityvietnam.com
-ruch.newreadermedia.net
 ruisgood.ru
 ruwadalkuwait.com
 rydchile.cl
@@ -4675,6 +4636,7 @@ sentierodelviandante.ml
 serendibsourcing.com
 servicemhkd.myvnc.com
 servicemhkd80.myvnc.com
+serviciovirtual.com.ar
 seyranikenger.com.tr
 sgessy.com.br
 shaheentbfoundation.com
@@ -4689,7 +4651,6 @@ shop.goldspot.agency
 shopsofe.com
 shrushtiinfotech.com
 sibernetix.fr
-siddharthpanditpautra.com
 sige.brisainformatica.com.br
 signatureads.co.in
 siili.net
@@ -4740,7 +4701,8 @@ static.3001.net
 statsres.com
 statssound.com
 statsspot.com
-stattilion.bar
+statsvilla.com
+stemschool.net
 stiepancasetia.ac.id
 stott-thompson.co.uk
 stratexec.co.za
@@ -4752,13 +4714,13 @@ sunmarkholidays.com
 supermercadostia.com
 support-4-free.com
 support.clz.kr
+supportit.online
 sw.yourpageserver.com
 sweaty.dk
 sweet-diet.com
 swentsai.com
 swiftlogisticseg.com
 swwbia.com
-syedpro.dezinetimes.com
 syracusecoffee.com
 sys.pbmadu.co.id
 sytraders.co
@@ -4772,6 +4734,7 @@ taltus.co.uk
 tapalkoedacoffee.com
 tarravalleyfoods.com.au
 taurus.ug
+tavo.cl
 taxicabsrilanka.com
 taxpos.com
 tc.snpsresidential.com
@@ -4792,6 +4755,7 @@ test.adventser.com
 test.letraele.es
 test.typoten.com
 test.wanepghana.org
+test1.asistencia247.com
 test1.milenial.id
 test1.tenplusone.my
 test2.basis-web.com
@@ -4858,7 +4822,7 @@ uniengrisb.com
 unisoftcc.com
 unyazitelecom.com
 upcbpta.com
-urbane.dezinetimes.com
+urbantrapfest.cl
 useformoney.000webhostapp.com
 usmadetshirts.com
 uss.ac.th
@@ -4867,7 +4831,6 @@ vbcargo.hu
 vcah.co.uk
 vegadelcasero.cl
 vendas.lidiacarmeli.com.br
-verify.aicosoft.com
 vfocus.net
 vidmattic.com
 vienen.gblix.srv.br
@@ -4885,6 +4848,7 @@ vladimirinternational.com
 vokasi.ub.ac.id
 vologroup.com.br
 voteyouramerica.dekitout.com
+vpinversiones.cl
 vstsample.com
 vtube.fadlymotivator.com
 vvsskmodinationalschool.com
@@ -4939,13 +4903,12 @@ yp.hnggzyjy.cn
 yskadvisors.com
 yummyyogaudaipur.com
 yzkzixun.com
-zakra.tecnasulstore.com.br
 zytrox.tk
 zz.690tx.com
 ||amumufree.weebly.com/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe$all
 ||analogx.com/files/proxyi.exe$all
+||b4ad7b79-534a-4e83-953e-c36da8cf27d9.s3.amazonaws.com/ww/setup.exe$all
 ||bitbucket.org/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe$all
-||bitbucket.org/densjons/bro/downloads/rew.exe$all
 ||bitbucket.org/dvdfv/anjj/downloads/jami.exe$all
 ||bitbucket.org/jpavelski/chpock/downloads/4.exe$all
 ||bitbucket.org/jpavelski/chpock/downloads/6.exe$all
@@ -5027,19 +4990,23 @@ zz.690tx.com
 ||cd.textfiles.com/hmatrix/data/hack1226.exe$all
 ||cdn.discordapp.com/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq$all
 ||cdn.discordapp.com/attachments/816070119281131570/816070273254162442/all.txt$all
+||cdn.discordapp.com/attachments/821809080812437507/824392185902006272/mmp1_1.exe$all
 ||cdn.discordapp.com/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso$all
+||cdn.discordapp.com/attachments/823810712891555890/824413943526195210/runpetest.exe$all
+||cdn.discordapp.com/attachments/824689793140129857/824690065988386816/sendhookfile.exe$all
+||cdn.discordapp.com/attachments/824689793140129857/824691026852970496/photo.exe$all
 ||chiptune.com/razor/rzr-winner_intro.zip$all
 ||cloudme.com/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz$all
 ||cloudme.com/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar$all
 ||codeload.github.com/meteoradminz/hidden-tear/zip/master$all
 ||colfincas.com/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/$all
 ||deepfreedom.org/qz0h69.pdf$all
+||digitalassets.ams3.digitaloceanspaces.com/hold/schost.exe$all
+||digitalassets.ams3.digitaloceanspaces.com/modern/five.exe$all
 ||docs.google.com/uc?id=11jnyjpzkjiie_rzc4xwa2feok3x__yvc$all
 ||docs.google.com/uc?id=151uxflny3vqh_lmghrkgjhhsqxi163sh$all
 ||docs.google.com/uc?id=15iwonkjkhyvri_okkc_llq56aasvnvb9$all
-||docs.google.com/uc?id=16gqndqbduwuhy3qzxdn2nd9nufm_9ctq$all
 ||docs.google.com/uc?id=1ak46tqftzejmq-og_ky2oupgpmkgujtm$all
-||docs.google.com/uc?id=1b6stzilakqykxaw1ct2w9hzccizwotff$all
 ||docs.google.com/uc?id=1brsmnj6g0lxa44ixkypvg5tcxkvi5gjt$all
 ||docs.google.com/uc?id=1by_s4vv8gdmmz8wl-lbpjbjy5adcrjk1$all
 ||docs.google.com/uc?id=1dpsxfbptpyl-zegto9t29vvcku2rjm9u$all
@@ -5048,15 +5015,11 @@ zz.690tx.com
 ||docs.google.com/uc?id=1erajjbz6gdxhsvvorlykzxyeoq-xu7wn$all
 ||docs.google.com/uc?id=1ev7gkzwjgtv2vlbbisg1ragd7nf0-xog$all
 ||docs.google.com/uc?id=1ey8zl85vszh-gdmubkoudacqs6zv2dup$all
-||docs.google.com/uc?id=1f5trx90ulgsd-m1zvdupuf_kfugoo9ye$all
 ||docs.google.com/uc?id=1gq_jf503du9oip5bwzcoi6_kgolr3kx2$all
-||docs.google.com/uc?id=1hlaoow8ug5gjejeeihwetcxyfjodcdut$all
 ||docs.google.com/uc?id=1imrv00kqbfz4ljzwq5qdau1to0zlmaqy$all
 ||docs.google.com/uc?id=1j6pvg1rznjh9pkldcyjiogo8ysiyl8_y$all
 ||docs.google.com/uc?id=1jlcqojhfhgifmirrsv0o5t-2rl-hblai$all
-||docs.google.com/uc?id=1jvvuxwek4wrjqs94bjm8_klnnngj7b5r$all
 ||docs.google.com/uc?id=1k6sh5h-nptesem_jsnuxmhzntnvdlgxz$all
-||docs.google.com/uc?id=1lc8lpsmu5ndjweyusqrxblm0g84sdcc7$all
 ||docs.google.com/uc?id=1lk6n-xrtv0dvdqljl26pzebxzp8tladk$all
 ||docs.google.com/uc?id=1lkcqgpimry4yp8grinnhsotnawquozcz$all
 ||docs.google.com/uc?id=1m34mp1cggxz-cz3a5ipjrgfog_qx8myx$all
@@ -5064,29 +5027,19 @@ zz.690tx.com
 ||docs.google.com/uc?id=1m8w1y1-mxxa2pktrzkwfetwjxrlw1alo$all
 ||docs.google.com/uc?id=1m9jxzqcbnb8j8uph1qfcas8b9pngcogj$all
 ||docs.google.com/uc?id=1mdnlxs6vy5qk-u4dxz9movem4j3a3o-8$all
-||docs.google.com/uc?id=1o6omlk34dxy3cbai8rvkvrnp5g-ovsj-$all
 ||docs.google.com/uc?id=1od6gtslxvylgyeujmrbvm9yhupmq_1lv$all
 ||docs.google.com/uc?id=1ozpasp-mr-e-ui4lshy4qy4a2pl8pxsi$all
-||docs.google.com/uc?id=1pnmkgw-rlm9mjstqdxfcq0en07_x93ue$all
 ||docs.google.com/uc?id=1q0edpjr7vgo_ytns7dgjcav6317juz9y$all
 ||docs.google.com/uc?id=1q5gqeinogsri3i-ynlgvu88ajqnn9siq$all
 ||docs.google.com/uc?id=1quyiobd7-d-vcddlhxiqbqrwxyg7ongo$all
-||docs.google.com/uc?id=1qyzpbxbnmnbp5opdk5rmeplmbga9c_q9$all
 ||docs.google.com/uc?id=1rrtyvouwizor2icbcoywdid4w9rwngxi$all
 ||docs.google.com/uc?id=1sao6yxf-a0t6wdgdr36srwlju57vigx_$all
-||docs.google.com/uc?id=1sbg8kdmxp5futgje5jcfvh-ieq28holg$all
-||docs.google.com/uc?id=1seb4h5c8z5jaf2_ulvhdv7mzqzmntp0k$all
-||docs.google.com/uc?id=1skuwjvkgsmicbr1o48gnalcksfytwtdp$all
 ||docs.google.com/uc?id=1st5mtgqyofsskuhlomfihfmz_qx-i32o$all
+||docs.google.com/uc?id=1u5q84w84g_x98ti4uflzhrgvzzfyj_qi$all
 ||docs.google.com/uc?id=1umz5zjobot9__v2jxdutyborb2az90hz$all
 ||docs.google.com/uc?id=1we-h5qtxj9czhkhzvzg0qqpxufgu_v__$all
-||docs.google.com/uc?id=1wmi0gpfe9ebcgai4w6iw6pninxo6ke-m$all
 ||docs.google.com/uc?id=1wurpipyf0s__fqtn1ov619nx7v1-tcy3$all
 ||docs.google.com/uc?id=1wwkqbfluu4qusqz26ewulr48zh9vzq-w$all
-||docs.google.com/uc?id=1xbvceq1wmfjad59zyxwtykzy3xwy9iqb$all
-||docs.google.com/uc?id=1xqcnagjbut3pdajnpsx0nonhla3nqes-$all
-||docs.google.com/uc?id=1xsj8d2ysnoluawhk3g4tadaoyp8ktmab$all
-||docs.google.com/uc?id=1xtflvdimom8odrygcmip7j4aesrjtgsm$all
 ||docs.google.com/uc?id=1yyuejm8cerrq2tctsibww4uetepcmh4i$all
 ||drive.google.com.it-barcelona.com/frm0reseen/prntscrnofamzorderid.jpg.exe$all
 ||drive.google.com/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm$all
@@ -5142,7 +5095,6 @@ zz.690tx.com
 ||jointings.org/eng/wp-content/plugins/featurific-for-wordpress/3$all
 ||justlficante.mediafire.com/file/jl01o54yy09qrzg/fac215.tgz/file$all
 ||karmakoincodes.weebly.com/uploads/3/2/8/8/3288864/karma_koin_codes.exe$all
-||kotakwarna.co.id/dg/etrac/nf4emwz/$all
 ||ksh.hu/docs/adatgyujtesek/elektra/csv_to_xml.exe$all
 ||kuaizip.com/down/affiliate/kuaizip_setup_10029.exe$all
 ||linuxforensicsbook.com.s3.amazonaws.com/linuxforensicscode.zip$all
@@ -5183,6 +5135,7 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4$all
 ||onedrive.live.com/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma$all
 ||onedrive.live.com/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48$all
+||onedrive.live.com/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq$all
 ||onedrive.live.com/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg$all
 ||onedrive.live.com/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw$all
 ||onedrive.live.com/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq$all
@@ -5220,6 +5173,7 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4$all
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0$all
+||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0$all
@@ -5296,8 +5250,6 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy$all
 ||onedrive.live.com/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw$all
 ||onedrive.live.com/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw$all
-||onedrive.live.com/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8$all
-||onedrive.live.com/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c$all
 ||onedrive.live.com/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y$all
 ||onedrive.live.com/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg$all
 ||onedrive.live.com/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns$all
@@ -5308,6 +5260,7 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4$all
 ||onedrive.live.com/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm$all
 ||onedrive.live.com/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu$all
+||onedrive.live.com/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8$all
 ||onedrive.live.com/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8$all
 ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc$all
 ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y$all
@@ -5329,6 +5282,7 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa$all
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu$all
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c$all
+||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy$all
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q$all
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm$all
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4$all
@@ -5368,7 +5322,6 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq$all
 ||onedrive.live.com/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g$all
 ||onedrive.live.com/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum$all
-||onedrive.live.com/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa$all
 ||onedrive.live.com/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi$all
 ||onedrive.live.com/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy$all
 ||onedrive.live.com/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o$all
@@ -5391,6 +5344,7 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg$all
 ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai$all
 ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc$all
+||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai$all
 ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc$all
 ||onedrive.live.com/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw$all
 ||onedrive.live.com/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8$all
@@ -5449,10 +5403,6 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w$all
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta$all
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em$all
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!210&authkey=agpl0pgvft8faaa$all
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c$all
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa$all
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c$all
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto$all
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum$all
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto$all
@@ -5556,6 +5506,7 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk$all
 ||onedrive.live.com/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw$all
 ||onedrive.live.com/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc$all
+||onedrive.live.com/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc$all
 ||onedrive.live.com/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e$all
 ||onedrive.live.com/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks$all
 ||onedrive.live.com/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks$all
@@ -5640,13 +5591,6 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy$all
 ||onedrive.live.com/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774!124&authkey=afq42wqejwvcv8o$all
 ||onedrive.live.com/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774%21124&authkey=afq42wqejwvcv8o$all
-||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na$all
-||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8$all
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o$all
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0$all
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o$all
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0$all
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw$all
 ||onedrive.live.com/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe$all
 ||onedrive.live.com/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq$all
 ||onedrive.live.com/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4$all
diff --git a/urlhaus-filter-snort2-online.rules b/urlhaus-filter-snort2-online.rules
index 5888ee92..76a2df9c 100644
--- a/urlhaus-filter-snort2-online.rules
+++ b/urlhaus-filter-snort2-online.rules
@@ -1,5 +1,5 @@
 # Title: Online Malicious URL Snort2 Ruleset
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -7,5778 +7,5722 @@
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"0-24bpautomentes.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100000001; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"0cl.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100000002; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.11.234.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000003; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.222.140.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000004; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.222.166.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000005; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.186.151.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000004; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.222.140.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000005; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.222.196.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000006; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.245.4.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000007; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000008; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000009; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000010; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000012; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000013; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000014; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000015; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000018; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000019; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000031; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000032; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000035; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000038; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000039; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000040; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000041; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000042; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000043; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000044; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000045; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000046; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000047; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100000048; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000049; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000050; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000051; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000052; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000053; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.247.221.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000054; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.247.221.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000055; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.250.159.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000056; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.252.102.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000057; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.254.250.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000058; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.60.77.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000059; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.65.166.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000060; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.82.104.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000061; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.12.184.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.2.131.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.8.77.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000064; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1008691.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100000065; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.130.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.109.246.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.16.183.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.16.98.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.229.85.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.255.36.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.105.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.106.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.145.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.76.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.30.128.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.30.38.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.64.119.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.64.161.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.75.157.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.130.115.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.141.240.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.107.113.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.124.104.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.218.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.139.89.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.141.138.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.145.13.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.146.174.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.156.221.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.159.155.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.16.145.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.207.1.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.217.215.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.4.117.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.66.78.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.79.112.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.145.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.98.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.240.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.240.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.241.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.241.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.184.75.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000122; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.33.52.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000123; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.61.86.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000124; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.1.112.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000125; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.172.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000126; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.193.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.105.33.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000128; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.113.177.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000129; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.165.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000130; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.193.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000131; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.249.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000132; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.155.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000133; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000134; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.144.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000135; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.250.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.197.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.31.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.181.136.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.189.8.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.194.242.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.219.185.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.220.119.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.221.96.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.201.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.250.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.55.199.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.104.151.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.124.90.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.233.196.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.235.7.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.248.58.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.86.85.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000155; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.127.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.57.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.99.37.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.10.58.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.12.123.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.14.58.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.187.229.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.190.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.195.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.241.119.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.241.23.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.247.151.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.247.153.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.124.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.175.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.251.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.251.10.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.213.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000173; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.51.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.255.101.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.255.167.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.145.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.208.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000178; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.221.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000179; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.223.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000180; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.225.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000181; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.233.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000182; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.235.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000183; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.4.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110fss.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100000185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.88.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.119.245.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.125.67.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.162.224.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.163.50.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.165.21.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.165.28.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.84.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.86.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.172.164.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.176.182.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.179.153.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.179.243.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.182.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.177.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.230.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.27.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.48.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000205; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.61.52.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.105.117.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.100.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.108.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.31.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.122.62.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.123.200.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.132.134.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.132.147.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.159.108.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.124.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.219.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.233.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.210.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.96.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.187.91.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.214.127.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.187.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.236.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.52.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.82.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.118.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.176.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.195.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.202.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.205.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.67.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.92.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.180.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.178.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.188.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.199.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.230.251.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.121.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.134.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.16.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.194.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.216.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.218.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.149.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.188.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.126.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.171.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.228.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.141.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.144.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.172.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.197.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.230.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.75.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.143.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.17.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.190.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.194.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.227.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.39.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.73.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.184.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.216.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.241.187.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.106.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.18.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.2.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.243.115.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.12.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.5.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.8.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.162.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.180.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.100.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.14.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.161.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.191.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.214.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.240.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.81.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.82.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.179.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.197.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.44.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.109.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.118.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.165.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.206.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.26.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.41.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.79.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.102.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.57.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.17.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.218.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.23.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.136.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.199.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.221.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.239.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.245.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.46.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.208.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.32.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.127.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.38.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.6.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.8.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.121.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.123.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.127.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.82.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.85.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.87.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.87.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.88.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.100.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.126.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.35.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.38.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.38.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.176.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.211.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.82.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.224.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.65.53.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.153.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.78.45.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.118.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.127.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.215.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.81.161.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.81.199.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.131.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.146.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.18.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100000460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.224.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.227.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.228.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.83.118.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.83.230.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.86.133.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.9.140.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.91.219.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.93.29.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.95.80.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.0.74.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.11.95.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.110.204.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.110.243.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.150.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.176.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.44.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.89.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.118.13.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.118.133.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.118.250.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.118.6.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.238.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.59.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.58.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.172.250.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.189.243.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.194.133.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.194.135.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.163.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.166.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.168.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.201.219.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.225.171.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.226.42.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.128.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.169.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.194.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.35.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.211.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.93.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.232.211.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.234.224.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.235.116.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.253.144.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.254.169.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.128.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.133.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.144.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.154.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.191.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.61.204.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.86.204.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.87.203.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.87.227.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.100.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.104.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.111.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.209.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.232.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.38.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000019; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000020; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000032; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000035; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000038; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000039; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000040; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000041; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000042; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000043; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000044; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000045; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000046; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000047; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000048; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000049; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100000050; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000051; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000052; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000053; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000054; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000055; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.247.221.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000056; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.247.221.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000057; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.250.159.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000058; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.252.102.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000059; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.254.250.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000060; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.60.77.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000061; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.65.166.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000062; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.82.104.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.12.184.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.2.131.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000065; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.8.77.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000066; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1008691.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100000067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.130.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.16.183.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.16.98.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.229.85.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.255.36.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.105.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.106.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.145.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.76.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.30.128.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.30.38.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.64.119.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.64.161.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.66.81.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.75.157.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.130.115.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.141.240.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.107.113.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.124.104.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.218.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.126.35.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.139.89.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.141.138.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.145.13.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.146.174.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.153.92.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.156.221.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.159.155.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.16.145.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.207.1.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.214.191.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.217.215.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.49.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.4.117.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.66.78.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.79.112.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.98.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.240.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.240.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.241.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.241.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000123; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000124; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000125; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000126; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000127; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000129; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000130; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.184.75.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000131; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.33.52.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000132; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.61.86.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000133; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.1.112.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000134; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.172.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000135; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.193.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000136; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.105.33.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.113.177.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.165.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.193.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.249.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.155.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.144.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.250.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.197.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.31.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.181.136.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.189.8.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.194.242.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.219.185.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.220.119.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.221.96.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.201.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.250.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.55.199.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000156; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.104.151.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.124.90.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.233.196.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.235.7.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.86.85.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.127.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.57.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.99.37.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.10.58.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.12.123.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.14.58.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.187.229.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.190.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.195.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.241.119.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.241.23.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000174; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.247.151.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.247.153.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.124.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.175.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.251.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000179; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.251.10.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000180; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.213.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000181; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.51.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000182; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.255.101.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000183; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.255.167.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000184; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.145.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.209.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.221.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.235.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.4.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110fss.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100000190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.111.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.88.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.119.245.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.125.67.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.162.224.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.163.50.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.165.21.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.165.28.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.84.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.86.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.172.164.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.176.182.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.179.153.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.179.243.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.182.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.177.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000206; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.230.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.27.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.48.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.61.52.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.108.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.31.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.122.62.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.122.63.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.132.134.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.132.147.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.159.108.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.167.165.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.124.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.233.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.210.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.96.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.187.91.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.214.127.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.187.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.236.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.52.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.82.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.118.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.195.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.202.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.67.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.92.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.180.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.178.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.188.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.199.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.230.251.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.134.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.16.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.194.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.216.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.218.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.149.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.188.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.126.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.171.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.228.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.141.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.144.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.172.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.197.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.230.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.75.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.143.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.17.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.190.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.194.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.227.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.39.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.73.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.184.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.216.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.241.187.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.106.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.18.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.2.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.97.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.243.115.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.12.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.178.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.5.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.8.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.162.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.180.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.100.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.16.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.161.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.191.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.214.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.240.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.25.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.81.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.82.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.179.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.197.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.44.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.109.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.118.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.165.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.206.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.26.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.41.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.79.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.102.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.57.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.17.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.218.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.23.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.136.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.199.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.221.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.239.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.245.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.46.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.128.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.188.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.208.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.32.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.127.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.38.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.6.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.8.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.121.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.123.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.127.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.82.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.85.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.87.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.87.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.88.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.100.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.126.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.35.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.38.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.38.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.176.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.211.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.82.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.87.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.224.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.65.53.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.153.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.226.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.231.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.78.45.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.118.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.127.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.215.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.81.161.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.81.199.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.131.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.146.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.18.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100000472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.224.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.227.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.228.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.83.118.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.83.230.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.86.133.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.9.140.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.91.219.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.93.29.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.0.74.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.11.95.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.110.204.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.118.13.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.118.159.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.119.37.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.238.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.59.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.58.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.172.250.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.189.243.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.193.29.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.194.133.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.194.135.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.163.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.166.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.168.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.201.219.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.226.42.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.128.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.169.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.194.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.35.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.211.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.93.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.232.156.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.234.224.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.235.116.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.253.144.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.254.169.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.128.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.154.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.191.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.61.204.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.86.204.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.87.203.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.232.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.38.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.39.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.90.27.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000521; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.92.93.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.199.204.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.199.253.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.224.203.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.226.100.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.227.156.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.228.205.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.228.242.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.229.165.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.229.52.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.234.189.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.235.115.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.30.54.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.161.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.172.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.165.216.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.171.239.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.193.83.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100000539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.201.38.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.201.98.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.208.97.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.209.234.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.223.159.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.229.250.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.23.88.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.42.47.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.163.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.179.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.188.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.200.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.49.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.124.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.158.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.36.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.43.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.80.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.96.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100000558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.15.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.199.253.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.224.203.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.226.100.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.227.156.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.228.205.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.228.242.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.229.165.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.229.52.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.234.189.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.235.115.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.161.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.172.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.165.216.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.171.239.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.193.83.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100000537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.201.38.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.201.98.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.205.197.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.208.97.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.209.234.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.223.159.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.229.250.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.42.47.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.163.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.179.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.188.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.201.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.41.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.124.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.158.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.24.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.36.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.79.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.1.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.168.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.171.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.175.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000559; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.19.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000560; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.20.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000561; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.206.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.226.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.228.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.238.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.239.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.240.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.211.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.238.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.239.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.242.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.247.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000567; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.61.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.91.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.96.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.104.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.106.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.79.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.91.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.96.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.7.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000572; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.17.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100000573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.53.200.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.53.224.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.53.234.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.53.238.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.123.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.70.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.105.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.144.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.145.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.157.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.158.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.158.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.161.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.179.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.206.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.206.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.26.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.42.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.111.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.114.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.132.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.133.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.134.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.137.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.139.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.143.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.145.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.148.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.151.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.151.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.154.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.175.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.189.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.31.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.98.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.99.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.132.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.134.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.161.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.90.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.198.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.209.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100000615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.212.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.214.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.228.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.235.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.253.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.57.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.82.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.102.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.118.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.118.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.139.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.152.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.155.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.26.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.139.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.141.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.180.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.189.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.21.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.37.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.53.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.73.3.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.75.217.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.78.133.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.92.174.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.96.61.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.97.136.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.124.219.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.149.243.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.2.100.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.206.164.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.207.71.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.211.100.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.212.132.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.212.142.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.30.4.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.30.95.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.72.51.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.73.222.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.75.199.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.75.212.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.76.114.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.11.234.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.12.48.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.156.69.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.192.224.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.192.225.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.192.225.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.192.227.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.160.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.163.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.166.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.166.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.210.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.236.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.243.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.200.76.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.200.76.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.67.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.67.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.67.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.70.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.71.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.207.5.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.208.134.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.208.134.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.11.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.14.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.14.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.14.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.15.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.43.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.44.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.46.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.47.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.8.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.215.248.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.215.251.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.160.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.162.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.164.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.164.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.169.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.172.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.174.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.241.64.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.241.67.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.242.208.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.242.208.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.247.200.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.247.202.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.247.203.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.247.204.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.247.204.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.60.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.26.235.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.27.10.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.60.204.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.113.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.195.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.252.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.53.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.86.105.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.91.240.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.93.115.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.93.79.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.172.80.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.104.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.157.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.7.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.211.38.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.32.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.5.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.72.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.12.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.128.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.208.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.209.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.214.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.88.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.221.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.63.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.65.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.250.51.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.42.125.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.43.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.68.245.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.70.83.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.120.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.200.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.240.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.240.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.50.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.70.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.125.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.161.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.164.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.218.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.50.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.58.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.83.79.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.91.24.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.179.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.183.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.239.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.100.40.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.108.251.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.109.34.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.112.22.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.112.27.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.115.247.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.119.52.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000771; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.123.125.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000772; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.123.216.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000773; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.123.218.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000774; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.123.221.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000775; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.123.237.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000776; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.14.143.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000777; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.147.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000778; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.162.109.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000779; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.144.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000780; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.207.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000781; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.93.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000782; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.18.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000783; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.31.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000784; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.107.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000785; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.163.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000786; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000787; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.241.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000788; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.27.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000789; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.68.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000790; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.170.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000791; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.19.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000792; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.97.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000793; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.1.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000794; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.2.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000795; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.26.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000796; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.63.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000797; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.201.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000798; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.248.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000799; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.249.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000800; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.120.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000801; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.157.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000802; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.16.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000803; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.170.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000804; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.190.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000805; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000806; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.75.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000807; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.18.38.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000808; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.101.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000809; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.106.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000810; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000811; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000812; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.11.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000813; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.231.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000814; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.33.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000815; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.9.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000816; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.94.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000817; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.119.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000818; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.124.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000819; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.115.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000820; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.9.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000821; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.14.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000822; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.172.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000823; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.237.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000824; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.43.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000825; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.186.140.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000826; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.186.22.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000827; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.195.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000828; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.220.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000829; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.137.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000830; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.227.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000831; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.190.211.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000832; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.190.234.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000833; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.190.240.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000834; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.150.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000835; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.187.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000836; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.215.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000837; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.240.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000838; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.253.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000839; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.204.30.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000840; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.250.129.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000841; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.105.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000842; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.12.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000843; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.14.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000844; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.131.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000845; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000846; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000847; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000848; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.148.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000849; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.155.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000850; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.172.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000851; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.195.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000852; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.96.37.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000853; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.96.70.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000854; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.188.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000855; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.190.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100000856; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.232.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000857; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.132.113.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000858; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.15.69.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000859; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000860; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000861; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000862; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000863; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.207.39.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000864; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.153.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000865; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.212.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000866; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.142.222.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000867; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.150.213.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000868; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.151.248.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000869; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000870; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000871; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000872; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000873; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000874; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000875; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000876; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000877; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000878; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000879; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000880; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100000881; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000882; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000883; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000884; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000885; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000886; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000887; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000888; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000889; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000890; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000891; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000892; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000893; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000894; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.93.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000895; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.121.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000896; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000897; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000898; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000899; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000900; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000901; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000902; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.127.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000903; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.99.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000904; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.210.89.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000905; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.43.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000906; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.5.15.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000907; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.66.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000908; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.93.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000909; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.57.98.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000910; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.141.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000911; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.8.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000912; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.69.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000913; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.7.75.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000914; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.7.90.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000915; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.83.189.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000916; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.165.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000917; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.169.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000918; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.170.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000919; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.173.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000920; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.185.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000921; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.236.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000922; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.238.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000923; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.238.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000924; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.9.32.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000925; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.114.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000926; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.96.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000927; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.121.44.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000928; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.123.53.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000929; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.127.155.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000930; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.136.249.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000931; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.141.11.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000932; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.15.142.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000933; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.151.78.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000934; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.159.22.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000935; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.17.103.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000936; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.170.234.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000937; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.185.31.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000938; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.190.36.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000939; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.225.11.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000940; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.226.82.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000941; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.23.57.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000942; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.230.171.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000943; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.231.103.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000944; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.233.18.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000945; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.238.175.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000946; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.239.15.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000947; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.24.116.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000948; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.25.101.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000949; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.254.43.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000950; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.254.76.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000951; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.101.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000952; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.102.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000953; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.107.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000954; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.97.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000955; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.98.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000956; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.88.99.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000957; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.100.150.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000958; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.137.52.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000959; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.160.147.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000960; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.176.44.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000961; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.188.86.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000962; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.190.19.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000963; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.192.190.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000964; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.66.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000965; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.72.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000966; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.79.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000967; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.37.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000968; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.41.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000969; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.252.199.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000970; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.252.250.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000971; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.183.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000972; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.29.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000973; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.33.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000974; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.0.240.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000975; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.131.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000976; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.41.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000977; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.83.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000978; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.11.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000979; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.4.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000980; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.7.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000981; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.71.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100000982; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000983; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000984; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.170.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000985; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000986; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.19.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000987; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.200.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000988; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.238.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000989; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.12.7.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000990; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.128.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000991; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.133.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000992; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.177.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000993; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.84.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000994; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.88.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000995; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.13.44.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000996; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.202.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000997; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.208.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000998; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.23.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000999; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.37.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001000; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.61.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001001; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.77.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001002; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.131.186.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001003; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.132.219.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001004; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.125.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001005; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.144.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001006; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.184.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001007; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.98.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001008; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.14.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001009; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.50.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001010; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.157.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.39.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001012; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.71.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001013; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.172.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001014; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.86.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001015; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.93.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.144.211.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.152.42.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001018; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.152.43.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001019; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.153.80.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.236.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.94.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.155.118.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.156.136.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.137.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.31.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.101.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.194.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.149.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.53.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001031; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.235.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001032; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.35.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001033; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.52.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001034; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.60.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001035; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.112.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001036; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.184.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001037; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.98.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001038; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.212.29.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001039; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.213.225.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001040; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.130.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001041; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.152.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100001042; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.100.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001043; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.116.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001044; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.184.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001045; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.246.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001046; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.235.226.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001047; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.103.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001048; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.181.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001049; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.79.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001050; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.148.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001051; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.184.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001052; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.27.44.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001053; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.28.217.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001054; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.11.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001055; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.166.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001056; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.176.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001057; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.177.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001058; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.193.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001059; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.209.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001060; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.241.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001061; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.76.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.83.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.85.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001064; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.123.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001065; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.143.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.146.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.190.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.5.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.8.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.56.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.194.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.245.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.105.105.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.162.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.221.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.76.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.167.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.104.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.130.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.131.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.136.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.151.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.26.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.41.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.54.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.72.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.132.110.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.135.34.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.135.34.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.136.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.236.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.160.126.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.154.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.65.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.65.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.72.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.77.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.89.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.90.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.165.123.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.187.111.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.199.56.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.226.24.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.230.174.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.234.6.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.254.254.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.5.92.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.6.0.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.67.89.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.7.254.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.80.46.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.91.237.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.93.94.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.95.17.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.105.219.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.126.69.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.128.28.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.142.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.168.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001122; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.191.113.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001123; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.209.71.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001124; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.36.148.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001125; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.1.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001126; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.113.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.160.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001128; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.17.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001129; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.237.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001130; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.25.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001131; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.65.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001132; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.73.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001133; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.74.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001134; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.75.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001135; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.208.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.244.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.6.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.7.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.74.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.96.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.96.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.97.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.107.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.124.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.98.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.98.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.112.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.112.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.133.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.167.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.2.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.21.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.215.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.26.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001155; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.33.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.37.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.53.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.53.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.60.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.73.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.92.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.10.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.107.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.175.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.198.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.212.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.243.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.31.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.8.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.153.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.55.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.138.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001173; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.166.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.205.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.206.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.217.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.241.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001178; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.241.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001179; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.245.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001180; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.250.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001181; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.252.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001182; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.254.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001183; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.254.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.28.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.45.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.57.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.91.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.79.192.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"128.116.133.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"130.255.159.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"134.195.139.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"134.255.93.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"135.181.192.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"138.99.204.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.159.226.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.173.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.174.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.216.102.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.227.46.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.102.17.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.102.97.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.136.80.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.109.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.109.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001205; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.155.220.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.160.24.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.169.164.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.181.64.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.189.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.205.201.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.248.187.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.37.222.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.45.127.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.25.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.98.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.55.29.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.98.184.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"140.237.30.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"140.237.5.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.11.216.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.177.56.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"146.71.79.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"148.69.108.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.20.176.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.124.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.36.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.85.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"150.116.207.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.177.163.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.33.230.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.73.124.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.225.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.234.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.40.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.43.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.44.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.135.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.23.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.29.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.35.111.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.35.27.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.36.126.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.101.165.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.174.213.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.51.125.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.224.74.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.165.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.205.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.194.28.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.209.98.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.125.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.157.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.18.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.193.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.195.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.200.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.202.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.202.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.202.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.203.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.204.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.204.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.204.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.207.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.243.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.255.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.204.208.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.204.211.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.204.211.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.53.206.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"165.90.16.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"168.90.204.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"170.81.238.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.113.36.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.118.18.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.118.210.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.217.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.218.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.219.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.248.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.255.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.120.125.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.121.6.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.123.134.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.242.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.30.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.30.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.64.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.65.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.75.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.126.70.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.223.72.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.114.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.179.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.160.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.161.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.162.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.174.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.36.249.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.145.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.148.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.217.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.219.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.223.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.223.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.105.36.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.114.244.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.81.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.167.85.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.169.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.19.58.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.233.85.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.235.209.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.25.113.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.95.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.97.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.119.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.92.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.106.33.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.48.181.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.61.3.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.73.246.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.81.78.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.83.73.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.10.147.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.11.193.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.115.241.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.117.66.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.145.200.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.146.17.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.150.168.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.153.144.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.162.137.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.162.195.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.162.69.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.165.90.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.168.139.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.17.90.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.174.93.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.199.33.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.201.104.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.208.230.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.212.6.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.42.46.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.8.113.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.9.24.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.174.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.12.117.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.4.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.9.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.124.7.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.40.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.84.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.11.92.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.131.226.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.229.64.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.44.61.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.86.235.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.124.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.125.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.25.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.45.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.57.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.150.174.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.151.143.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.165.122.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.0.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.0.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.0.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100001414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001521; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001559; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001560; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001561; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001567; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001572; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001771; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001772; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001773; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001774; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001775; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001776; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001777; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001778; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001779; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001780; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001781; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001782; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001783; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001784; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001785; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001786; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001787; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001788; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001789; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001790; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001791; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001792; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001793; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001794; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001795; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001796; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001797; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001798; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001799; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001800; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001801; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001802; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001803; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001804; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001805; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001806; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001807; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001808; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001809; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001810; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001811; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001812; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001813; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001814; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001815; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001816; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001817; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001818; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001819; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001820; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001821; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001822; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001823; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001824; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001825; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001826; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001827; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001828; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001829; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001830; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001831; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001832; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001833; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001834; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001835; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001836; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001837; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001838; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001839; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001840; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001841; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001842; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001843; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001844; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001845; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001846; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001847; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001848; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001849; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001850; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001851; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001852; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001853; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001854; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001855; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001856; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001857; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001858; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001859; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001860; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001861; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001862; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001863; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001864; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001865; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001866; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001867; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001868; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001869; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001870; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001871; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001872; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001873; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001874; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001875; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001876; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001877; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001878; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001879; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001880; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001881; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001882; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001883; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001884; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001885; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001886; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001887; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001888; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001889; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001890; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001891; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001892; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001893; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001894; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001895; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001896; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001897; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001898; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001899; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001900; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001901; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001902; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001903; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001904; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001905; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001906; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001907; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001908; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001909; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001910; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001911; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001912; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001913; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001914; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001915; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001916; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001917; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001918; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001919; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001920; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001921; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001922; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001923; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001924; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001925; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001926; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001927; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001928; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001929; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001930; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001931; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001932; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001933; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001934; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001935; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001936; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001937; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001938; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001939; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001940; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001941; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001942; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001943; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001944; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001945; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001946; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001947; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001948; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001949; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001950; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001951; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001952; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001953; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001954; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001955; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001956; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001957; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001958; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001959; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001960; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001961; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001962; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001963; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001964; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001965; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001966; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001967; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001968; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001969; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001970; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001971; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001972; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001973; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001974; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001975; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001976; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001977; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001978; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001979; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001980; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001981; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001982; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001983; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001984; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001985; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001986; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001987; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001988; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001989; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001990; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001991; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001992; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001993; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001994; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001995; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001996; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001997; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001998; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001999; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002000; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002001; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002002; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002003; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002004; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100002005; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002006; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002007; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002008; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100002009; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002010; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100002011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002012; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002013; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002014; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002015; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002018; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002019; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100002024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.73.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.73.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.73.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002031; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002032; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002033; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002034; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002035; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002036; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002037; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002038; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002039; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002040; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002041; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002042; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002043; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002044; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002045; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002046; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002047; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002048; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002049; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100002050; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002051; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002052; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002053; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002054; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002055; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100002056; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002057; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002058; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002059; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002060; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002061; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002064; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002065; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100002068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.82.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.82.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100002079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100002086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100002087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100002092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100002093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100002110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100002111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100002112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002122; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002123; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002124; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002125; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100002126; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002128; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002129; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002130; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002131; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002132; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002133; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002134; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002135; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100002142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002155; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100002164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100002165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002173; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.19.183.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.205.101.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002178; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.21.164.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002179; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.217.8.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002180; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.22.117.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002181; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.222.252.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002182; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.34.183.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002183; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.48.235.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100002184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.92.246.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.95.115.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.95.136.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.159.58.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.4.187.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.43.157.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.60.84.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.99.210.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.109.36.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.111.101.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.114.111.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.116.203.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.120.149.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.122.13.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.125.44.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.157.66.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.175.236.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.175.93.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.105.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.110.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.165.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002205; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.214.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.34.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.96.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.104.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.242.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.218.5.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.248.80.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.111.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.53.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.94.170.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.138.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.143.60.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.193.107.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100002223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.210.45.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.215.47.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.224.242.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.236.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.59.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.43.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.52.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.111.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.24.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.49.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100002233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.64.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.79.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.83.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.92.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.93.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.101.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.103.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.104.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.108.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.108.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.118.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.60.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.61.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.80.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.94.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100002248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.99.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.15.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.25.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.26.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.29.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.39.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.118.146.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.100.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.109.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.118.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.14.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.166.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.176.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.211.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.214.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.221.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.225.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.255.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.7.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.33.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100002271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.37.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.43.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100002273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.11.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100002274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.129.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.130.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.133.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.134.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.158.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.205.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.205.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.207.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.40.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.50.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100002284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.66.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.9.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100002286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.94.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.181.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.202.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.123.203.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.123.211.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100002291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.123.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.177.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.19.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.88.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.113.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.120.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.126.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.127.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.181.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.52.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.67.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.80.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100002303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.83.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.88.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.103.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.104.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.110.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100002308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.152.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.155.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.209.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.221.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.160.98.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.172.36.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.233.0.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.235.252.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.53.197.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.58.219.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.225.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.109.169.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.11.238.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.136.252.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.150.138.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.150.244.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.16.208.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.185.112.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.187.163.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100002328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.151.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.180.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.188.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.228.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.105.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.125.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.127.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100002335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.26.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.99.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.92.195.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.95.147.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.97.22.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.164.185.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.175.115.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.74.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.106.209.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.107.3.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.172.110.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.181.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.219.133.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.221.3.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.228.141.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.239.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.245.96.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.26.113.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.34.16.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.43.19.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100002359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.45.103.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.55.1.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.68.230.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.81.157.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100002364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.90.166.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.151.144.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.219.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.253.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.183.131.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.225.120.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.232.44.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100002379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.28.60.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.33.112.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.33.112.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.33.112.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.33.113.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.33.113.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.4.125.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.73.188.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.12.10.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.212.200.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.233.208.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.33.71.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.21.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.231.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.113.102.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.113.81.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.13.179.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.138.200.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.152.41.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.178.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.199.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100002400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.36.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.45.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.167.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.242.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.81.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.83.202.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"189.222.157.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"19.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.0.42.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.109.178.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.110.161.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.111.151.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.119.207.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.12.99.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.121.194.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.15.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.20.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.141.117.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.147.16.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.159.240.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.187.55.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.210.214.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.177.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.226.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.49.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.214.24.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.216.140.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.35.225.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.65.206.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.92.4.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.41.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"191.255.248.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.175.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.241.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.185.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.209.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.220.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.228.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.3.152.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.3.73.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.99.240.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.142.146.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.228.135.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.91.131.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.147.142.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.15.36.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.152.35.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.38.20.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.139.126.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.228.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.24.94.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.202.26.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.218.48.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.166.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.159.2.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.50.27.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.133.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.207.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.251.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.251.72.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.201.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100002470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.202.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"199.188.101.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1am.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.229.89.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.249.161.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.111.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.125.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.83.152.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"20.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.105.167.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.111.189.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.194.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.2.161.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.30.132.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.142.147.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100002486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.163.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.248.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.187.102.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.200.254.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100002490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.203.221.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.215.84.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.218.97.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.107.233.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.164.153.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.166.217.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.29.95.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.4.124.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.176.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.191.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.74.236.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.109.201.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.130.69.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.170.115.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.189.156.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.204.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.229.21.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.236.190.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.238.86.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.70.166.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.77.80.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.119.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.171.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.82.36.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.82.49.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002521; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.93.6.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"204.195.116.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.185.115.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.185.123.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.248.137.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.47.41.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.5.32.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.163.58.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.39.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.145.60.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.124.149.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.152.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.153.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.234.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.237.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.245.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.68.242.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.96.116.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.116.220.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.172.11.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.179.43.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.132.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.75.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.204.215.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.66.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100002548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.93.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.216.66.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.114.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.120.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.246.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.238.83.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.113.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100002555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.5.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.36.174.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.51.174.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.122.86.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002559; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.143.227.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002560; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.156.215.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002561; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.46.197.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.56.197.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.119.74.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.123.206.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.135.178.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.14.173.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100002567; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.182.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.190.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002572; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100002576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100002580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.117.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.117.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100002593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.117.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.119.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.119.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100002600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100002601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100002604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.189.178.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.226.140.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100002611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.240.218.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.249.156.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.27.8.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.80.44.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.87.87.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.254.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.127.185.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.170.240.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.183.54.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.36.12.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.11.75.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.127.133.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100002625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.8.228.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100002626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.12.162.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.12.181.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.2.40.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.215.243.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.238.246.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.28.160.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.207.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.227.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.68.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.81.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.48.135.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.56.93.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.57.53.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.59.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.72.198.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.79.103.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.103.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.114.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.114.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.115.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.126.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.147.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.148.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.173.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.102.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.113.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.14.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.170.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.24.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.243.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.26.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.26.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.29.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100002661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.31.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.31.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.42.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100002664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.98.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.131.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.167.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.17.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.23.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.60.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100002670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.88.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.9.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.11.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.146.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.147.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.150.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.178.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.178.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.183.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.223.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.223.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.42.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.67.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.241.6.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100002685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.163.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.171.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.251.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.5.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.69.71.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.80.217.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.85.145.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"21robo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.118.168.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.126.237.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.133.30.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.200.22.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.71.239.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.1.162.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.124.78.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.11.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.122.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.165.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.47.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.58.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.108.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.125.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.127.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100002709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.147.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.21.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.212.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.234.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.236.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100002714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.237.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.250.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.253.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.54.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.55.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.157.191.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.136.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100002722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100002724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.196.12.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.198.167.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.2.190.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.130.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100002728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.224.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.116.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.172.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.184.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.237.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.252.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.8.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.1.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.179.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.137.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.142.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100002739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.112.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.32.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.34.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100002742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.43.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.68.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.108.17.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.119.65.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100002746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.132.125.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.102.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.103.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.105.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.219.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.26.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.67.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.136.49.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.136.53.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.101.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.101.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.121.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.137.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.138.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.148.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.160.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.172.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.198.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100002764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.239.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100002765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.49.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.5.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.57.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.72.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100002769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.85.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.96.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002771; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.143.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002772; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.151.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002773; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.189.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002774; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.201.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002775; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.23.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002776; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.96.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002777; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.139.16.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002778; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.129.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100002779; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.162.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002780; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.163.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002781; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.17.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002782; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.209.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002783; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.254.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002784; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.39.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002785; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.120.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002786; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.13.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002787; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.44.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002788; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.73.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002789; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.9.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100002790; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.162.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002791; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.192.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002792; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.209.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002793; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.209.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002794; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.245.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002795; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.179.215.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002796; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.185.116.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002797; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.186.20.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002798; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.187.184.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100002799; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.187.9.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002800; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.211.72.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002801; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.214.54.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002802; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.218.220.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002803; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.236.85.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002804; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.238.230.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002805; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.239.83.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002806; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.248.64.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002807; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.83.150.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100002808; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.92.9.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100002809; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.99.171.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002810; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.166.117.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002811; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.167.118.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002812; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.225.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002813; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.234.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002814; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.5.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002815; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.73.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002816; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.125.186.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002817; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.126.120.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002818; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.228.143.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002819; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.24.213.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002820; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.149.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002821; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.21.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002822; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.95.89.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002823; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.103.74.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002824; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.11.141.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002825; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.119.158.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002826; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.137.147.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002827; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.152.235.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002828; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.158.25.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002829; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.176.206.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002830; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.184.1.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002831; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.192.191.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002832; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.225.114.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002833; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.227.190.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100002834; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.35.245.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002835; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.181.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002836; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002837; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.42.229.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100002838; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.45.4.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002839; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.51.91.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002840; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002841; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002842; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002843; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002844; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002845; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.106.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002846; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.152.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002847; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.116.84.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002848; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.12.245.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002849; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.141.218.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002850; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.29.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002851; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.40.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002852; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.153.207.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002853; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.184.244.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002854; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.184.54.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002855; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.187.248.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002856; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.187.250.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002857; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.196.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002858; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.217.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002859; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.149.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002860; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.158.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002861; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.192.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002862; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.210.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002863; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.17.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002864; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.22.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002865; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.23.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002866; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.24.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002867; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.28.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002868; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.148.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002869; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.232.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002870; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.3.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002871; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.34.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002872; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.110.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100002873; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.140.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002874; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.2.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002875; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.23.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002876; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.32.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100002877; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.201.183.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002878; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.182.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002879; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.66.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002880; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.102.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002881; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.126.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002882; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.154.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002883; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.165.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002884; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.175.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002885; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.185.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002886; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.185.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002887; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.213.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002888; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002889; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.255.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002890; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.28.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002891; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.4.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002892; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.54.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002893; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.68.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002894; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.87.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002895; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.94.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002896; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.204.253.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002897; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.205.178.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002898; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.136.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100002899; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.148.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002900; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.154.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002901; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.26.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002902; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.80.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002903; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.81.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002904; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.83.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002905; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.97.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002906; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.151.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100002907; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.155.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002908; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.170.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002909; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.54.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002910; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.144.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002911; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.152.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002912; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.160.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100002913; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.164.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002914; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.166.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002915; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.201.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002916; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.214.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002917; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.247.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002918; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.25.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100002919; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.34.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002920; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.46.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002921; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.92.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002922; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.160.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002923; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.231.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002924; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.60.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002925; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.107.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002926; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.127.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002927; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.172.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002928; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.234.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002929; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.236.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002930; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.63.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002931; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.211.251.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002932; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.104.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002933; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.109.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002934; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.109.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002935; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.145.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002936; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.167.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002937; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.175.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002938; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.220.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002939; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.255.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002940; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.255.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002941; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.84.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002942; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.214.37.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002943; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.139.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002944; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.190.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002945; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.212.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002946; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.212.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002947; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.253.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002948; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002949; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.38.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002950; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.38.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002951; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.71.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002952; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.98.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002953; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.131.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002954; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.144.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002955; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.193.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002956; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.197.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002957; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.223.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002958; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.225.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002959; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.227.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002960; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.234.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002961; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002962; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.58.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002963; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.95.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002964; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.120.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002965; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.133.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100002966; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.191.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002967; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.76.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002968; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002969; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.219.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002970; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.240.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002971; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.248.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002972; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.119.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002973; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.132.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002974; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.151.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002975; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.160.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002976; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.172.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002977; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.173.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002978; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.176.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100002979; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.184.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002980; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.192.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002981; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.83.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002982; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.40.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002983; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.80.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002984; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.85.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100002985; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.221.239.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002986; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.241.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002987; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.249.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002988; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.42.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002989; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.50.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002990; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.223.242.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002991; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.24.28.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002992; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.107.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002993; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.129.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100002994; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.154.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002995; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.212.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100002996; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.58.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002997; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002998; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.9.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100002999; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.44.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003000; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.44.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003001; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.46.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100003002; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.46.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003003; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.23.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100003004; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.34.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003005; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.46.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003006; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.6.195.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003007; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.6.240.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003008; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.6.242.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003009; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.0.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003010; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.11.51.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.13.23.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003012; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.154.234.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003013; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.163.191.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003014; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.179.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003015; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.184.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.191.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.194.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003018; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.216.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100003019; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.219.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100003020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.24.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.30.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.60.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.63.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.65.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.94.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.179.201.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.195.84.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100003029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100003030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.28.7.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003031; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.30.119.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003032; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32.208.157.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100003033; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32.218.180.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100003034; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"35.184.169.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003035; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.108.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003036; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.250.203.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003037; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.157.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100003038; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.18.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003039; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.19.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003040; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.51.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003041; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.255.90.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100003042; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.128.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003043; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.160.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100003044; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.34.150.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003045; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.36.243.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003046; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.105.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003047; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.111.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003048; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.133.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003049; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.139.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003050; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.89.18.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003051; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.96.187.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003052; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360.lcy2zzx.pw"; content:"Host"; http_header; classtype:trojan-activity; sid:100003053; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360down7.miiyun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003054; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.222.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003055; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.233.60.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100003056; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.179.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003057; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003058; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.44.238.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003059; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.49.229.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003060; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.49.230.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100003061; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.52.117.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100003062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.14.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"38.77.14.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003064; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.245.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003065; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.98.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.114.137.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.117.31.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.162.104.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.64.28.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.196.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.59.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100003072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.115.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.129.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.125.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.146.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.148.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.124.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100003080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.171.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.249.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.60.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.167.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.5.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100003085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.67.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.10.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.163.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.203.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100003089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.104.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100003090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.184.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100003091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.31.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.68.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.194.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.33.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.79.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.97.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.113.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.114.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100003099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.136.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.14.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.150.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.197.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.209.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100003104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.94.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100003105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.95.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.146.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.166.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.218.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.62.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.91.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.93.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.127.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.18.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100003114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.191.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.205.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.36.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.251.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100003119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.27.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100003120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.29.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.82.86.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100003122; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.83.94.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003123; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.115.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100003124; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.157.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003125; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.34.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100003126; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.95.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003128; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003129; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.129.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003130; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.13.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100003131; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.170.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100003132; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.184.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003133; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.211.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100003134; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.216.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003135; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.234.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100003136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.248.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100003137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.60.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.66.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100003139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.73.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100003140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.78.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100003141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.63.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.90.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.93.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.141.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.155.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.233.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.41.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100003148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.67.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100003149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.72.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100003150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.157.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100003153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.63.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.90.86.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100003155; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"40.88.2.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.139.209.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.165.130.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.193.192.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100003159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.219.185.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.230.31.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.72.203.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.176.112.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.177.164.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.179.162.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.179.163.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100003172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.202.101.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100003173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.172.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.53.200.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.53.224.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.53.234.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.53.58.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.113.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.123.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.158.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.127.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100000582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.144.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.145.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.157.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.158.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.158.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.161.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.179.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.198.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.206.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.206.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.26.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.42.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.52.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.111.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.114.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.131.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.133.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.134.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.135.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100000601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.137.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.139.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.142.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.145.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.148.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.150.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.151.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.151.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.154.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.155.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.189.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.31.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.31.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.98.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.99.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.132.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.134.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.86.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.90.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.91.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.198.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.212.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.214.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.228.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.253.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.57.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.82.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.103.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.112.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.118.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.118.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.158.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.155.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.171.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.26.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.131.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.139.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.141.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.180.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.189.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.21.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.53.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.73.3.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.75.217.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.78.133.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.92.174.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.97.139.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.124.219.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.149.243.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.206.164.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.207.71.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.211.100.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.212.132.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.212.142.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.30.4.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.30.95.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.72.28.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.73.52.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.74.101.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.74.17.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.75.193.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.75.198.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.75.212.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.76.114.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.9.43.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.11.234.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.12.48.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.156.69.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.148.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.160.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.164.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.167.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.196.48.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.196.48.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.196.50.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.196.50.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.196.50.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.210.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.236.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.243.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.200.76.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.200.76.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.67.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.208.132.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.208.132.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.44.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.161.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.164.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.164.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.173.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.175.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.241.64.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.248.62.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.26.235.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.27.10.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.60.204.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.113.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.195.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.252.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.53.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.86.105.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.91.240.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.93.115.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.93.79.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.114.84.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.172.176.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.104.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.157.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.7.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.211.38.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.32.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.5.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.72.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.12.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.128.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.208.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.209.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.214.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.88.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000722; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000723; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000724; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.221.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000725; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.63.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000726; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.65.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000727; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.250.51.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000728; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.42.125.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000729; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.43.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000730; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.70.83.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000731; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.120.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000732; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.240.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000733; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.240.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000734; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.50.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000735; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.70.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000736; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.125.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000737; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.161.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000738; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.164.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000739; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.218.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000740; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.50.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000741; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.58.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000742; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.96.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000743; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.83.79.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000744; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.91.41.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000745; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.179.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000746; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.183.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000747; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.239.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000748; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.100.40.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000749; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.108.251.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000750; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.112.22.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000751; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.115.247.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000752; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.118.150.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000753; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.119.176.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000754; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.119.52.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000755; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.123.173.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000756; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.123.175.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000757; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.14.143.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000758; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.147.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000759; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.162.109.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000760; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.144.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000761; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.207.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000762; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.93.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000763; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.18.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000764; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.31.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000765; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.107.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000766; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.163.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000767; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000768; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.241.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000769; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.27.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000770; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.68.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000771; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.170.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000772; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.19.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000773; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.97.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000774; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.1.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000775; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.2.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000776; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.26.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000777; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.63.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000778; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.201.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000779; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.248.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000780; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.249.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000781; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.120.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000782; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.157.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000783; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.16.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000784; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.170.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000785; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.190.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000786; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000787; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.75.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000788; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.18.38.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000789; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.101.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000790; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.106.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000791; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000792; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000793; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.11.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000794; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.231.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000795; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.33.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000796; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.9.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000797; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.94.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000798; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.119.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000799; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.124.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000800; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.115.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000801; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.9.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000802; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.14.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000803; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.172.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000804; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.237.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000805; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.43.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000806; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.186.140.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000807; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.186.22.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000808; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.195.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000809; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.220.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000810; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.137.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000811; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.227.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000812; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.190.211.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000813; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.190.234.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000814; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.150.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000815; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.187.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000816; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.215.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000817; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.240.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000818; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.253.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000819; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.204.30.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000820; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.250.129.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000821; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.105.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000822; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.12.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000823; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.14.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000824; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.131.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000825; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.140.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000826; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000827; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000828; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.148.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000829; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.155.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000830; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.172.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000831; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.96.37.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000832; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.96.70.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000833; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.188.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000834; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.190.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100000835; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.232.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000836; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.132.113.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000837; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.15.69.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000838; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000839; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000840; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000841; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000842; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.207.39.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000843; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.153.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000844; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.212.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000845; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.231.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000846; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.142.222.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000847; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.150.213.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000848; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.151.248.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000849; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000850; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000851; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000852; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000853; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000854; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000855; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000856; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000857; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000858; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000859; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000860; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100000861; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000862; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000863; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000864; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000865; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000866; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000867; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000868; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000869; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000870; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000871; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000872; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000873; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000874; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000875; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.93.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000876; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.121.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000877; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000878; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000879; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000880; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000881; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000882; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000883; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.127.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000884; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.99.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000885; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.210.89.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000886; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.43.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000887; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.5.15.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000888; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.66.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000889; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.93.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000890; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.57.214.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000891; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.57.98.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000892; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.141.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000893; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.241.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000894; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.8.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000895; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.69.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000896; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.7.75.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000897; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.7.90.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000898; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.83.189.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000899; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.165.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000900; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.185.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000901; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.196.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000902; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.208.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000903; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.238.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000904; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.9.32.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000905; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.114.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000906; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.96.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000907; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.121.44.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000908; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.123.53.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000909; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.127.155.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000910; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.141.11.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000911; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.15.142.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000912; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.159.22.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000913; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.17.103.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000914; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.170.234.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000915; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.185.31.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000916; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.190.36.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000917; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.225.11.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000918; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.226.82.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000919; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.23.57.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000920; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.230.171.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000921; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.231.103.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000922; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.233.18.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000923; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.238.175.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000924; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.239.15.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000925; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.24.116.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000926; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.25.101.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000927; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.254.43.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000928; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.254.76.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000929; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.102.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000930; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.107.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000931; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.97.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000932; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.98.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000933; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.88.99.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000934; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.100.150.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000935; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.160.147.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000936; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.176.44.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000937; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.188.86.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000938; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.66.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000939; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.72.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000940; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.79.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000941; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.37.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000942; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.41.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000943; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.252.199.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000944; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.183.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000945; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.29.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000946; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.33.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000947; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.0.240.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000948; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.83.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000949; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.11.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000950; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.4.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000951; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.7.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000952; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.71.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100000953; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000954; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000955; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.170.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000956; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000957; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.19.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000958; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.200.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000959; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.238.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000960; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.12.189.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000961; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.12.225.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000962; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.12.235.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000963; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.12.243.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000964; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.128.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000965; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.133.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000966; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.177.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000967; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.84.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000968; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.88.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000969; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.202.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000970; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.208.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000971; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.23.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000972; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.27.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000973; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.37.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000974; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.61.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000975; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.77.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000976; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.131.186.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000977; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.132.219.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000978; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.125.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000979; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.144.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000980; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.184.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000981; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.98.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000982; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.14.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000983; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.50.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000984; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.39.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000985; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.71.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000986; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.127.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000987; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.173.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000988; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.249.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000989; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.34.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000990; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.37.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000991; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.50.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000992; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.93.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000993; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.144.211.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000994; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.152.42.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000995; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.153.80.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000996; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.116.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000997; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.236.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000998; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.94.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000999; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.155.118.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001000; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.156.136.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001001; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.137.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001002; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.31.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001003; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001004; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.101.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001005; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.194.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001006; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.149.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001007; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.53.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001008; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.235.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001009; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.35.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001010; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.52.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001011; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.60.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.112.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001013; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.184.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001014; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.98.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001015; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.212.29.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001016; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.213.225.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.130.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.152.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100001019; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.100.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001020; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.116.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.184.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.246.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.235.226.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.103.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.181.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.79.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.148.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.184.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.27.44.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.28.217.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.11.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001032; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.166.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001033; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.177.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001034; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.194.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001035; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.209.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001036; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.241.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001037; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.45.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001038; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.76.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001039; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.83.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001040; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.85.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001041; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.143.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001042; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.146.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001043; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.190.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001044; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.5.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001045; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.8.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001046; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.56.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001047; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.71.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001048; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.194.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001049; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.240.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001050; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.245.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001051; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.105.105.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001052; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.162.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001053; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.221.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001054; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.76.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001055; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.167.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001056; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001057; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.104.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001058; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.130.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001059; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.131.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001060; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.136.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001061; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.137.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001062; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.151.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.24.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001065; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.26.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001066; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.41.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.54.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.72.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.132.110.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.135.34.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.135.34.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.136.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.236.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.160.126.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.154.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.65.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.65.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.72.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.77.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.89.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.90.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.165.123.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.187.111.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.199.56.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.226.24.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.230.174.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.254.254.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.5.92.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.6.0.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.67.89.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.7.254.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.80.46.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.91.237.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.92.135.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.93.94.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.105.219.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.126.69.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.128.28.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.142.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.168.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.191.113.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.209.71.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.36.148.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.1.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.113.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.25.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.65.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.73.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.74.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.75.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.141.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.164.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.185.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.196.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.208.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.6.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.7.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.74.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.96.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.96.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.97.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.97.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001123; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.107.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001124; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.124.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001125; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.112.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001126; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.112.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001127; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.133.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.167.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001129; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.215.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001130; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.33.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001131; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.53.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001132; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.53.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001133; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.6.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001134; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.60.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001135; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.63.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001136; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.10.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.107.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.175.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.198.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.208.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.212.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.227.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.70.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.8.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.153.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.43.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.55.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.166.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.166.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.205.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.206.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.217.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.241.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.125.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.241.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001156; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.245.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.248.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.250.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.254.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.28.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.38.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.45.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.47.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.57.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.91.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.79.192.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"128.116.133.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"130.255.159.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"134.195.139.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"134.255.93.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"135.181.192.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"138.99.204.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.159.226.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001174; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.173.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.174.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.213.97.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.216.102.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.227.46.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001179; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.102.17.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001180; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.102.97.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001181; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.109.126.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001182; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.136.80.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001183; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.109.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001184; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.155.220.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.160.24.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.169.164.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.181.64.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.189.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.205.201.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.248.187.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.37.222.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.45.127.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.25.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.98.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.55.29.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.98.184.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"140.237.30.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"140.237.30.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"140.237.5.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"140.240.151.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.11.216.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.177.56.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"146.71.79.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001206; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"148.69.108.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.20.176.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.124.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.73.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"150.116.207.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.177.163.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.33.230.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.73.124.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.225.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.234.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.40.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.43.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.44.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.135.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.23.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.29.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.35.27.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.36.126.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.101.165.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.174.213.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.51.125.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.224.74.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.165.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.205.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.194.28.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.209.98.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.212.203.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.18.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.193.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.200.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.200.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.202.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.202.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.202.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.203.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.203.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.204.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.204.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.206.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.255.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.204.208.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.204.211.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.204.211.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.204.211.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.53.206.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"165.90.16.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"168.194.146.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"168.205.223.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"168.90.204.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"170.81.238.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.113.36.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.118.18.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.118.210.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.217.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.218.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.219.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.248.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.255.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.120.125.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.121.6.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.123.134.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.122.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.242.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.30.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.30.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.64.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.65.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.65.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.75.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.126.70.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.223.72.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.114.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.179.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.160.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.161.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.162.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.174.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.36.249.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.145.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.148.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.219.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.223.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.223.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.105.36.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.114.244.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.81.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.167.85.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.169.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.19.58.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.233.85.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.235.209.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.25.113.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.95.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.97.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.119.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.92.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.106.33.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.48.181.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.61.3.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.73.246.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.81.78.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.83.73.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.10.147.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.11.193.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.115.241.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.117.66.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.145.200.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.146.17.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.150.168.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.162.137.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.162.195.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.162.69.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.164.61.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.165.90.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.168.139.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.169.13.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.17.90.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.174.93.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.199.33.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.201.104.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.208.230.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.212.6.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.42.46.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.8.113.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.9.24.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.174.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.12.117.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.4.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.9.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.124.7.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.221.251.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.40.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.84.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.11.92.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.131.226.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.229.64.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.54.82.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.124.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.134.185.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.25.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.44.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.45.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.57.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.150.174.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.151.143.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.165.122.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.0.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100001388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001522; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001560; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001561; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001562; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001568; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001573; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001722; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001723; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001724; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001725; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001726; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001727; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001728; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001729; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001730; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001731; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001732; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001733; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001734; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001735; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001736; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001737; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001738; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001739; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001740; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001741; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001742; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001743; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001744; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001745; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001746; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001747; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001748; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001749; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001750; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001751; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001752; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001753; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001754; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001755; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001756; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001757; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001758; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001759; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001760; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001761; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001762; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001763; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001764; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001765; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001766; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001767; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001768; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001769; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001770; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001771; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001772; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001773; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001774; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001775; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001776; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001777; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001778; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001779; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001780; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001781; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001782; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001783; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001784; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001785; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001786; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001787; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001788; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001789; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001790; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001791; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001792; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001793; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001794; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001795; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001796; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001797; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001798; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001799; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001800; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001801; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001802; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001803; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001804; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001805; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001806; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001807; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001808; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001809; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001810; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001811; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001812; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001813; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001814; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001815; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001816; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001817; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001818; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001819; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001820; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001821; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001822; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001823; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001824; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001825; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001826; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001827; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001828; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001829; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001830; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001831; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001832; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001833; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001834; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001835; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001836; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001837; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001838; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001839; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001840; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001841; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001842; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001843; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001844; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001845; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001846; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001847; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001848; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001849; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001850; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001851; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001852; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001853; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001854; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001855; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001856; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001857; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001858; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001859; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001860; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001861; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001862; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001863; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001864; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001865; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001866; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001867; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001868; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001869; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001870; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001871; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001872; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001873; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001874; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001875; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001876; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001877; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001878; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001879; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001880; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001881; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001882; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001883; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001884; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001885; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001886; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001887; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001888; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001889; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001890; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001891; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001892; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001893; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001894; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001895; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001896; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001897; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001898; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001899; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001900; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001901; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001902; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001903; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001904; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001905; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001906; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001907; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001908; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001909; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001910; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001911; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001912; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001913; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001914; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001915; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001916; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001917; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001918; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001919; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001920; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001921; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001922; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001923; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001924; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001925; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001926; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001927; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001928; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001929; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001930; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001931; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001932; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001933; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001934; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001935; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001936; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001937; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001938; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001939; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001940; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001941; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001942; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001943; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001944; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001945; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001946; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001947; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001948; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001949; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001950; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001951; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001952; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001953; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001954; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001955; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001956; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001957; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001958; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001959; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001960; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001961; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001962; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001963; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001964; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001965; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001966; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001967; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001968; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001969; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001970; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001971; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001972; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001973; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001974; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001975; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001976; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001977; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001978; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001979; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001980; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001981; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001982; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001983; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001984; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001985; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001986; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001987; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001988; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001989; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001990; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001991; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001992; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001993; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001994; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001995; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001996; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001997; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001998; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001999; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.73.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002000; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002001; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002002; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002003; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002004; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002005; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002006; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002007; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002008; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002009; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002010; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002011; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002013; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002014; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002015; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002016; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100002019; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002020; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100002025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002032; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002033; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002034; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002035; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002036; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002037; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100002038; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100002039; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002040; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002041; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002042; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002043; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002044; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002045; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.82.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100002046; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.82.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002047; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002048; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002049; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002050; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100002051; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002052; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002053; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002054; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002055; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002056; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002057; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002058; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100002059; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100002060; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002061; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002062; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002065; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100002066; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100002067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100002084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100002085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100002095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100002101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100002115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100002119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002123; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002124; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002125; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002126; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002127; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002129; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002130; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002131; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002132; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002133; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002134; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002135; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100002136; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100002140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.19.183.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.205.101.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.21.164.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.217.8.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.22.117.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.222.252.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.34.183.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.48.235.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100002152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.92.246.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.95.115.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.95.136.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.159.58.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002156; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.4.187.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.42.107.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.43.157.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.60.84.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.99.210.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.109.36.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.111.101.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.114.111.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.116.203.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.120.149.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.122.13.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.125.44.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.157.66.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.175.236.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.105.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.110.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.165.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.214.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002174; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.34.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.96.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.104.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.242.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.218.5.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002179; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.248.80.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002180; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.253.99.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002181; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.111.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002182; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.53.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002183; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.94.170.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002184; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.138.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.143.60.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.193.107.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.210.45.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.215.47.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.224.242.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.236.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.59.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.28.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.34.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.43.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.52.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.238.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.29.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.105.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.111.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.64.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.76.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002206; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.79.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.83.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.92.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.93.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.104.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.105.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.108.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.116.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.118.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.119.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.36.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.60.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.61.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.80.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.94.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100002221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.99.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.13.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.15.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.25.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.26.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.29.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.39.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.49.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.118.146.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.118.166.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.100.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.109.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.118.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.14.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.15.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100002237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.166.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.166.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100002239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.179.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.197.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.202.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.21.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.211.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.214.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.221.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.226.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.255.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.7.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.89.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.37.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.43.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100002254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.129.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.134.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.15.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.157.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.205.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.205.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.207.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.254.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100002262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.55.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.66.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.9.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100002265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.94.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.202.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.123.203.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.123.211.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100002269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.123.241.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.123.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.177.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.19.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.201.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.88.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.113.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.123.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.126.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.127.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.67.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.83.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.88.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.0.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.103.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.104.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.106.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100002286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.152.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.155.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.221.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.93.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.160.98.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.172.36.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.233.0.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.235.252.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.53.197.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.56.193.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.59.235.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.225.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.109.169.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.11.238.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.136.252.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.150.244.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.16.208.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.185.112.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.185.162.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.187.163.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100002307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.151.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.180.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.188.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.228.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.93.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.105.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.127.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100002314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.26.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.92.195.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.97.22.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.164.185.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.175.115.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.74.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.106.209.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.107.3.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.172.110.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.181.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.219.133.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.221.3.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.228.141.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.239.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.245.96.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.26.113.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.34.16.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.43.19.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100002336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.45.103.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.55.1.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.68.230.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.81.157.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100002341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.90.166.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.151.144.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.219.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.253.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.183.131.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.225.120.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.232.44.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100002356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.28.60.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.33.113.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.4.125.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.73.188.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.12.10.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.188.124.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.212.200.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.233.208.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.33.71.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.21.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.231.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.113.102.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.113.81.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.119.45.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.13.179.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.138.200.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.152.41.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.178.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.179.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100002375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.45.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.167.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.242.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.81.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.83.202.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"189.222.157.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"19.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.0.42.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.109.178.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.110.161.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.111.151.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.119.207.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.12.99.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.121.194.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.15.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.20.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.141.117.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.147.16.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.159.240.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.187.55.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.210.214.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.177.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.226.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.49.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.214.24.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.216.140.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.35.225.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.65.206.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.73.12.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.92.4.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.41.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"191.255.248.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.175.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.241.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.209.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.220.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.228.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.3.152.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.3.73.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.99.240.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.142.146.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.228.135.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.38.55.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.91.131.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.147.142.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.15.36.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.152.35.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.38.20.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.139.126.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.228.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.24.94.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.202.26.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.218.48.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.166.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.159.2.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.50.27.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.133.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.207.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.251.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.251.72.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.201.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100002444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.202.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"199.188.101.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1am.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.229.89.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.249.161.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.111.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.125.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.58.69.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100002453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.83.152.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"20.185.42.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"20.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.105.167.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.111.189.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.194.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.2.161.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.30.132.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.142.147.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100002462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.163.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.248.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.187.102.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.200.254.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100002466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.203.221.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.203.27.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.215.84.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.218.97.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.107.233.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.150.176.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.164.153.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.166.217.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.29.95.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.4.124.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.176.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.191.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.74.236.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.109.201.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.130.69.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.189.156.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.204.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.229.21.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.236.190.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.70.166.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.77.80.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.119.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.171.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.82.36.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.82.49.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.93.6.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"204.195.116.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.185.115.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.248.137.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.47.41.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.5.32.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.163.58.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.39.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.145.60.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.124.149.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.152.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.153.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.234.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.234.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.237.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.245.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.68.242.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.96.116.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.116.220.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.172.11.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.179.43.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.132.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.75.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.204.215.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.66.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100002521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.93.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002522; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.216.66.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.114.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.120.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.246.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.238.83.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.113.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100002528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.5.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.36.174.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.47.102.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.51.174.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.122.86.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.143.227.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.156.215.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.46.197.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.56.197.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.119.74.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.123.206.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.135.178.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.14.173.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100002541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.182.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.190.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100002554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002560; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002561; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002562; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.117.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002568; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.117.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100002569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.117.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002573; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.119.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.119.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100002576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100002580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.189.178.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.240.218.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.249.156.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.27.8.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.80.44.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.87.87.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.254.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.127.185.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.170.240.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.183.54.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.36.12.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.11.75.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.127.133.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100002601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.8.228.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100002602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.12.162.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.12.181.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.2.40.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.215.243.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.238.246.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.28.160.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.207.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.227.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.68.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.81.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.48.135.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.56.93.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.57.109.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.57.53.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.59.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.72.198.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.79.103.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.103.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.114.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.115.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.116.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100002625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.126.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.142.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.143.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.147.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.148.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.173.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.178.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.41.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.102.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.11.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.113.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.14.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.209.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.24.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.243.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.26.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.29.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100002642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.31.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.31.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.86.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100002645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.98.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.131.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.17.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.176.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.23.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.60.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100002651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.65.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.88.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.11.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.146.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.147.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.150.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.178.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.178.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.183.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.214.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.223.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.42.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.67.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.241.6.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100002666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.163.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.171.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.245.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.251.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.5.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.69.71.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.80.217.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.85.145.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"21robo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.118.168.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.126.237.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.133.30.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.200.22.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.71.239.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.90.159.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.1.162.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.124.78.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.122.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.165.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.185.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.47.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.47.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.57.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.108.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.112.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.125.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.155.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.190.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.234.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.237.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.250.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.253.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.54.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.55.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.157.191.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.136.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100002704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100002706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.196.12.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.198.167.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.2.190.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.202.232.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.130.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100002711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.224.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.251.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.116.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.172.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.184.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.237.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.252.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.8.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.1.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.179.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.137.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002722; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.142.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100002723; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.112.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002724; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.32.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002725; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.34.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100002726; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.43.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002727; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.68.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002728; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.108.17.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002729; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.119.65.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100002730; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.132.125.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002731; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.102.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002732; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.103.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002733; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.105.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002734; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.219.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002735; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.26.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002736; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.67.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002737; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.136.53.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002738; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.136.77.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002739; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.101.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002740; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.101.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002741; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.121.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002742; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.137.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002743; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.138.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002744; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.148.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002745; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.161.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002746; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.172.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002747; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.198.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100002748; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.220.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002749; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.237.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002750; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.239.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100002751; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.49.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002752; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.53.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002753; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.72.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100002754; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.96.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002755; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.118.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002756; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.143.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002757; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.151.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002758; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.189.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002759; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.201.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002760; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.213.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002761; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.226.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002762; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.96.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002763; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.139.106.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002764; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.162.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002765; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.163.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002766; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.17.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002767; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.179.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002768; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.208.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002769; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.209.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002770; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.39.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002771; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.101.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002772; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.120.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002773; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.13.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002774; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.40.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002775; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.46.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002776; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.9.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100002777; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.192.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002778; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.209.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002779; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.179.215.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002780; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.185.116.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002781; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.187.9.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002782; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.211.72.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002783; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.214.54.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002784; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.218.220.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002785; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.236.85.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002786; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.238.230.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002787; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.239.83.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002788; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.248.64.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002789; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.81.156.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002790; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.92.9.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100002791; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.99.171.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002792; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.166.117.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002793; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.167.118.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002794; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.225.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002795; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.234.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002796; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.5.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002797; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.73.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002798; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.125.186.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002799; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.126.120.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002800; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.228.143.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002801; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.24.213.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002802; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.149.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002803; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.21.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002804; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.95.89.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002805; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.103.74.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002806; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.11.141.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002807; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.119.158.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002808; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.137.147.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002809; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.152.235.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002810; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.158.25.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002811; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.176.206.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002812; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.184.1.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002813; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.192.191.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002814; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.225.114.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002815; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.227.190.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100002816; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.35.245.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002817; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.181.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002818; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002819; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.42.229.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100002820; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.45.4.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002821; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.51.91.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002822; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002823; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002824; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002825; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002826; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002827; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.106.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002828; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.152.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002829; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.116.84.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002830; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.12.245.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002831; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.141.218.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002832; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.29.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002833; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.40.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002834; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.153.142.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002835; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.184.244.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002836; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.184.54.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002837; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.187.248.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002838; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.187.250.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002839; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.196.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002840; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.217.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002841; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.149.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002842; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.192.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002843; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.210.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002844; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.17.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002845; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.22.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002846; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.23.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002847; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.24.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002848; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.28.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002849; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.148.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002850; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.232.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002851; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.3.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002852; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.34.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002853; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.110.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100002854; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.140.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002855; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.2.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002856; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.23.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002857; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.32.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100002858; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.201.183.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002859; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.182.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002860; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.66.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002861; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.102.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002862; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.126.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002863; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.154.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002864; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.165.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002865; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.175.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002866; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.185.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002867; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.213.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002868; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002869; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.255.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002870; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.28.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002871; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.4.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002872; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.68.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002873; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.87.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002874; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.94.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002875; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.204.253.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002876; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.205.178.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002877; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.136.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100002878; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.148.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002879; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.154.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002880; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.26.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002881; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.80.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002882; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.81.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002883; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.83.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002884; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.97.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002885; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.151.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100002886; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.155.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002887; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.170.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002888; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.54.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002889; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.144.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002890; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.152.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002891; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.160.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100002892; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.164.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002893; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.166.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002894; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.201.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002895; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.247.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002896; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.25.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100002897; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.34.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002898; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.70.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002899; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.92.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002900; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.160.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002901; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.231.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002902; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.60.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002903; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.107.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002904; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.127.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002905; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.172.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002906; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.234.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002907; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.236.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002908; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.63.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002909; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.211.251.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002910; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.104.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002911; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.109.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002912; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.109.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002913; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.145.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002914; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.166.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002915; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.167.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002916; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.175.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002917; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.220.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002918; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.255.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002919; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.255.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002920; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.84.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002921; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.214.37.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002922; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.139.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002923; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.190.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002924; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.212.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002925; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.212.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002926; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.253.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002927; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.27.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100002928; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002929; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.38.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002930; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.38.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002931; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.71.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002932; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.98.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002933; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.131.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002934; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.144.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002935; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.193.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002936; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.197.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002937; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.223.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002938; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.225.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002939; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.227.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002940; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.234.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002941; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002942; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.95.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002943; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.120.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002944; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.133.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100002945; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.191.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002946; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.76.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002947; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002948; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.219.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002949; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.240.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002950; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.248.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002951; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.119.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002952; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.132.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002953; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.151.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002954; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.160.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002955; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.172.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002956; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.173.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002957; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.176.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100002958; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.184.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002959; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.192.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002960; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.83.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002961; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.40.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002962; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.80.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002963; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.85.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100002964; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.221.239.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002965; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.241.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002966; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.249.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002967; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.42.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002968; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.50.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002969; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.223.242.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002970; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.24.28.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002971; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.107.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002972; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.129.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100002973; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.154.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002974; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.212.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100002975; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.58.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002976; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.159.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002977; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.37.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002978; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.9.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002979; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.9.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100002980; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.97.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002981; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.43.108.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100002982; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.43.111.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002983; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.43.117.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002984; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.23.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002985; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.44.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002986; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.44.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002987; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.45.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100002988; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.46.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002989; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.46.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002990; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.23.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002991; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.47.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002992; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.6.240.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002993; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.6.38.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002994; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.0.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002995; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.11.51.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002996; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.13.23.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002997; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.154.234.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002998; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.163.191.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002999; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.124.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003000; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.179.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003001; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.184.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003002; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.191.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003003; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.194.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003004; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.216.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100003005; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.219.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100003006; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.24.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003007; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.30.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003008; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.60.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003009; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.63.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003010; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.65.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003011; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.94.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.179.201.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003013; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.195.84.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003014; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100003015; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100003016; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.28.7.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.30.119.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32.208.157.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100003019; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32.218.180.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100003020; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32792.prolocksmithwinterpark.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"35.184.169.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.108.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.250.203.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.157.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100003025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.18.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.18.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.19.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.51.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.255.90.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100003030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.128.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.160.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100003032; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.34.150.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003033; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.36.243.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003034; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.43.11.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003035; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.105.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003036; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.111.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003037; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.133.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003038; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.139.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003039; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.67.152.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003040; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.81.23.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003041; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.89.18.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003042; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.96.187.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003043; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360.lcy2zzx.pw"; content:"Host"; http_header; classtype:trojan-activity; sid:100003044; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360down7.miiyun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003045; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.222.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003046; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.233.60.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100003047; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.179.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003048; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003049; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.44.238.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003050; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.49.229.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003051; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.49.230.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100003052; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.52.117.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100003053; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.14.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003054; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"38.77.14.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003055; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.245.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003056; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.98.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003057; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.114.137.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003058; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.117.31.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003059; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.162.104.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003060; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.64.28.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003061; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.196.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003062; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.59.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100003063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.115.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.129.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003065; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003066; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.125.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.146.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.148.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.124.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100003071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.171.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.249.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.60.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.167.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.5.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100003076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.67.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.10.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.163.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.203.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100003080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.104.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100003081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.184.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100003082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.31.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.68.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.194.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.33.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.79.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.97.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.113.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.114.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100003090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.136.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.14.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.150.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.197.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.209.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100003095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.48.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.94.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100003097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.95.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.146.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.163.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.166.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.218.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.62.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.91.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.93.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.127.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.18.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100003107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.191.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.205.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.36.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.37.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.251.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100003113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.27.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100003114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.29.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.82.86.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100003116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.83.94.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.115.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100003118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.157.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.34.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100003120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.95.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003123; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.129.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003124; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.13.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100003125; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.170.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100003126; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.184.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003127; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.211.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100003128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.216.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003129; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.234.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100003130; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.248.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100003131; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.66.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100003132; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.73.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100003133; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.63.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003134; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.90.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003135; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.93.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003136; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.141.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.155.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.233.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.67.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100003140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.72.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100003141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.157.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100003144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.63.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.90.86.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100003146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"40.88.2.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.139.209.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.165.130.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.193.192.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100003150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.219.185.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.230.31.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.72.203.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100003156; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.19.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100003160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.19.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100003161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100003167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.176.112.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.177.164.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.179.162.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.179.163.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100003171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.202.101.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100003172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.122.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003173; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.122.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100003174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.169.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100003175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.171.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100003176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.172.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.18.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.171.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100003175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.172.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.188.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100003177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.189.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100003178; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.19.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003179; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.220.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003180; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.233.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100003181; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.234.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003182; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.245.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100003183; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.249.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100003184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.36.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.56.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.69.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.70.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.120.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.205.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.241.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.226.89.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100003192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.194.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100003193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.196.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100003194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.66.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.39.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100003196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.40.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.60.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.67.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100003199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.68.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.70.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100003201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.70.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.84.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100003203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.153.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.219.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100003205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.249.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.3.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100003186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.36.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.52.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.68.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.69.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.70.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.120.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.205.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.241.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.194.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100003195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.196.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100003196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.66.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.196.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100003198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.40.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.60.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.67.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100003201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.68.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.70.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100003203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.70.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.218.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003205; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.25.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.48.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.231.95.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100003208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.232.102.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.232.23.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100003210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.233.78.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.233.90.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.234.85.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100003213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.23.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.3.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100003215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.82.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.86.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100003217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.90.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.95.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.148.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.237.252.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.21.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.98.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100003223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.242.200.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100003224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.56.15.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.61.99.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100003226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.84.37.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.87.29.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.230.156.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.241.106.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.203.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.135.134.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100003235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100003237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.141.84.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100003240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100003245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.110.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.178.101.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.179.171.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.22.209.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.23.22.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.231.210.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.27.253.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.33.112.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.51.104.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.81.235.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.9.148.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.151.155.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.172.75.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.175.184.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.182.173.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.182.173.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100003267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.20.63.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.21.153.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.214.27.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.24.130.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.243.179.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100003273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.25.242.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100003274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.118.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100003275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.86.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.97.76.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.145.152.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.151.23.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.157.97.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.16.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.197.0.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.21.202.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.46.231.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.162.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100003285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.87.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.143.32.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.143.43.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.156.35.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.158.201.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.20.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.21.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.174.182.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.170.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.178.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.179.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.68.221.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.68.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.70.15.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.146.202.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.181.135.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.2.70.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.53.146.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.8.10.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100003306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.121.91.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.252.47.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.171.146.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100003309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.222.56.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.114.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.180.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.114.246.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.162.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100003314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.174.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.125.191.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.126.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.141.122.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.166.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100003319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.200.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.143.142.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.143.189.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.18.103.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.19.249.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.218.67.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100003325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.22.212.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100003326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.226.129.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.229.194.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.23.245.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100003329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.230.89.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.238.42.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.240.147.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100003332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.57.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.78.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.243.126.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.112.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.140.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.143.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100003338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.144.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.144.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.147.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100003341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.151.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.153.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100003343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.76.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.77.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.82.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.12.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100003347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.14.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100003348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.16.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100003349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.19.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.23.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.73.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.74.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100003353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.74.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100003354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.75.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100003355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.75.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100003356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.77.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.79.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.82.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.86.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.87.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.88.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.252.176.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.253.13.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.48.154.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.50.221.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100003368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.76.151.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100003369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.97.206.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.0.211.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.102.168.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100003372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.202.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.214.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.29.133.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100003375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.32.97.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100003376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.42.62.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100003377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.45.235.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100003378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.58.104.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.58.117.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.7.124.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.8.35.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.176.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.18.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.181.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100003385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.182.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100003386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.182.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.218.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100003388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.218.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.17.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.18.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.22.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100003392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.94.180.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100003393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.94.181.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.94.183.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.95.174.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100003396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.95.175.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.96.38.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.96.38.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.168.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.169.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100003401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.169.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100003402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.171.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.172.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100003404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.173.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.174.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.175.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.136.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.136.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.138.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.139.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100003411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.141.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.40.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100003413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.40.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.41.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.44.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.44.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.44.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.47.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.47.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.93.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.94.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100003422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.13.61.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100003423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.14.48.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.16.247.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100003425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.162.122.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.164.130.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.176.249.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.184.149.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.20.217.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.208.135.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.122.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.186.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.216.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.233.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.33.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.19.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.6.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.162.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100003440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.202.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.206.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.218.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.220.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100003444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.254.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100003446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.162.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.58.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.83.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.214.73.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100003450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.214.93.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.165.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.195.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100003453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.207.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.4.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100003455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.177.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.86.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.223.84.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.25.109.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100003459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.25.115.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100003460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.25.76.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100003461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.15.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100003462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.39.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.42.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.51.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.26.17.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.10.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.8.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.99.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.102.243.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.162.169.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.162.55.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.163.142.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.164.96.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.171.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100003478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.18.112.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100003479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.192.73.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100003480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.213.118.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100003481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.247.224.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.253.94.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100003483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.124.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100003484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.124.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100003485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.127.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.149.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100003487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.47.220.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.103.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.11.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.159.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.195.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.212.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.214.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.237.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100003495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.242.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.48.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.76.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.9.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.9.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.99.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.100.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.102.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.117.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.119.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.122.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.123.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.192.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.2.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.201.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.54.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.72.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.81.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.99.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.103.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.168.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.232.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100003517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.40.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.58.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100003519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.58.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100003520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.63.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003521; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.64.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100003522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.76.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.77.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100003524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.180.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.181.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100003526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.57.96.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100003527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.170.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.73.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.61.218.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.65.172.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.0.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.104.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.110.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100003535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100003536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.255.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.45.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.98.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.1.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.117.124.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.141.73.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.131.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100003543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.155.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.227.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.31.126.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.43.207.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.90.165.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"63.245.122.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"64.233.154.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.125.128.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.21.58.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.26.155.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.35.61.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.153.233.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.229.214.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003559; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.57.55.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003560; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.74.7.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100003561; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.91.21.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.245.151.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.3.169.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100003566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.8.138.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100003567; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.81.98.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100003568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.82.242.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.83.49.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.84.138.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.151.244.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003572; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.174.182.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.175.107.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.188.144.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.204.88.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.106.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.119.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100003578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.78.33.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.115.37.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100003580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.120.237.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.123.245.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.124.231.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100003583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.127.214.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.146.232.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.165.173.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.196.158.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.222.157.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.229.0.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.63.73.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.115.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.227.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.76.240.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100003593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.115.31.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100003594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.118.240.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.167.10.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.236.190.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.25.5.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100003598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.93.129.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.127.148.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100003600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.146.190.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100003601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.167.164.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100003602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.19.150.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.204.63.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100003604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.29.48.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.34.191.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.40.234.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.106.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.2.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.235.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100003610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.47.133.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.71.60.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100003612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.85.106.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100003613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.17.22.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100003614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.186.139.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.180.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.200.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.214.69.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.230.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.35.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.204.216.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100003621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.101.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.108.224.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.194.117.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.195.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100003625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.199.84.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.64.139.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100003627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.75.165.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.127.141.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.176.213.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.83.102.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.99.213.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.108.199.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.170.11.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.178.22.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100003635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.250.199.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.254.129.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.84.134.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.95.12.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.237.25.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.50.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.52.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.79.191.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.89.203.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100003644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.186.155.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.141.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.240.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.41.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.168.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.188.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100003650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.104.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100003651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.176.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.23.172.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.8.225.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.11.195.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.13.49.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.130.253.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100003657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.147.123.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100003658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.170.31.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.175.42.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.21.84.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.7.170.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.79.58.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.8.70.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.9.88.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.107.89.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100003666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.19.101.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.211.181.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.217.12.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100003669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.67.32.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.99.128.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.136.146.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.165.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.191.40.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.111.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.141.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100003676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.215.199.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.187.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100003678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.195.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100003679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.237.128.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.246.225.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.92.36.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.103.108.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.135.196.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.212.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100003685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.85.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.207.61.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.209.250.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100003688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.211.156.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.110.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.53.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.138.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.139.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100003693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.154.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.187.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.100.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.106.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.108.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.131.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100003699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.19.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.197.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.215.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100003702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.232.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100003703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.234.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100003704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.28.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.4.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.55.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.73.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100003709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.9.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.165.237.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.147.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.218.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.242.253.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.252.9.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.212.219.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.224.162.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100003720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.50.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.95.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100003722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.247.83.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100003723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.254.39.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.33.111.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.40.127.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.42.20.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100003727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.11.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100003729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.123.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100003730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.135.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100003731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.208.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100003732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.224.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100003733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.241.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100003734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.214.149.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.64.181.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.74.215.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.130.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.195.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"86.35.43.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.61.89.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.119.171.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100003742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.208.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.219.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.225.222.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.247.96.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.136.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.51.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.249.244.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.204.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100003750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.226.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.254.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100003752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.122.183.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.29.213.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.34.26.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.35.62.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.85.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.87.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.46.237.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100003759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8poieq.bn.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"90.152.144.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"90.63.176.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.177.139.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100003763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.187.103.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.212.150.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100003765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.217.104.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.233.112.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.234.60.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.239.168.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.244.169.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.92.16.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003771; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.98.4.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100003772; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.113.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003773; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.114.191.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003774; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.241.78.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003775; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.27.246.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003776; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.54.237.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003777; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.54.237.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003778; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.83.62.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003779; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.85.18.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100003780; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.171.157.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100003781; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.21.224.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003782; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100003783; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.137.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003784; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.182.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100003785; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.206.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003786; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.57.43.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003787; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.73.99.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003788; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.136.69.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100003789; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.143.53.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003790; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.17.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100003791; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.82.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100003792; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.200.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003793; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.224.83.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003794; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.53.120.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003795; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.132.129.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003796; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.153.241.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003797; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.154.20.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003798; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.158.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003799; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.113.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003800; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.201.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003801; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.181.155.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003802; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.146.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100003803; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.6.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003804; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.66.196.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003805; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.9.120.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003806; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.239.73.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003807; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.47.147.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003808; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.103.64.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003809; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.68.140.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003810; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.96.199.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003811; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.210.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003812; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.239.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003813; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.113.239.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100003814; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.116.72.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003815; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.128.147.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003816; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.178.242.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003817; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.249.236.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003818; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.28.200.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003819; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.30.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003820; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.150.245.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003821; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.33.195.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003822; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99centsdigitals.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003823; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abcd.bg"; content:"Host"; http_header; classtype:trojan-activity; sid:100003824; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abclicks.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003825; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abissnet.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003826; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aboveandbelow.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003827; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absoftechworld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003828; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absupplies.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003829; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abyssos.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003830; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acbick.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003831; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts.thesmarttechhub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003832; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aceeprc.com.aceeprc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003833; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acellr.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003834; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aciabogados.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003835; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acteon.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003836; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"activateyourdiscount.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003837; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"activecost.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003838; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adamorinmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003839; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"addahealingmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003840; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003841; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.memengers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003842; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.erapor.smk-alasror.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003843; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.gentbcn.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003844; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.grandoceanvilla.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003845; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adventureexplorer.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003846; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aeropilates.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003847; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afrimedspecialist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003848; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agemn.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003849; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciadigitalwdys.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003850; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciatabletshouse.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003851; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenda.gmelloinformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003852; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agentt.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003853; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agile8studio.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003854; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agmcarpetcare.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003855; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiqtest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003856; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajpharmaholding.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003857; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajstudiollc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003858; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"akivj07.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100003859; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"al-wahd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003860; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alasdemariposas.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003861; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alemelektronik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003862; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alena1971.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100003863; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alexdubai.com.aldiabsteel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003864; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"algreenstdykelveskbg.dns.army"; content:"Host"; http_header; classtype:trojan-activity; sid:100003865; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alka.institute"; content:"Host"; http_header; classtype:trojan-activity; sid:100003866; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"allforcreative.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003867; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alltheway.travel"; content:"Host"; http_header; classtype:trojan-activity; sid:100003868; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpaylar.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003869; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"am-concepts.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003870; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amamontajes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003871; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarresdeamorymaestroshechiceros.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003872; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarteargentina.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003873; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amenyan.zouri.jp"; content:"Host"; http_header; classtype:trojan-activity; sid:100003874; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amos524.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003875; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ams.alvinasschools.org.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100003876; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anantam.net.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003877; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreelapeyre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003878; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andremaraisbeleggings.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003879; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003880; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003881; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreshconcejal.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003882; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelazgheibld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003883; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelsdetour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003884; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angloteste.bigprime.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003885; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anhung1102.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003886; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anysbergbiltong.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003887; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apartamentoscitta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003888; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api-ms.cobainaja.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003889; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003890; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.quocbao.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003891; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.sampy.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100003892; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apoolcondo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003893; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.adsensearticle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003894; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.explicitsurveys.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003895; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.prerana.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003896; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apps.saintsoporte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003897; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aqv.news"; content:"Host"; http_header; classtype:trojan-activity; sid:100003898; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"areyoulivingwell.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003899; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"arsapetrolab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003900; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"artedibujoyarquitectura.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003901; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ask-regard.call-save.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003902; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atfile.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003903; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"athenacapsg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003904; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atlasconcreteworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003905; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atnetech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003906; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"attach.66rpg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003907; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atteuqpotentialunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003908; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"augustair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003909; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aulist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003910; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"australiafashions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003911; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"automaticrefreshments.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003912; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"avadhanagames.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003913; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"avissrilanka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003914; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayamallah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003915; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azmeasurement.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003916; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azraktours.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003917; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"b2b.toptanakaryakit.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003918; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"backgrounds.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003919; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"badeggdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003920; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"balealgodon.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003921; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangkok-orchids.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003922; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"barcionstw.eastus.cloudapp.azure.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003923; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bary.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003924; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bash.givemexyz.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003925; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"basma.com.kw"; content:"Host"; http_header; classtype:trojan-activity; sid:100003926; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003927; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bavhome.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003928; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003929; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcmt.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003930; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcrg.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003931; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bearcatpumps.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003932; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beautincollagen.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100003933; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bekape.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003934; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bespokeweddings.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100003935; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestcarenepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003936; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betone.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003937; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betycopaints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003938; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beveragesmiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003939; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bhavaniengineering.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003940; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bigbag.wootraining.certificacion.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003941; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilbosaquet.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003942; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilhen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003943; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing.rahitechnosoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003944; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"binoy.stalphonsamissionva.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003945; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birdi.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003946; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birminghamlink.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003947; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.callensaxen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003948; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.oyinblogs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003949; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.takbelit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003950; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bmlifestyle.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003951; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bnrbook.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003952; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bnrnews.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003953; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bodenstein.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003954; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"booksearch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003955; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bounces.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003956; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bpo.correct.go.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003957; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brandtrust.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003958; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brendanquine.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003959; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brideofmessiah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003960; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bridesofmaldives.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003961; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightmega.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003962; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightonrooms.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003963; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightstarshop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003964; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"browardinsurancemiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003965; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bt2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003966; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"btdapi.robotake.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003967; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bucrinsuranlceonlines.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003968; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buenavista.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003969; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buigiaphat.com.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003970; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bullseyemedia.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003971; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"busandvanrentalmalaysia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003972; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buscascolegios.diit.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003973; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003974; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buyingmusiconline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003975; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bwsr.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003976; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c.oooooooooo.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100003977; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c0140529.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003978; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"caballo.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003979; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"calgaryautorepairservice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003980; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"callbury.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003981; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"camminachetipassa.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100003982; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"campusvirtual.cepsanjuanbosco.net.pe"; content:"Host"; http_header; classtype:trojan-activity; sid:100003983; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cancer.educandome.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003984; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalgroup-kw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003985; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalnewsagency.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003986; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capoeiraventrelivre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003987; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cashyinvestment.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003988; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchpoolshetlands.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003989; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cazyacustomfurniture.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003990; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ccauthority.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003991; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cdaonline.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003992; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cec.asso.ac-amiens.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003993; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cellas.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003994; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cendekiabinaaksara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003995; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cespol-bote.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003996; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cfs5.tistory.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003997; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.rmu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003998; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"changematterscounselling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003999; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chardhamdodham.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004000; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cheacrilnsurances.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004001; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chealablilitycarinsurances.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004002; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chezalice.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004003; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"childselect.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004004; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004005; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004006; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cible-energy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004007; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cifeer.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004008; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citycapproperty.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004009; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cityglobalgospel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004010; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"civi.istmejia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cleanbydesignllc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004012; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cloud.fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004013; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"codsambal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004014; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colinde.pricesne.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004015; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colorpak.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"competancy.indigoconsult.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"config.cqhbkjzx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004018; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"constructoralyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004019; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"consulateins.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"contributeindustry.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"controladoradeplagasmm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"controleautomacao.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"copelandscapes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"coulsongraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"coutler.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"covid19.cyberschool.or.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-sq.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"craftnesia.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"creationskateboards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crecerco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004031; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crittersbythebay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004032; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crm.notariavieitoyvelamazan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004033; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crscorretordeimoveis.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004034; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cse-engineer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004035; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"csnserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004036; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubescargoexpress.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004037; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubrebocasenpuebla.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004038; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"curasoles.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004039; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"currantmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004040; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cwa.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004041; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyber.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004042; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyclomove.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004043; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cynkon.kairoscs.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004044; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czas.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004045; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czsl.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004046; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d.powerofwish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004047; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d9.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004048; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"da.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004049; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"damagedessentialtelecommunications.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004050; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dandyair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004051; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dartoonpictures.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004052; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.cdevelop.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004053; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.over-blog-kiwi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004054; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datapolish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004055; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dating.khokhas.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004056; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datsom.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004057; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"daunhotq10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004058; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davethompson.me.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004059; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davidmcguinness.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004060; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dayspringdaisies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004061; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dd.qiyuea.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"de.gsearch.com.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"decifrar.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004064; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"deigratia2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004065; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dekovizyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo-cliente.mindcreative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo6.hiites.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dent-estet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dental.xiaoxiao.media"; content:"Host"; http_header; classtype:trojan-activity; sid:100004070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dentalalliance.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100004071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"designerliving.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"desiringhands.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"despertaresi.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"destinymc.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"detorre.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev-interestingtech.pantheonsite.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.sayse-tienda.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.sebpo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfcf.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfsfcsfcdsfsdvcfsvcscv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"diamantenegro.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dienmayminhhung.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digilib.dianhusada.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"djking.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.1003b.56a.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.installcdn-aws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.packetstormsecurity.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.rina-roleplay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.zkytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dns.cyberium.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100004092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dockerupdate.anondns.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"docman.orientalservices.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dodsonimaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dokan.blueberrytec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom-chel74.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom.daf.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doncedyhall.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donghobinhminh.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dongphuctop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donwnloasecury.ath.cx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosman.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dovberger.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.flash-plays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.pcclear.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.udashi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.webbora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down1.arpun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.caihong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.doumaibiji.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.exrnybuf.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.kaobeitu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.pdf00.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.rising.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.skycn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.zjsyawqj.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"downloads.jxtsteel.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dragonsknot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drbaby.com.sa"; content:"Host"; http_header; classtype:trojan-activity; sid:100004121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drohnen.ensenanzainteligente.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004122; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drools-moved.46999.n3.nabble.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004123; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drsha.innovativesolutions.mobi"; content:"Host"; http_header; classtype:trojan-activity; sid:100004124; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsenterprize.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004125; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsspainting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004126; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"du-wizards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duque.guantanameratravel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004128; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dutapp.wisolve.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004129; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duvalcharter.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004130; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dx.qqyewu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004131; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dzinestudio87.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004132; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-commerce.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004133; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004134; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebruyatkin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004135; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"econews.treegle.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"efficientegroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"elliot.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"en.baoend.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enc-tech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"endurotanzania.co.tz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ennovate.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enriquecendocomconsorcio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"envios.petpienso.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"equimination.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100004145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"escola.probommar.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"esnconsultants.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"essentia.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eubanks7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"evidencemarketing.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exilum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exitoalfaomega.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"extrovertoffers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"f1sol.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"familydentist.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100004155; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"farmaciasdrogaminas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fate3.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"faveraprojects.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"felicienne.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fi.bonitastores.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files.martellexpress.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100004162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"final.makkahkmcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fineartgallerym.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fkd.derpcity.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flintspin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flyingbuddhadesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fmjplastering.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fms.buladde.or.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foothills.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"footweardirect.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"forum.mdb.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fotoobjetivo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004173; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foundationrepairhoustontx.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foxeps.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freecnetdownload.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freedombookshop.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freisites.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004178; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ftp.n3twork30cm.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100004179; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fullelectronica.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004180; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"funletters.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004181; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fusionfiresolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004182; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gametwogame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004183; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garciadogshow.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow4.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gbbulls.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gcpc.co.id.chronoscurtain.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"generaldeviales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfmodd1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfold1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghettohub.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghislain.dartois.pagesperso-orange.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giadungg7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giddos.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100004195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gilliem.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"girotexuniformes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giteletropical.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"globaltask.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"glowinmedia.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmtransformationacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmvadmission.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnimelf.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnscrew.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gold.investforex.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004205; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcake.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcupmortgage.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"golden-memories-funerals.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldmen.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupoinmare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gruposelt.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gs.monerorx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gulfac-house.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gvpcdpgc.edu.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"habbotips.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hagebakken.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100004218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"harshraval.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hd11315.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdkamera2003.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hds.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"healthy20.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"heavymaq.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hellogorgeous.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"help.hizuko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"herchinfitout.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hhaward.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandroadcoc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandslasvegas.atakdev.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hindi.factsriver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hiptool.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitpe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitstation.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hmpmall.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoagietesting10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoayeuthuong-my.sharepoint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"homefindersolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hongluosi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hookedupboatclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostelkielce.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostzaa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"houstonshutters.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100004244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hr2019.vrcom7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hseda.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsmwebapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"htownbars.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hubtech.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hunggiang.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"husamiyahschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iam313.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"icon.shatangmu.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idea-secure-login.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idilsoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idj.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100004256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idvindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iesanjosemonitos.edu.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ikexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ilrafrica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"images.jermiau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"imbueautoworx.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incodimsa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incrediblepixels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incredicole.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infair.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infovator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"innatosbrand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inodesthetotaldesigners.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inovations.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inrajahmundry.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"insignificantfinecore.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"instantindialoan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intellectsmart.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intersel-idf.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intuitiveideas.com.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inversiones.arrayanfinanciero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"invest.xpcorporative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ipmes.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100004279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iremart.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isaac.mikhailmotoringschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iscamenabe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ismf.com.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100004283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iso-dubai.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"israrulhaq.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100004285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isrorg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isso.ps"; content:"Host"; http_header; classtype:trojan-activity; sid:100004287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"it123.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itc-demo.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itconsultus.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamesjorgensen.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamiekaylive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamshed.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jansen-heesch.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jathra.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jay.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100004296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jebs.net.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeffdahlke.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jewsjuice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jhayesconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jiaoyuzixun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jing-da.com.tw"; content:"Host"; http_header; classtype:trojan-activity; sid:100004302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jmcomputacion.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jmtc.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jnanbharati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jobs.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"joelbonissilver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"join.cl8movement.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josegene.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josuarochoa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jpwoodfordco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jumpmanualjacobhiller.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jupiter.toxsl.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jurgensen.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"justinscott.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kaizenjanitorial.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalawatihomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalpataru-elitus-mulund.thakkers.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"karer.by"; content:"Host"; http_header; classtype:trojan-activity; sid:100004319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"katanvetov.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100004320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kbdom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kensingtondriving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kevinjewelry.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"keywatch.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kingssa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kjcpromo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kleinendeli.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"korrectconceptservices.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ktb.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kubatoglubaklava.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kumaralok.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kwanfromhongkong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kz.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lacasadelosalebrijes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ladylabonde.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lameguard.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laodongnhat.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laravel.pointersoftwares.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lasermobilesounds.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lauratomismith.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lautarosanmiguel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawforall.edu.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lceventos.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ld.mediaget.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ldgcorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"learning.real-academy.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leasiacherise.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leczkregoslup.acelero.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"legend.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leluibuffet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lestesteux.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"libantravel.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.arihantmbainstitute.ac.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.uib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lidoraggiodisole.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lifebeam.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lindnerelektroanlagen.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"linkintec.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"litroxlitro.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"livetrack.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsindian.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lm.stagingarea.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmaancha.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100004363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.login2.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmvirtualbookkeeping.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lnt-rejuve-360.thakkers.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"location-voitures.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100004368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.trezor.com.stockfootagesindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"logotypfabriken.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100004370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotix.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotusanddragonfly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.carrduci.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.definerisco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.juancamilogarciareyes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.tecnimasdecolombia.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ltc.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luckybrownie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luminouspneuma.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luxomodels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m-technics.kz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.estudiomoros.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"madicon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"magianegramagiablancayamarres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.bs-eiendomme.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.golimoapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.jeffsono.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maksi.feb.unib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malaya.tv"; content:"Host"; http_header; classtype:trojan-activity; sid:100004390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malwarecoding.github.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managed.oss-cn-beijing.aliyuncs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managemysalon.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manantialesdelnorte.uy"; content:"Host"; http_header; classtype:trojan-activity; sid:100004394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manhtien.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marcapinyo.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mario-sunjic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariobrown.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariotessarollo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketinfosales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketing.enexusgroup.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marksidfgs.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"masjidhabeebiyarazviya.mysunni.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"materialescantu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"matruchhaya.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mattysplayground.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxtox.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbgrm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbsolutions.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100004409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mdasa.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medevlb.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"media-server.skyinternet.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mediamaster.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medianews.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100004414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medistaffconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meeweb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megamart.afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merbay.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merkathink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mertlog.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"metalin-cr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mettaanand.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meuoculosnanet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mfevr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"micalle.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michaelphilip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michimal2.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microblading.mirliandias.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microcomm-group.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mikhailmotoringschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mindfulbuildingandliving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mingguanwms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"minuevavida.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mirror.mypage.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mis.nbcc.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"misterson.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mixr.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100004439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mkontakt.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100004440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mktf.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmogollon.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mncarteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobile.illumetechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modelhouseturkey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modernmanna.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"monetization.business"; content:"Host"; http_header; classtype:trojan-activity; sid:100004447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moninediy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mopai.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"motorcomunicacion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"msacontabil.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mtspsmjeli.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"muzimbiti.xigubo.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mxpiqw.am.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mydatebook.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymlql.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myritz.vettickal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myscape.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysura.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"namnyak.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nap.mgsservers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"navayurveda.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nbs.vizzhost.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nec-i.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nelitrianggraeni.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nerve.untergrund.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nettube.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"networkwheels.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neuromedic.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neverseenshop.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newinfinitysynergy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"news.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtreedesign.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtrendeg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newvisionopticallab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newxing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nextdigitalday.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ngdaycare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nguyenkekhuyen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nhorangtreem.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nicolas.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nidhi.iexist.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nikanpolimer.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilehouse.co.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilinkeji.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nisacooks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"njtiledesigncenter.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nobius.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocalnoodle.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nomadicbees.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nonnarina.ax"; content:"Host"; http_header; classtype:trojan-activity; sid:100004491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"notamuzikaletleri.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ns1.the-widyantos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsb.org.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsheldon.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuthuassociates.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuwagi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyeh2o.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oakleyandfriends.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"obseques-conseils.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ocean.tecnasulstore.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohe.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100004502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohsewgorgeous.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oknoplastik.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oleholeh.memangbeda.website"; content:"Host"; http_header; classtype:trojan-activity; sid:100004505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"olirecords.mixture.ltd"; content:"Host"; http_header; classtype:trojan-activity; sid:100004506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"olooom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaromatic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omega.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100004510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oms.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omscoc.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedigitalcard.granvizionnecorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedrive.listifyapp.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.creedglobal.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinestatis.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ont.proman.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"open.warehousesaas.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opolis.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opticaoptigral.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optimus.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004521; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optitechsa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"order.bizpeed.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orientgatewayltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orion445.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orpod.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oserve.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ottimade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ourteam.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ozemag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p1.lingpao8.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p3.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p6.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pablobrothel.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacificgroup.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100004535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacwebdesigns.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pagos.krayem.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"palochusvet.szm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parallel.rockvideos.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100004539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parejasfelices.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parkhussion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pastorpaulocosta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.51lg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch3.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paths.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paulmercier.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payerrealty.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payments.atifsiddiqui.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100004549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pcsoori.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pd.oceaniarp.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpus.onlineman7-jombang.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpustekim.untirta.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"petercollie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ph4s.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phasdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phenhuong.sanpham.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100004557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phittc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photo360.kubooking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004559; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photographytipsclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004560; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pink99.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004561; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pizzabarletta.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"plasfan.ind.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pmglance.startwriteup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pokojewewladyslawowie.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pole.com.vc"; content:"Host"; http_header; classtype:trojan-activity; sid:100004566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pool.phxdir.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004567; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pooltablemoversdenver.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"posmicrosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"poulman.panagiotopoulos-tours.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ppdb.smk-ciptaskill.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pptvideotemplates.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004572; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestigehomeautomation.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prishaartcreations.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"production.sparshims.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"programaoperadoronline.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"project.exquitec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promotoradescomplica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promoversdubai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosoc.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosyarmakassar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"provence.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prueba.danielluza.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ptpmeccatronica.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pujashoppe.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punchdialogues.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punjabdevelopersassociation.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"purefoe.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100004590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pvcprinting.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qadir.tickfa.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qatarglobalconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qmsled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"quartier-midi.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100004595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"querocar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rachmat-assuhaimi.my.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rainbowisp.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raodigitalmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rarlabarchiver.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100004600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rasadbar.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rashika.ascarvalho.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ratemyfenancialadvisor.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ravenproductionsltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rc.ixiaoyang.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rcmesilva.charbelsales.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"readymmade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redchillicrackers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reifenquick.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"relaxindulge.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"renehavis.com.ua"; content:"Host"; http_header; classtype:trojan-activity; sid:100004611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"repatriacioncolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"res.uf1.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.digimitra.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"resuco.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rezkabum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rhema.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richancyber.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richmondminerals.co.zm"; content:"Host"; http_header; classtype:trojan-activity; sid:100004619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinaefoundation.org.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinkaisystem-ht.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"riverfox.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkcable.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkverify.securestudies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roadfurylifts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertmcardle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertsinclair.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robinhood-sports.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"romanianpoints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ronnietucker.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roomsvc.servegate.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshan.academy"; content:"Host"; http_header; classtype:trojan-activity; sid:100004632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshnijewellery.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rs-toolkit.mikestclair.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rsgym.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubazar.pro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubycityvietnam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruch.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruisgood.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruwadalkuwait.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rydchile.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rzminc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.51shijuan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.thechinesemuslim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sacredscentsonline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safcol-colors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safehubsecurity.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safety.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sahathaikasetpan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"saisoftwareinc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salecorner.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sandovalgraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"santyago.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sarakem.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sasystemsuk.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"savasaachi.systems"; content:"Host"; http_header; classtype:trojan-activity; sid:100004656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scarfaceindustries.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scglobal.co.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schalke04rss.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scheff.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schoolbustracker.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sec-doc-w.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-doc-reader.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"segalsmetals.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sellmyphonela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"selltechtoday.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"senbiaojita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sentierodelviandante.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100004668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serendibsourcing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"seyranikenger.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgessy.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shaheentbfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahikhana.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharkrigs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharpelevators.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shembefoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shivakunwar.com.np"; content:"Host"; http_header; classtype:trojan-activity; sid:100004679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shoblasaathitrust.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shooka-co.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shop.goldspot.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100004682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shopsofe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shrushtiinfotech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sibernetix.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siddharthpanditpautra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sige.brisainformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"signatureads.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siili.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simoneporzi.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simplithy.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindicato1ucm.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindpol.tiejuris.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sinergidwireka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sipahielektrik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siperb.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sistelligent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skkksolo.beweiretail.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyflyfares.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyscan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarthouseforum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarts.tj"; content:"Host"; http_header; classtype:trojan-activity; sid:100004702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartzedu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokeandgrowrichtour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokesolutionindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobethuacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.110route.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.officelabo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sohs.conceptechs.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solar.amazingtribe.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solo2.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somcorbera.cat"; content:"Host"; http_header; classtype:trojan-activity; sid:100004712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somir.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soralapps.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sorteio.orgaostalita.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sota-france.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sowingminerals.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"space.proactint.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spaceframe.mobi.space-frame.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"special-key.cf"; content:"Host"; http_header; classtype:trojan-activity; sid:100004720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spent.com.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spetsesyachtcharter.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spititourism.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spittinfire.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sports-net.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"src1.minibai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sreenivasapaintingworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sriglobalit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srvmanos.no-ip.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ss.monita.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"staging.apparelpunch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"starcountry.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"static.3001.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statsres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statssound.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statsspot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stattilion.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiepancasetia.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stott-thompson.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stratexec.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"streetdemo.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"suboldesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sumerians.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunbrero.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunmarkholidays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supermercadostia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-4-free.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support.clz.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sw.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweaty.dk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweet-diet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swentsai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swiftlogisticseg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swwbia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"syedpro.dezinetimes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"syracusecoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sys.pbmadu.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sytraders.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.honker.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.netcatkit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tacticohosting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tadoo.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tafsantoursandtravels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tallyinvoicecustomization.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taltus.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tapalkoedacoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tarravalleyfoods.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taurus.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taxicabsrilanka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taxpos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tc.snpsresidential.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004771; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tcy.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004772; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tdsp.yngw518.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004773; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"techgms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004774; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"technogreen.crmmanivela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004775; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"technohub.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004776; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tecnicaencolectores.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004777; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tecnologyschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004778; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teduae.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004779; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teleargentina.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004780; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telescopelms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004781; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telmed.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004782; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"temptmag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004783; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tentandoserfitness.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004784; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.adventser.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004785; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.letraele.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004786; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004787; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.wanepghana.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004788; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.milenial.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004789; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004790; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.basis-web.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004791; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.marrenconstruction.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100004792; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.clickitsolutionsmw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004793; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.thinkingcorp.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004794; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testnew.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004795; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teteaffiche.stephanebillon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004796; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tewoerd.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004797; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"textile.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004798; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"texturesbyvinita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004799; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tharringtonsponsorship.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004800; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecleaningladiespdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004801; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecreativecafe.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004802; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefuturelife.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004803; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehighlightinterior.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004804; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehouseofpragya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004805; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thekassia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004806; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thelaunchpadteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004807; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thesummitpc.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004808; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theurbantutors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004809; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thosewebbs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004810; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tianangdep.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004811; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickfood.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004812; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickjobs.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004813; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickmart.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004814; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"timegonebuy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004815; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tksb.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004816; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tlcc.com.gt"; content:"Host"; http_header; classtype:trojan-activity; sid:100004817; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"todoapp.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004818; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonydong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004819; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonyzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004820; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tooba.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004821; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topcell9.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004822; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topicsnepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004823; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toplevel.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004824; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"torresquinterocorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004825; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"towme.services"; content:"Host"; http_header; classtype:trojan-activity; sid:100004826; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toyotacollege.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004827; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpef.lsoftdemo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004828; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpke.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004829; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tradezone.ejuicysolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004830; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"translaterjemah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004831; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"travelwithmanta.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004832; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trezors.io.mahlongwa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004833; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"triplonet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004834; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"troki.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004835; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tropics.codeleek.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004836; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trucks.softwarenecessities.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004837; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trudelfavreau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004838; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsd.jxwan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004839; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tulli.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004840; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tupperware.michaelroberge.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004841; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"turanggaresources.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004842; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uat.indianfilmzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004843; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ublretailerdemo.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004844; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uc-56.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004845; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"udesk.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004846; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ugprs-ubih.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004847; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ultimate-24.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004848; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"umwelt-kirchhof.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004849; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unicorpbrunei.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004850; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uniengrisb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004851; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unisoftcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004852; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unyazitelecom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004853; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"upcbpta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004854; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"urbane.dezinetimes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004855; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"useformoney.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004856; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"usmadetshirts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004857; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uss.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004858; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uzzepay.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004859; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vbcargo.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004860; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vcah.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004861; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vegadelcasero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004862; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vendas.lidiacarmeli.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004863; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"verify.aicosoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004864; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vfocus.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004865; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vidmattic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004866; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vienen.gblix.srv.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004867; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villamarand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004868; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villatera.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004869; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"violinstop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004870; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viraltalking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004871; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visions.alnisamart.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004872; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visualhome.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004873; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vitoriamodaintima.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004874; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vivationdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004875; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viveirodoiscorregos.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004876; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vksales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004877; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vladimirinternational.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004878; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vokasi.ub.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004879; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vologroup.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004880; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"voteyouramerica.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004881; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vstsample.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004882; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vtube.fadlymotivator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004883; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvsskmodinationalschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004884; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepliberia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004885; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepniger.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004886; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weareactum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004887; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.eng.ubu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004888; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geetle.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100004889; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geomegasoft.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004890; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.newinnovationtechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004891; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.smarts-works.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004892; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004893; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webgis.perumdasolo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004894; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100004895; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webpresario.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004896; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"website-work.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004897; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weinsteincounseling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004898; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wexfashion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004899; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whcms.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004900; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteglovetailgate.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004901; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteresponse.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004902; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wi522012.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004903; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wikalen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004904; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildnights.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004905; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildtrust.mediadevstaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004906; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wimbamusica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004907; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"windcomtechnologies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004908; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wishesconcierge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004909; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woezon.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100004910; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wolfgang-brodte.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004911; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woodsytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004912; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wordpress.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004913; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wozata.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004914; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wp.readhere.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004915; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wpdemo.101clients.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004916; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"writtendeer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004917; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ws5588.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004918; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wyklej.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004919; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"x2vn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004920; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xia.beihaixue.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004921; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xixaoclothing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004922; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xk.996is.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004923; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--80akinnkiib6h.xn--90ais"; content:"Host"; http_header; classtype:trojan-activity; sid:100004924; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--polimerbizmimarlk-rvc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004925; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ybom.urbanolab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004926; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yeichner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004927; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ylfpremium.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004928; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yoast.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004929; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yourtopdog.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004930; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"youtubetrainingacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004931; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yp.hnggzyjy.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004932; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yskadvisors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004933; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yummyyogaudaipur.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004934; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yzkzixun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004935; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zakra.tecnasulstore.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004936; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004937; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zz.690tx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004938; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; http_uri; nocase; content:"amumufree.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004939; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/files/proxyi.exe"; http_uri; nocase; content:"analogx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004940; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004941; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/densjons/bro/downloads/rew.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004942; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dvdfv/anjj/downloads/jami.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004943; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/4.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004944; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/6.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004945; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004946; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr3.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004947; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/instaler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004948; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/installer.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004949; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatej.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004950; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatev.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004951; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/work.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004952; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/component.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004953; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004954; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/regsvc.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004955; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/skygaming/updates/downloads/update.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004956; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/001.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004957; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1488.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004958; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1_cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004959; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004960; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1fc2d.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004961; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/26a5.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004962; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004963; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/abjects.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004964; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/attached.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004965; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/b7f2c.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004966; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/battletext.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004967; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004968; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004969; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004970; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_makros.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004971; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_silent.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004972; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_sup.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004973; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004974; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004975; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004976; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildss.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004977; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientnik.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004978; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientrevers.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004979; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dcrat.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004980; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004981; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004982; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004983; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hans.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004984; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hulu.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004985; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfive.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004986; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfour.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004987; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelone.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004988; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelthree.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004989; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/inteltwo.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004990; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004991; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/kleiman.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004992; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004993; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/notepadplus.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004994; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004995; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004996; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004997; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004998; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/putty.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004999; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/rockethcd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005000; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/scvhost900.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005001; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/sessionwin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005002; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/siliculose.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005003; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/statemobi.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005004; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005005; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005006; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stgedo.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005007; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/svcperf.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005008; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005009; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurjok.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005010; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurusbabac.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/telekiller.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005012; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateanddr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005013; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateandr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005014; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/vhajeja.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005015; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/word.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/www.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/xlsd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005018; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005019; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hmatrix/data/hack1226.exe"; http_uri; nocase; content:"cd.textfiles.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/816070119281131570/816070273254162442/all.txt"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/razor/rzr-winner_intro.zip"; http_uri; nocase; content:"chiptune.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/meteoradminz/hidden-tear/zip/master"; http_uri; nocase; content:"codeload.github.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; http_uri; nocase; content:"colfincas.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qz0h69.pdf"; http_uri; nocase; content:"deepfreedom.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=11jnyjpzkjiie_rzc4xwa2feok3x__yvc"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005031; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=151uxflny3vqh_lmghrkgjhhsqxi163sh"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005032; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=15iwonkjkhyvri_okkc_llq56aasvnvb9"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005033; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=16gqndqbduwuhy3qzxdn2nd9nufm_9ctq"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005034; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1ak46tqftzejmq-og_ky2oupgpmkgujtm"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005035; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1b6stzilakqykxaw1ct2w9hzccizwotff"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005036; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1brsmnj6g0lxa44ixkypvg5tcxkvi5gjt"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005037; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1by_s4vv8gdmmz8wl-lbpjbjy5adcrjk1"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005038; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1dpsxfbptpyl-zegto9t29vvcku2rjm9u"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005039; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1dwb7nww_ahtjfeed-afxl4hvm_xqkx-h"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005040; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1e7t_hnuohxuziwcxihocdievcj5_dsgj"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005041; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1erajjbz6gdxhsvvorlykzxyeoq-xu7wn"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005042; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1ev7gkzwjgtv2vlbbisg1ragd7nf0-xog"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005043; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1ey8zl85vszh-gdmubkoudacqs6zv2dup"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005044; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1f5trx90ulgsd-m1zvdupuf_kfugoo9ye"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005045; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1gq_jf503du9oip5bwzcoi6_kgolr3kx2"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005046; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1hlaoow8ug5gjejeeihwetcxyfjodcdut"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005047; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1imrv00kqbfz4ljzwq5qdau1to0zlmaqy"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005048; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1j6pvg1rznjh9pkldcyjiogo8ysiyl8_y"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005049; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1jlcqojhfhgifmirrsv0o5t-2rl-hblai"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005050; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1jvvuxwek4wrjqs94bjm8_klnnngj7b5r"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005051; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1k6sh5h-nptesem_jsnuxmhzntnvdlgxz"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005052; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1lc8lpsmu5ndjweyusqrxblm0g84sdcc7"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005053; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1lk6n-xrtv0dvdqljl26pzebxzp8tladk"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005054; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1lkcqgpimry4yp8grinnhsotnawquozcz"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005055; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1m34mp1cggxz-cz3a5ipjrgfog_qx8myx"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005056; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1m6kdawqt1fwxea6epcae6t1qevfhl0-5"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005057; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1m8w1y1-mxxa2pktrzkwfetwjxrlw1alo"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005058; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1m9jxzqcbnb8j8uph1qfcas8b9pngcogj"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005059; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1mdnlxs6vy5qk-u4dxz9movem4j3a3o-8"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005060; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1o6omlk34dxy3cbai8rvkvrnp5g-ovsj-"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005061; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1od6gtslxvylgyeujmrbvm9yhupmq_1lv"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1ozpasp-mr-e-ui4lshy4qy4a2pl8pxsi"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1pnmkgw-rlm9mjstqdxfcq0en07_x93ue"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005064; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1q0edpjr7vgo_ytns7dgjcav6317juz9y"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005065; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1q5gqeinogsri3i-ynlgvu88ajqnn9siq"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1quyiobd7-d-vcddlhxiqbqrwxyg7ongo"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1qyzpbxbnmnbp5opdk5rmeplmbga9c_q9"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1rrtyvouwizor2icbcoywdid4w9rwngxi"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1sao6yxf-a0t6wdgdr36srwlju57vigx_"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1sbg8kdmxp5futgje5jcfvh-ieq28holg"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1seb4h5c8z5jaf2_ulvhdv7mzqzmntp0k"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1skuwjvkgsmicbr1o48gnalcksfytwtdp"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1st5mtgqyofsskuhlomfihfmz_qx-i32o"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1umz5zjobot9__v2jxdutyborb2az90hz"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1we-h5qtxj9czhkhzvzg0qqpxufgu_v__"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1wmi0gpfe9ebcgai4w6iw6pninxo6ke-m"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1wurpipyf0s__fqtn1ov619nx7v1-tcy3"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1wwkqbfluu4qusqz26ewulr48zh9vzq-w"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1xbvceq1wmfjad59zyxwtykzy3xwy9iqb"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1xqcnagjbut3pdajnpsx0nonhla3nqes-"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1xsj8d2ysnoluawhk3g4tadaoyp8ktmab"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1xtflvdimom8odrygcmip7j4aesrjtgsm"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1yyuejm8cerrq2tctsibww4uetepcmh4i"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; http_uri; nocase; content:"drive.google.com.it-barcelona.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/1zilg/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/qcgfmfvh/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/emclick.zip"; http_uri; nocase; content:"e-mudhra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100005114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100005115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/x/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005122; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; http_uri; nocase; content:"file.elecfans.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005123; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005124; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005125; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; http_uri; nocase; content:"gist.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005126; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; http_uri; nocase; content:"hqdecig.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/suy/"; http_uri; nocase; content:"hsecaravans.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100005128; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/19/items/startup_20210219/startup.txt"; http_uri; nocase; content:"ia801802.us.archive.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005129; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online-timer-kvhxz/ilxl/"; http_uri; nocase; content:"ie-best.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100005130; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100005131; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100005132; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ebook/cs17.exe"; http_uri; nocase; content:"jcedu.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005133; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005134; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005135; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/jl01o54yy09qrzg/fac215.tgz/file"; http_uri; nocase; content:"justlficante.mediafire.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; http_uri; nocase; content:"karmakoincodes.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dg/etrac/nf4emwz/"; http_uri; nocase; content:"kotakwarna.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100005139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; http_uri; nocase; content:"ksh.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100005140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/down/affiliate/kuaizip_setup_10029.exe"; http_uri; nocase; content:"kuaizip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/linuxforensicscode.zip"; http_uri; nocase; content:"linuxforensicsbook.com.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/k/big5/1giof6/"; http_uri; nocase; content:"minpic.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100005143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-contentbak/t9m/"; http_uri; nocase; content:"morrobaydrugandgift.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; http_uri; nocase; content:"my.cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/aacenc.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100005146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/doxillionsetup.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100005147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/4/1/6/6/4166984/keygen.exe"; http_uri; nocase; content:"newyarlfm.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; http_uri; nocase; content:"nhipcauytevietnhat.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; http_uri; nocase; content:"note.youdao.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; http_uri; nocase; content:"oldschoolvalue.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005155; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005173; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005178; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005179; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005180; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005181; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005182; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005183; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005205; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!296&authkey=adsdrrjllbu1nwa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!297&authkey=am7nspchat4aqtw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21296&authkey=adsdrrjllbu1nwa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!210&authkey=agpl0pgvft8faaa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=80dabacd46496407&resid=80dabacd46496407%21124&authkey=abnj7t59iwijpdy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005521; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005559; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005560; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005561; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005567; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005572; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1045&authkey=aetgoeo_eku-6ba"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211045&authkey=aetgoeo_eku-6ba"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21122&authkey=ajqq2okqxfq8iuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774!124&authkey=afq42wqejwvcv8o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774%21124&authkey=afq42wqejwvcv8o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4a3bd996f92bf71&resid=e4a3bd996f92bf71%211944&authkey=ao3lztaialsza88"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f8d2350982acb14f&resid=f8d2350982acb14f%21140&authkey=ajo86idqg2jvzfq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!196&authkey=amm2av5ubkbhoru"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!197&authkey=apnt4trskzjga_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21196&authkey=amm2av5ubkbhoru"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21197&authkey=apnt4trskzjga_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/yqvsvlvq"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/llc/mwcacs65xienqdp/"; http_uri; nocase; content:"pierreconsulting.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100005733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; http_uri; nocase; content:"pioneiraagronegocio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100005734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skoda22.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; http_uri; nocase; content:"qjbutterflyevents.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100005737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/maersk-bl+draft-copy-shipping-documents.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/purchasing+ordersigned+contractinv-30067121.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/myqseeaccount/one/main/one.htm"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tennc/webshell/master/other/small_shell.txt"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; http_uri; nocase; content:"res.yeshen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/q05z91"; http_uri; nocase; content:"sendspace.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a-nurse-ss8d9/z/"; http_uri; nocase; content:"technologydistilled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/databases/merit.php"; http_uri; nocase; content:"truemerit.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100005766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/23.exe"; http_uri; nocase; content:"tsrv4.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100005767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/crisanar/defis/jek_crackme1.7.zip"; http_uri; nocase; content:"users.skynet.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100005768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/amowvegfrt9ja/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100005769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100005770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100005771; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100005772; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005773; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb%5efr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005774; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb^fr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005775; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005776; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/151_155/tidex_-_short_stuff.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005777; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/syria-files/attach/222/222051_instruction.zip"; http_uri; nocase; content:"wikileaks.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005778; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.46.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.48.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.231.95.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100003209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.232.102.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.232.46.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.233.159.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100003212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.233.78.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.234.247.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100003214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.234.85.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100003215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.23.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.67.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.82.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.87.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100003219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.90.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.95.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.148.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.237.142.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100003223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.237.24.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.237.252.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.237.60.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100003226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.238.228.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100003227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.155.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100003228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.202.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.21.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.218.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.98.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100003232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.242.200.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100003233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.56.15.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.61.99.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100003235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.84.37.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.87.29.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.230.156.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.241.106.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.252.8.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.203.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.135.134.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100003245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100003247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.141.84.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100003250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.165.215.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100003256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.110.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.178.101.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.179.171.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.22.209.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.23.22.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.231.210.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.27.253.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.33.112.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.51.104.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.81.235.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.9.148.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.151.155.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.161.185.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100003277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.172.75.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.175.184.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.182.173.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.20.63.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.21.153.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.214.27.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.24.130.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.243.179.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100003286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.25.242.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100003287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.118.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100003288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.86.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.97.76.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.145.152.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.151.23.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.157.97.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.16.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.197.0.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.21.202.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.46.231.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.162.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100003298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.87.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.143.32.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.143.43.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.158.201.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.20.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.21.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.174.182.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.170.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.178.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.179.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.68.221.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.68.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.70.15.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.70.95.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100003312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.146.202.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.181.135.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.2.70.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.42.37.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100003316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.53.146.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.8.10.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.121.91.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.252.47.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.171.146.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100003322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.222.56.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.114.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.180.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.114.246.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.108.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.162.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100003328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.174.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.125.191.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.126.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.141.122.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.166.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100003333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.200.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.143.142.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.143.189.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.18.103.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.19.249.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.218.67.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100003339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.22.212.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100003340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.226.129.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.23.245.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100003342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.230.89.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.238.42.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.240.147.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100003345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.57.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.78.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.243.126.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.112.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.117.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100003350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.142.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.143.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100003352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.144.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100003353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.147.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.151.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.153.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100003356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.74.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100003357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.77.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.12.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100003359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.14.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100003360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.16.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100003361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.19.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.72.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.74.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.74.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100003365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.75.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.77.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.80.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100003368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.82.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.87.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.89.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100003371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.252.176.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.255.133.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.255.140.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100003374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.48.154.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.50.221.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100003378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.76.151.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100003379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.76.151.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.97.206.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.0.211.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.102.168.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100003383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.127.11.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.202.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.214.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.246.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.29.133.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100003388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.45.235.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100003389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.58.104.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.58.117.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.7.124.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.8.35.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.180.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100003394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.217.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.94.180.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100003396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.96.37.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100003397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.96.37.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.96.39.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100003399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.193.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.13.61.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100003401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.14.48.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.16.247.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100003403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.162.122.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.164.130.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.176.249.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.184.149.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.20.217.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.208.135.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.122.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.186.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.216.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.233.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.33.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.19.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.6.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.111.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100003418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.162.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100003419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.202.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.206.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.218.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.220.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100003423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.254.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100003425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.162.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.58.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.83.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.214.217.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.214.32.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100003430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.214.73.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100003431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.214.93.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.165.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.195.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100003434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.207.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.4.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100003436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.177.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.86.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.223.84.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.25.109.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100003440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.25.115.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100003441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.25.76.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100003442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.15.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100003443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.4.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.42.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.51.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.26.17.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.10.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.8.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.99.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.102.243.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.130.195.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.162.169.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.162.55.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.163.142.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.164.96.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.171.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100003459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.192.73.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100003460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.213.118.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100003461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.247.224.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.253.94.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100003463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.124.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.151.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.47.220.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.103.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.103.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100003468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.109.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100003469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.11.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.159.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.167.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.195.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.210.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100003474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.211.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.212.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.214.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.234.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100003478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.237.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100003479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.242.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.30.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.4.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.42.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.48.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.76.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.9.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.9.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.98.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.99.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.102.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.117.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.119.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.122.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.123.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.192.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.201.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.103.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.168.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.232.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100003499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.40.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.58.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100003501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.64.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100003502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.180.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.181.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100003504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.57.96.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100003505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.170.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.73.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.61.218.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.65.172.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.0.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.104.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.110.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100003513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100003514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.255.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.45.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.98.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.1.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.117.124.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.141.73.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.131.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100003521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003522; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.155.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.227.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.31.126.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.43.207.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.90.165.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"63.245.122.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"64.233.154.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.125.128.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.21.58.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.26.155.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.35.61.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.153.233.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.229.214.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.57.55.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.74.7.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100003539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.91.21.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.245.151.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.3.169.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100003544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.8.138.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100003545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.81.98.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100003546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.83.49.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.84.138.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.151.244.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.174.182.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.175.107.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.183.25.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.188.144.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.204.88.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.106.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.119.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100003556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.78.33.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68468438438.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.115.37.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100003559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.120.237.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003560; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.123.245.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003561; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.124.231.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100003562; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.127.214.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.146.232.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.165.173.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.196.158.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.222.157.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.229.0.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003568; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.63.73.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.115.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.227.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.76.240.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100003572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.115.31.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100003573; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.118.240.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.167.10.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.236.190.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.25.5.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100003577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.93.129.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.127.148.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100003579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.146.190.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100003580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.167.164.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100003581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.204.63.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100003582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.29.48.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.34.191.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.40.234.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.106.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.2.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.235.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100003588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.47.133.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.71.60.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100003590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.85.106.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100003591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.17.22.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100003592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.186.139.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.180.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.200.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.214.69.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.230.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.35.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.31.40.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.204.216.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100003600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.101.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.108.224.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.116.216.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100003603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.194.117.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.195.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100003605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.199.84.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.64.139.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100003607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.75.165.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.127.141.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.83.102.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.99.213.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.108.199.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.170.11.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.178.22.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100003614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.250.199.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.254.129.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.84.134.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.95.12.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.237.25.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.50.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.52.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.79.191.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.89.203.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100003623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.94.89.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100003624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.186.155.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.141.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.240.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.41.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.168.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.188.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100003630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.104.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100003631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.176.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.23.172.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.8.225.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.11.195.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.13.49.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.130.253.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100003637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.147.123.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100003638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.170.31.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.175.42.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.21.84.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.7.170.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.79.58.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.8.70.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.9.88.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.107.89.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100003646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.19.101.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.211.181.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.217.12.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100003649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.67.32.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.99.128.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.136.146.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.165.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.191.40.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.111.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.141.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100003656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.215.199.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.187.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100003658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.195.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100003659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.237.128.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.246.225.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.92.36.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.103.108.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.135.196.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.212.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100003665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.85.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.207.61.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.209.250.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100003668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.211.156.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.110.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.53.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.138.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.139.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100003673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.154.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.187.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.100.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.108.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.131.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100003678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.19.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.197.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.215.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100003681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.232.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100003682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.234.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100003683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.28.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.4.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.55.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.73.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100003688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.9.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.165.237.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.147.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.218.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.242.253.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.252.9.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.212.219.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.50.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.95.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100003700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.238.24.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.247.83.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100003702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.254.39.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.33.111.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.40.127.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.42.20.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100003706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.11.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100003708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.123.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100003709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.135.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100003710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.208.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100003711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.224.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100003712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.241.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100003713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.214.149.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.64.181.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.74.215.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.130.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.195.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"86.35.43.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.61.89.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87du.vip"; content:"Host"; http_header; classtype:trojan-activity; sid:100003721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.119.171.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100003722; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.208.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003723; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.219.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003724; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.225.222.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003725; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.247.96.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003726; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.136.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003727; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.51.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003728; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.249.244.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003729; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.204.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100003730; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.226.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003731; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.254.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100003732; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.122.183.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003733; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.29.213.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003734; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.35.62.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003735; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.85.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003736; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.87.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003737; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.46.237.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100003738; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8poieq.bn.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003739; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"90.152.144.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003740; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"90.63.176.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003741; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.177.139.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100003742; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.187.103.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003743; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.212.150.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100003744; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.217.104.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003745; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.233.112.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003746; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.234.60.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003747; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.239.168.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003748; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.244.169.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003749; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.92.16.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003750; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.98.4.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100003751; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.113.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003752; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.114.191.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003753; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.241.78.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003754; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.27.246.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003755; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.54.237.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003756; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.83.62.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003757; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.85.18.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100003758; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.171.157.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100003759; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.21.224.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003760; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100003761; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.137.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003762; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.182.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100003763; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.206.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003764; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.57.43.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003765; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.73.99.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003766; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.136.69.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100003767; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.143.53.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003768; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.17.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100003769; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.82.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100003770; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.200.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003771; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.224.83.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003772; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.53.120.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003773; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.132.129.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003774; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.153.241.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003775; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.154.20.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003776; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.158.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003777; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.113.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003778; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.113.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003779; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.201.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003780; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.181.155.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003781; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.146.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100003782; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.6.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003783; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.66.196.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003784; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.9.120.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003785; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.239.73.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003786; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.47.147.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003787; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.68.140.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003788; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.96.199.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003789; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.210.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003790; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.239.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003791; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.113.239.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100003792; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.116.72.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003793; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.128.147.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003794; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.178.242.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003795; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.249.236.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003796; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.28.200.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003797; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.30.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003798; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.150.245.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003799; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.33.195.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003800; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abcd.bg"; content:"Host"; http_header; classtype:trojan-activity; sid:100003801; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abclicks.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003802; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abissnet.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003803; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aboveandbelow.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003804; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absoftechworld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003805; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absupplies.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003806; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abyssos.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003807; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"academyshademani.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003808; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acbick.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003809; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts.thesmarttechhub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003810; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aceeprc.com.aceeprc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003811; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acellr.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003812; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aciabogados.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003813; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acteon.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003814; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"activateyourdiscount.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003815; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"activecost.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003816; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adamorinmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003817; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"addahealingmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003818; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003819; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.memengers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003820; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.erapor.smk-alasror.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003821; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.gentbcn.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003822; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.grandoceanvilla.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003823; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adventureexplorer.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003824; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aeropilates.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003825; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afrimedspecialist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003826; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agemn.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003827; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciadigitalwdys.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003828; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciatabletshouse.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003829; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenda.gmelloinformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003830; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agentt.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003831; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agile8studio.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003832; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agmcarpetcare.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003833; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiqtest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003834; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajpharmaholding.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003835; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajstudiollc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003836; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"akauk09.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100003837; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"akivj07.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100003838; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"akpgi08.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100003839; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"al-wahd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003840; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alasdemariposas.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003841; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alemelektronik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003842; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alena1971.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100003843; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alexdubai.com.aldiabsteel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003844; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"algreenstdykelveskbg.dns.army"; content:"Host"; http_header; classtype:trojan-activity; sid:100003845; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alka.institute"; content:"Host"; http_header; classtype:trojan-activity; sid:100003846; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"allforcreative.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003847; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alltheway.travel"; content:"Host"; http_header; classtype:trojan-activity; sid:100003848; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpaylar.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003849; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"am-concepts.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003850; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amamontajes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003851; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarresdeamorymaestroshechiceros.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003852; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarteargentina.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003853; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amenyan.zouri.jp"; content:"Host"; http_header; classtype:trojan-activity; sid:100003854; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amos524.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003855; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ams.alvinasschools.org.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100003856; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anantam.net.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003857; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreelapeyre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003858; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andremaraisbeleggings.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003859; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003860; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003861; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreshconcejal.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003862; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelazgheibld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003863; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelsdetour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003864; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angloteste.bigprime.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003865; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anhung1102.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003866; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anysbergbiltong.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003867; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apartamentoscitta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003868; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api-ms.cobainaja.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003869; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003870; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.quocbao.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003871; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.sampy.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100003872; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aplicativoparasindicato.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003873; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apoolcondo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003874; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.adsensearticle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003875; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.explicitsurveys.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003876; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.prerana.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003877; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apps.saintsoporte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003878; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aqv.news"; content:"Host"; http_header; classtype:trojan-activity; sid:100003879; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"areyoulivingwell.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003880; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"artedibujoyarquitectura.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003881; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ask-regard.call-save.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003882; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atfile.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003883; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"athenacapsg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003884; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atlasconcreteworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003885; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atnetech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003886; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"attach.66rpg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003887; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atteuqpotentialunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003888; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"augustair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003889; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aulist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003890; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"automaticrefreshments.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003891; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"avadhanagames.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003892; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayamallah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003893; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azmeasurement.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003894; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azraktours.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003895; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"b2b.toptanakaryakit.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003896; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"backgrounds.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003897; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"badeggdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003898; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"balealgodon.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003899; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangkok-orchids.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003900; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"barcionstw.eastus.cloudapp.azure.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003901; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bary.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003902; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bash.givemexyz.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003903; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"basma.com.kw"; content:"Host"; http_header; classtype:trojan-activity; sid:100003904; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003905; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bavhome.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003906; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003907; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcmt.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003908; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcrg.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003909; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bearcatpumps.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003910; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beautincollagen.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100003911; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bekape.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003912; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bespokeweddings.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100003913; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestcarenepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003914; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betone.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003915; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betycopaints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003916; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beveragesmiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003917; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bhavaniengineering.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003918; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bigbag.wootraining.certificacion.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003919; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilbosaquet.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003920; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilhen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003921; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing.rahitechnosoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003922; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"binoy.stalphonsamissionva.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003923; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birdi.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003924; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birminghamlink.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003925; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.callensaxen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003926; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.oyinblogs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003927; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.takbelit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003928; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bmlifestyle.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003929; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bnrnews.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003930; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bodenstein.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003931; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"booksearch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003932; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bounces.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003933; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bpo.correct.go.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003934; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bradleyinstitute.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003935; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brandtrust.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003936; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brendanquine.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003937; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brideofmessiah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003938; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bridesofmaldives.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003939; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightmega.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003940; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightonrooms.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003941; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightstarshop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003942; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"browardinsurancemiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003943; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bt2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003944; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"btdapi.robotake.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003945; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buigiaphat.com.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003946; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bullseyemedia.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003947; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"busandvanrentalmalaysia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003948; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buscascolegios.diit.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003949; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003950; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buyingmusiconline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003951; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bwsr.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003952; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c.oooooooooo.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100003953; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c0140529.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003954; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"caballo.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003955; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"calgaryautorepairservice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003956; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"callbury.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003957; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"camminachetipassa.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100003958; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"campusvirtual.cepsanjuanbosco.net.pe"; content:"Host"; http_header; classtype:trojan-activity; sid:100003959; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cancer.educandome.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003960; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalgroup-kw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003961; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalnewsagency.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003962; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capoeiraventrelivre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003963; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cashyinvestment.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003964; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchpoolshetlands.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003965; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cazyacustomfurniture.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003966; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ccauthority.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003967; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cdaonline.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003968; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cec.asso.ac-amiens.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003969; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cecra.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003970; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cellas.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003971; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cendekiabinaaksara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003972; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cespol-bote.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003973; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cfs5.tistory.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003974; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.rmu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003975; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"changematterscounselling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003976; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chardhamdodham.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003977; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chezalice.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003978; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"childselect.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003979; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003980; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003981; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cible-energy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003982; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cifeer.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003983; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citycapproperty.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003984; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cityglobalgospel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003985; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"civi.istmejia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003986; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cleanbydesignllc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003987; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cloud.fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003988; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"codsambal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003989; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colinde.pricesne.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003990; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colorpak.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003991; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"competancy.indigoconsult.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003992; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"config.cqhbkjzx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003993; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"constructoralyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003994; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"consulateins.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003995; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"contributeindustry.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003996; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"controleautomacao.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003997; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"copelandscapes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003998; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"coulsongraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003999; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"covid19.cyberschool.or.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004000; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-sq.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004001; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"craftnesia.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004002; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"creationskateboards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004003; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crecerco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004004; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crittersbythebay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004005; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crm.notariavieitoyvelamazan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004006; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crscorretordeimoveis.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004007; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cse-engineer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004008; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"csnserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004009; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubescargoexpress.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004010; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubrebocasenpuebla.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004011; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"curasoles.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"currantmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004013; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cwa.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004014; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyber.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004015; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyclomove.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004016; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cynkon.kairoscs.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czas.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czsl.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004019; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d.powerofwish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004020; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d9.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"da.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"damagedessentialtelecommunications.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dandyair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dartoonpictures.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.cdevelop.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.over-blog-kiwi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datapolish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dating.khokhas.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datsom.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"daunhotq10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davethompson.me.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004032; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davidmcguinness.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004033; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dayspringdaisies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004034; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dd.qiyuea.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004035; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"de.gsearch.com.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004036; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"decifrar.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004037; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"deigratia2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004038; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dekovizyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004039; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo-cliente.mindcreative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004040; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo6.hiites.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004041; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dent-estet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004042; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dental.xiaoxiao.media"; content:"Host"; http_header; classtype:trojan-activity; sid:100004043; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dentalalliance.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100004044; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"designerliving.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004045; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"desiringhands.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004046; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"despertaresi.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004047; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"destinymc.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004048; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"detorre.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004049; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev-interestingtech.pantheonsite.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004050; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.sebpo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004051; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dezcom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004052; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfcf.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004053; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"diamantenegro.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004054; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dienmayminhhung.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004055; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digilib.dianhusada.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004056; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"djking.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004057; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl-link.link"; content:"Host"; http_header; classtype:trojan-activity; sid:100004058; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.1003b.56a.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004059; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004060; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.installcdn-aws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004061; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.packetstormsecurity.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004062; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.rina-roleplay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.zkytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dns.cyberium.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100004065; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dockerupdate.anondns.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004066; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"docman.orientalservices.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dodsonimaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dokan.blueberrytec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom-chel74.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom.daf.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doncedyhall.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donghobinhminh.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dongphuctop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donwnloasecury.ath.cx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosman.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dovberger.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.flash-plays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.pcclear.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.webbora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down1.arpun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.caihong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.doumaibiji.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.exrnybuf.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.kaobeitu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.pdf00.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.rising.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.skycn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.zjsyawqj.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"downloads.jxtsteel.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dragonsknot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drbaby.com.sa"; content:"Host"; http_header; classtype:trojan-activity; sid:100004093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drohnen.ensenanzainteligente.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drools-moved.46999.n3.nabble.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drsha.innovativesolutions.mobi"; content:"Host"; http_header; classtype:trojan-activity; sid:100004096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsenterprize.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsspainting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"du-wizards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duckrambo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duque.guantanameratravel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dutapp.wisolve.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duvalcharter.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dx.qqyewu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dzinestudio87.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-commerce.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebruyatkin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"econews.treegle.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"efficientegroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"en.baoend.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enc-tech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"endurotanzania.co.tz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ennovate.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enriquecendocomconsorcio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"envios.petpienso.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"equimination.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100004117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"escola.probommar.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"esnconsultants.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"essentia.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eubanks7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"evidencemarketing.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exilum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004123; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exitoalfaomega.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004124; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"extrovertoffers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004125; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"familydentist.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100004126; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"farmaciasdrogaminas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004127; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fate3.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"faveraprojects.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004129; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004130; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"felicienne.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004131; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fi.bonitastores.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004132; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files.martellexpress.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100004133; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"final.makkahkmcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004134; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fineartgallerym.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004135; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fixauto.illumetechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004136; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fkd.derpcity.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flintspin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flyingbuddhadesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fmjplastering.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fms.buladde.or.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foothills.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"footweardirect.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"forum.mdb.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fotoobjetivo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foxeps.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freecnetdownload.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freedombookshop.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freisites.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ftp.n3twork30cm.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100004150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fullelectronica.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"funletters.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fusionfiresolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gametwogame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garciadogshow.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004156; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow4.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gbbulls.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gcpc.co.id.chronoscurtain.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"generaldeviales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfmodd1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfold1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghettohub.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghislain.dartois.pagesperso-orange.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giadungg7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giddos.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100004166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"girotexuniformes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giteletropical.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"globaltask.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"glowinmedia.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmtransformationacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmvadmission.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnimelf.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnscrew.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004174; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gold.investforex.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcake.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcupmortgage.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004179; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"golden-memories-funerals.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004180; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldmen.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004181; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gracejukes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004182; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupoinmare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004183; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gruposelt.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004184; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gs.monerorx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gulfac-house.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gvpcdpgc.edu.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"habbotips.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hagebakken.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100004189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"harshraval.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hd11315.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdkamera2003.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdrest.fastlinktz.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hds.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"healthy20.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"heavymaq.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hellogorgeous.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"help.hizuko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"herchinfitout.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hhaward.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandroadcoc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandslasvegas.atakdev.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hindi.factsriver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hiptool.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitpe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004206; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitstation.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hmpmall.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoagietesting10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoayeuthuong-my.sharepoint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"homefindersolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hongluosi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hookedupboatclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostzaa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"houstonshutters.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100004215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hr2019.vrcom7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hseda.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsmwebapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"htownbars.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hubtech.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hunggiang.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"husamiyahschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iam313.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"icon.shatangmu.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idea-secure-login.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idilsoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idj.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100004227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idvindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iesanjosemonitos.edu.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ikexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ilrafrica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"imbueautoworx.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incodimsa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incrediblepixels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incredicole.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infair.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infovator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"innatosbrand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inodesthetotaldesigners.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inovations.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inrajahmundry.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"insignificantfinecore.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"instantindialoan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intellectsmart.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intersel-idf.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intuitiveideas.com.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inversiones.arrayanfinanciero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"invest.xpcorporative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"investinae.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ipmes.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100004250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iremart.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iris101.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isaac.mikhailmotoringschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iscamenabe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ismf.com.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100004255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iso-dubai.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"israrulhaq.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100004257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isrorg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isso.ps"; content:"Host"; http_header; classtype:trojan-activity; sid:100004259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"it123.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itc-demo.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itconsultus.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamiekaylive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamshed.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jansen-heesch.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jathra.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jay.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100004267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jebs.net.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeffdahlke.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jhayesconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jiaoyuzixun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jing-da.com.tw"; content:"Host"; http_header; classtype:trojan-activity; sid:100004272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jmcomputacion.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jmtc.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jnanbharati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jobs.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"joelbonissilver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"join.cl8movement.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josegene.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josuarochoa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jpwoodfordco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jumpmanualjacobhiller.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jupiter.toxsl.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"justinscott.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalawatihomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalpataru-elitus-mulund.thakkers.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"karer.by"; content:"Host"; http_header; classtype:trojan-activity; sid:100004287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"katanvetov.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100004288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kensingtondriving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kevinjewelry.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"keywatch.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kingssa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kjcpromo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kleinendeli.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"korrectconceptservices.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ktb.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kubatoglubaklava.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kumaralok.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kwanfromhongkong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kz.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lacasadelosalebrijes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ladylabonde.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lameguard.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laodongnhat.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laravel.pointersoftwares.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lasermobilesounds.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lauratomismith.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lautarosanmiguel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawforall.edu.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lceventos.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ld.mediaget.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ldgcorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"learning.real-academy.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leasiacherise.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leczkregoslup.acelero.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"legend.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leluibuffet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lestesteux.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"libantravel.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.arihantmbainstitute.ac.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.uib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lidoraggiodisole.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lifebeam.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lindnerelektroanlagen.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"linkintec.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"livetrack.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsindian.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lm.stagingarea.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmaancha.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100004329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.login2.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmvirtualbookkeeping.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lnt-rejuve-360.thakkers.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"location-voitures.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100004334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.trezor.com.stockfootagesindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"logotypfabriken.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100004336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotix.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotusanddragonfly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.definerisco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ltc.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luckybrownie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luminouspneuma.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luxomodels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m-technics.kz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.estudiomoros.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"madicon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"magianegramagiablancayamarres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.bs-eiendomme.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.golimoapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.jeffsono.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maksi.feb.unib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malaya.tv"; content:"Host"; http_header; classtype:trojan-activity; sid:100004353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malwarecoding.github.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managed.oss-cn-beijing.aliyuncs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managemysalon.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manantialesdelnorte.uy"; content:"Host"; http_header; classtype:trojan-activity; sid:100004357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manhtien.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marcapinyo.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mario-sunjic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariobrown.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariotessarollo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketinfosales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketing.enexusgroup.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marksidfgs.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"masjidhabeebiyarazviya.mysunni.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"materialescantu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"matruchhaya.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mattysplayground.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxiquim.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxtox.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbgrm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbsolutions.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100004373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mdasa.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medevlb.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"media-server.skyinternet.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mediamaster.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medianews.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100004378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medistaffconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meditreat.itwebservice.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meeweb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megamart.afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merbay.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merkathink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mertlog.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"metalin-cr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mettaanand.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meuoculosnanet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mfevr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"micalle.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michaelphilip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michimal2.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microblading.mirliandias.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microcomm-group.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mikhailmotoringschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mindfulbuildingandliving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mingguanwms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"minuevavida.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mirror.mypage.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mis.nbcc.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"misterson.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mixr.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100004404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mkontakt.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100004405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mktf.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmogollon.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mncarteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobile.illumetechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modelhouseturkey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modernmanna.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"monetization.business"; content:"Host"; http_header; classtype:trojan-activity; sid:100004412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moninediy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mopai.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"motorcomunicacion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"msacontabil.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mtspsmjeli.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"muzimbiti.xigubo.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mxpiqw.am.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mydatebook.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymlql.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myritz.vettickal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myscape.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysura.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"namnyak.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nap.mgsservers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"navayurveda.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nbs.vizzhost.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nec-i.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nelitrianggraeni.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nerve.untergrund.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nettube.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"networkwheels.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neuromedic.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neverseenshop.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newinfinitysynergy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"news.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtreedesign.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtrendeg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newvisionopticallab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newxing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nextdigitalday.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ngdaycare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nguyenkekhuyen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nhorangtreem.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nicolas.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nidhi.iexist.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nikanpolimer.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilehouse.co.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilinkeji.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"njtiledesigncenter.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nobius.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocalnoodle.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nomadicbees.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nonnarina.ax"; content:"Host"; http_header; classtype:trojan-activity; sid:100004455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"notamuzikaletleri.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ns1.the-widyantos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsb.org.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsheldon.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuthuassociates.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuwagi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyeh2o.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oakleyandfriends.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"obseques-conseils.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohe.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100004465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohsewgorgeous.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oknoplastik.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oleholeh.memangbeda.website"; content:"Host"; http_header; classtype:trojan-activity; sid:100004468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"olirecords.mixture.ltd"; content:"Host"; http_header; classtype:trojan-activity; sid:100004469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"olooom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaromatic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omega.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100004473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oms.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omscoc.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedigitalcard.granvizionnecorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedrive.listifyapp.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.creedglobal.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinestatis.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ont.proman.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"open.warehousesaas.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opolis.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opticaoptigral.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optimus.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optitechsa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"order.bizpeed.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orientgatewayltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orion445.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orpod.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oserve.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ottimade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ourteam.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ozemag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p1.lingpao8.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p3.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p6.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pablobrothel.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacificgroup.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100004498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacwebdesigns.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pagos.krayem.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"palochusvet.szm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parallel.rockvideos.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100004502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parejasfelices.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parkhussion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pastorpaulocosta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.51lg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch3.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paths.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paulmercier.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payerrealty.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payments.atifsiddiqui.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100004512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pcsoori.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pd.oceaniarp.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpustekim.untirta.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"petercollie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ph4s.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phasdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phenhuong.sanpham.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100004519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phittc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photo360.kubooking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photographytipsclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004522; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pink99.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pizzabarletta.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"plasfan.ind.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pmglance.startwriteup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pokojewewladyslawowie.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pole.com.vc"; content:"Host"; http_header; classtype:trojan-activity; sid:100004528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pool.phxdir.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pooltablemoversdenver.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"posmicrosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"poulman.panagiotopoulos-tours.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ppdb.smk-ciptaskill.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pptvideotemplates.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestasicash.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestigehomeautomation.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prishaartcreations.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"production.sparshims.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"programaoperadoronline.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"project.exquitec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promotoradescomplica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promoversdubai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosoc.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosyarmakassar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"provence.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prueba.danielluza.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pujashoppe.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punchdialogues.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punjabdevelopersassociation.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"purefoe.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100004552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pvcprinting.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qadir.tickfa.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qatarglobalconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qmsled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"quartier-midi.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100004557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"querocar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rachmat-assuhaimi.my.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rainbowisp.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004560; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raodigitalmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004561; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rarlabarchiver.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100004562; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rasadbar.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rashika.ascarvalho.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ratemyfenancialadvisor.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ravenproductionsltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rc.ixiaoyang.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rcmesilva.charbelsales.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004568; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"readymmade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redchillicrackers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reifenquick.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"relaxindulge.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"renehavis.com.ua"; content:"Host"; http_header; classtype:trojan-activity; sid:100004573; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"repatriacioncolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"res.uf1.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.digimitra.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"resuco.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rezkabum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rhema.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richancyber.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richmondminerals.co.zm"; content:"Host"; http_header; classtype:trojan-activity; sid:100004581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinaefoundation.org.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinkaisystem-ht.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"riverfox.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkcable.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkverify.securestudies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roadfurylifts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertmcardle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertsinclair.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robinhood-sports.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"romanianpoints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ronnietucker.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roomsvc.servegate.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshan.academy"; content:"Host"; http_header; classtype:trojan-activity; sid:100004594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshnijewellery.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rs-toolkit.mikestclair.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rsgym.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubazar.pro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubycityvietnam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruisgood.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruwadalkuwait.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rydchile.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rzminc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.51shijuan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.thechinesemuslim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sacredscentsonline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safcol-colors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safehubsecurity.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safety.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sahathaikasetpan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"saisoftwareinc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salecorner.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sandovalgraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"santyago.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sarakem.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sasystemsuk.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"savasaachi.systems"; content:"Host"; http_header; classtype:trojan-activity; sid:100004617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scarfaceindustries.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scglobal.co.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schalke04rss.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scheff.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schoolbustracker.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sec-doc-w.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-doc-reader.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"segalsmetals.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sellmyphonela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"selltechtoday.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"senbiaojita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sentierodelviandante.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100004629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serendibsourcing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviciovirtual.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"seyranikenger.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgessy.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shaheentbfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahikhana.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharkrigs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharpelevators.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shembefoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shivakunwar.com.np"; content:"Host"; http_header; classtype:trojan-activity; sid:100004641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shoblasaathitrust.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shooka-co.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shop.goldspot.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100004644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shopsofe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shrushtiinfotech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sibernetix.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sige.brisainformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"signatureads.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siili.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simoneporzi.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simplithy.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindicato1ucm.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindpol.tiejuris.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sinergidwireka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sipahielektrik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siperb.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sistelligent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skkksolo.beweiretail.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyflyfares.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyscan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarthouseforum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarts.tj"; content:"Host"; http_header; classtype:trojan-activity; sid:100004663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartzedu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokeandgrowrichtour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokesolutionindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobethuacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.110route.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.officelabo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sohs.conceptechs.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solar.amazingtribe.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solo2.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somcorbera.cat"; content:"Host"; http_header; classtype:trojan-activity; sid:100004673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somir.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soralapps.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sorteio.orgaostalita.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sota-france.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sowingminerals.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"space.proactint.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spaceframe.mobi.space-frame.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"special-key.cf"; content:"Host"; http_header; classtype:trojan-activity; sid:100004681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spent.com.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spetsesyachtcharter.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spititourism.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spittinfire.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sports-net.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"src1.minibai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sreenivasapaintingworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sriglobalit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srvmanos.no-ip.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ss.monita.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"staging.apparelpunch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"starcountry.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"static.3001.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statsres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statssound.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statsspot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statsvilla.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stemschool.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiepancasetia.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stott-thompson.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stratexec.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"streetdemo.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"suboldesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sumerians.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunbrero.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunmarkholidays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supermercadostia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-4-free.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support.clz.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supportit.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100004711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sw.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweaty.dk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweet-diet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swentsai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swiftlogisticseg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swwbia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"syracusecoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sys.pbmadu.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sytraders.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.honker.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.netcatkit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004722; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tacticohosting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004723; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tadoo.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004724; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tafsantoursandtravels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004725; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tallyinvoicecustomization.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004726; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taltus.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004727; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tapalkoedacoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004728; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tarravalleyfoods.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004729; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taurus.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004730; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tavo.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004731; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taxicabsrilanka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004732; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taxpos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004733; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tc.snpsresidential.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004734; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tcy.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004735; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tdsp.yngw518.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004736; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"techgms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004737; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"technogreen.crmmanivela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004738; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"technohub.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004739; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tecnicaencolectores.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004740; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tecnologyschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004741; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teduae.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004742; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teleargentina.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004743; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telescopelms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004744; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telmed.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004745; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"temptmag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004746; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tentandoserfitness.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004747; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.adventser.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004748; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.letraele.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004749; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004750; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.wanepghana.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004751; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.asistencia247.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004752; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.milenial.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004753; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004754; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.basis-web.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004755; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.marrenconstruction.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100004756; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.clickitsolutionsmw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004757; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.thinkingcorp.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004758; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testnew.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004759; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teteaffiche.stephanebillon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004760; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tewoerd.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004761; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"textile.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004762; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"texturesbyvinita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004763; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tharringtonsponsorship.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004764; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecleaningladiespdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004765; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecreativecafe.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004766; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefuturelife.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004767; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehighlightinterior.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004768; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehouseofpragya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004769; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thekassia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004770; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thelaunchpadteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004771; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thesummitpc.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004772; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theurbantutors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004773; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thosewebbs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004774; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tianangdep.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004775; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickfood.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004776; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickjobs.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004777; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickmart.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004778; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"timegonebuy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004779; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tksb.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004780; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tlcc.com.gt"; content:"Host"; http_header; classtype:trojan-activity; sid:100004781; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"todoapp.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004782; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonydong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004783; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonyzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004784; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tooba.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004785; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topcell9.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004786; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topicsnepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004787; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toplevel.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004788; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"torresquinterocorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004789; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"towme.services"; content:"Host"; http_header; classtype:trojan-activity; sid:100004790; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toyotacollege.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004791; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpef.lsoftdemo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004792; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpke.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004793; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tradezone.ejuicysolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004794; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"translaterjemah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004795; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"travelwithmanta.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004796; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trezors.io.mahlongwa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004797; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"triplonet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004798; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"troki.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004799; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tropics.codeleek.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004800; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trucks.softwarenecessities.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004801; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trudelfavreau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004802; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsd.jxwan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004803; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tulli.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004804; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tupperware.michaelroberge.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004805; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"turanggaresources.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004806; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uat.indianfilmzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004807; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ublretailerdemo.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004808; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uc-56.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004809; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"udesk.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004810; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ugprs-ubih.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004811; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ultimate-24.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004812; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"umwelt-kirchhof.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004813; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unicorpbrunei.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004814; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uniengrisb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004815; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unisoftcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004816; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unyazitelecom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004817; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"upcbpta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004818; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"urbantrapfest.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004819; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"useformoney.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004820; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"usmadetshirts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004821; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uss.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004822; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uzzepay.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004823; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vbcargo.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004824; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vcah.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004825; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vegadelcasero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004826; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vendas.lidiacarmeli.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004827; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vfocus.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004828; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vidmattic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004829; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vienen.gblix.srv.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004830; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villamarand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004831; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villatera.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004832; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"violinstop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004833; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viraltalking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004834; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visions.alnisamart.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004835; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visualhome.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004836; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vitoriamodaintima.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004837; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vivationdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004838; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viveirodoiscorregos.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004839; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vksales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004840; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vladimirinternational.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004841; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vokasi.ub.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004842; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vologroup.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004843; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"voteyouramerica.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004844; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vpinversiones.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004845; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vstsample.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004846; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vtube.fadlymotivator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004847; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvsskmodinationalschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004848; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepliberia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004849; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepniger.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004850; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weareactum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004851; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.eng.ubu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004852; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geetle.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100004853; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geomegasoft.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004854; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.newinnovationtechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004855; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.smarts-works.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004856; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004857; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webgis.perumdasolo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004858; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100004859; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webpresario.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004860; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"website-work.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004861; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weinsteincounseling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004862; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wexfashion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004863; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whcms.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004864; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteglovetailgate.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004865; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteresponse.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004866; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wi522012.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004867; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wikalen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004868; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildnights.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004869; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildtrust.mediadevstaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004870; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wimbamusica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004871; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"windcomtechnologies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004872; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wishesconcierge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004873; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woezon.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100004874; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wolfgang-brodte.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004875; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woodsytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004876; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wordpress.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004877; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wozata.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004878; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wp.readhere.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004879; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wpdemo.101clients.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004880; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"writtendeer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004881; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ws5588.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004882; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wyklej.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004883; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"x2vn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004884; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xia.beihaixue.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004885; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xixaoclothing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004886; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xk.996is.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004887; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--80akinnkiib6h.xn--90ais"; content:"Host"; http_header; classtype:trojan-activity; sid:100004888; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--polimerbizmimarlk-rvc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004889; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ybom.urbanolab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004890; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yeichner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004891; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ylfpremium.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004892; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yoast.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004893; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yourtopdog.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004894; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"youtubetrainingacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004895; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yp.hnggzyjy.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004896; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yskadvisors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004897; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yummyyogaudaipur.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004898; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yzkzixun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004899; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004900; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zz.690tx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004901; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; http_uri; nocase; content:"amumufree.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004902; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/files/proxyi.exe"; http_uri; nocase; content:"analogx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004903; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ww/setup.exe"; http_uri; nocase; content:"b4ad7b79-534a-4e83-953e-c36da8cf27d9.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004904; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004905; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dvdfv/anjj/downloads/jami.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004906; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/4.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004907; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/6.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004908; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004909; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr3.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004910; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/instaler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004911; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/installer.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004912; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatej.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004913; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatev.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004914; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/work.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004915; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/component.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004916; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004917; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/regsvc.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004918; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/skygaming/updates/downloads/update.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004919; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/001.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004920; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1488.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004921; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1_cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004922; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004923; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1fc2d.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004924; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/26a5.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004925; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004926; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/abjects.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004927; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/attached.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004928; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/b7f2c.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004929; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/battletext.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004930; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004931; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004932; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004933; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_makros.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004934; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_silent.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004935; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_sup.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004936; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004937; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004938; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004939; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildss.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004940; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientnik.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004941; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientrevers.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004942; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dcrat.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004943; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004944; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004945; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004946; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hans.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004947; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hulu.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004948; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfive.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004949; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfour.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004950; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelone.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004951; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelthree.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004952; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/inteltwo.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004953; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004954; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/kleiman.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004955; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004956; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/notepadplus.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004957; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004958; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004959; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004960; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004961; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/putty.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004962; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/rockethcd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004963; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/scvhost900.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004964; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/sessionwin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004965; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/siliculose.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004966; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/statemobi.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004967; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004968; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004969; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stgedo.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004970; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/svcperf.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004971; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004972; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurjok.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004973; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurusbabac.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004974; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/telekiller.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004975; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateanddr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004976; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateandr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004977; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/vhajeja.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004978; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/word.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004979; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/www.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004980; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/xlsd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004981; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004982; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004983; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hmatrix/data/hack1226.exe"; http_uri; nocase; content:"cd.textfiles.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004984; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004985; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/816070119281131570/816070273254162442/all.txt"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004986; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/821809080812437507/824392185902006272/mmp1_1.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004987; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004988; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/823810712891555890/824413943526195210/runpetest.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004989; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/824689793140129857/824690065988386816/sendhookfile.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004990; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/824689793140129857/824691026852970496/photo.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004991; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/razor/rzr-winner_intro.zip"; http_uri; nocase; content:"chiptune.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004992; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004993; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004994; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/meteoradminz/hidden-tear/zip/master"; http_uri; nocase; content:"codeload.github.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004995; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; http_uri; nocase; content:"colfincas.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004996; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qz0h69.pdf"; http_uri; nocase; content:"deepfreedom.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004997; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hold/schost.exe"; http_uri; nocase; content:"digitalassets.ams3.digitaloceanspaces.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004998; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/modern/five.exe"; http_uri; nocase; content:"digitalassets.ams3.digitaloceanspaces.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004999; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=11jnyjpzkjiie_rzc4xwa2feok3x__yvc"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005000; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=151uxflny3vqh_lmghrkgjhhsqxi163sh"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005001; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=15iwonkjkhyvri_okkc_llq56aasvnvb9"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005002; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1ak46tqftzejmq-og_ky2oupgpmkgujtm"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005003; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1brsmnj6g0lxa44ixkypvg5tcxkvi5gjt"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005004; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1by_s4vv8gdmmz8wl-lbpjbjy5adcrjk1"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005005; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1dpsxfbptpyl-zegto9t29vvcku2rjm9u"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005006; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1dwb7nww_ahtjfeed-afxl4hvm_xqkx-h"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005007; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1e7t_hnuohxuziwcxihocdievcj5_dsgj"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005008; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1erajjbz6gdxhsvvorlykzxyeoq-xu7wn"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005009; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1ev7gkzwjgtv2vlbbisg1ragd7nf0-xog"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005010; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1ey8zl85vszh-gdmubkoudacqs6zv2dup"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005011; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1gq_jf503du9oip5bwzcoi6_kgolr3kx2"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1imrv00kqbfz4ljzwq5qdau1to0zlmaqy"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005013; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1j6pvg1rznjh9pkldcyjiogo8ysiyl8_y"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005014; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1jlcqojhfhgifmirrsv0o5t-2rl-hblai"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005015; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1k6sh5h-nptesem_jsnuxmhzntnvdlgxz"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005016; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1lk6n-xrtv0dvdqljl26pzebxzp8tladk"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1lkcqgpimry4yp8grinnhsotnawquozcz"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1m34mp1cggxz-cz3a5ipjrgfog_qx8myx"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005019; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1m6kdawqt1fwxea6epcae6t1qevfhl0-5"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005020; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1m8w1y1-mxxa2pktrzkwfetwjxrlw1alo"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1m9jxzqcbnb8j8uph1qfcas8b9pngcogj"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1mdnlxs6vy5qk-u4dxz9movem4j3a3o-8"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1od6gtslxvylgyeujmrbvm9yhupmq_1lv"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1ozpasp-mr-e-ui4lshy4qy4a2pl8pxsi"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1q0edpjr7vgo_ytns7dgjcav6317juz9y"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1q5gqeinogsri3i-ynlgvu88ajqnn9siq"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1quyiobd7-d-vcddlhxiqbqrwxyg7ongo"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1rrtyvouwizor2icbcoywdid4w9rwngxi"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1sao6yxf-a0t6wdgdr36srwlju57vigx_"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1st5mtgqyofsskuhlomfihfmz_qx-i32o"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1u5q84w84g_x98ti4uflzhrgvzzfyj_qi"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005032; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1umz5zjobot9__v2jxdutyborb2az90hz"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005033; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1we-h5qtxj9czhkhzvzg0qqpxufgu_v__"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005034; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1wurpipyf0s__fqtn1ov619nx7v1-tcy3"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005035; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1wwkqbfluu4qusqz26ewulr48zh9vzq-w"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005036; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=1yyuejm8cerrq2tctsibww4uetepcmh4i"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005037; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; http_uri; nocase; content:"drive.google.com.it-barcelona.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005038; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005039; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005040; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005041; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005042; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005043; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005044; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005045; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005046; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005047; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005048; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005049; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005050; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005051; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005052; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005053; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005054; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005055; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005056; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005057; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005058; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005059; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005060; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005061; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005062; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/1zilg/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/qcgfmfvh/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005065; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/emclick.zip"; http_uri; nocase; content:"e-mudhra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005066; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100005067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100005068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/x/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; http_uri; nocase; content:"file.elecfans.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; http_uri; nocase; content:"gist.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; http_uri; nocase; content:"hqdecig.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/suy/"; http_uri; nocase; content:"hsecaravans.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100005081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/19/items/startup_20210219/startup.txt"; http_uri; nocase; content:"ia801802.us.archive.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online-timer-kvhxz/ilxl/"; http_uri; nocase; content:"ie-best.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100005083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100005084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100005085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ebook/cs17.exe"; http_uri; nocase; content:"jcedu.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/jl01o54yy09qrzg/fac215.tgz/file"; http_uri; nocase; content:"justlficante.mediafire.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; http_uri; nocase; content:"karmakoincodes.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; http_uri; nocase; content:"ksh.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100005092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/down/affiliate/kuaizip_setup_10029.exe"; http_uri; nocase; content:"kuaizip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/linuxforensicscode.zip"; http_uri; nocase; content:"linuxforensicsbook.com.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/k/big5/1giof6/"; http_uri; nocase; content:"minpic.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100005095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-contentbak/t9m/"; http_uri; nocase; content:"morrobaydrugandgift.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; http_uri; nocase; content:"my.cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/aacenc.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100005098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/doxillionsetup.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100005099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/4/1/6/6/4166984/keygen.exe"; http_uri; nocase; content:"newyarlfm.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; http_uri; nocase; content:"nhipcauytevietnhat.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; http_uri; nocase; content:"note.youdao.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; http_uri; nocase; content:"oldschoolvalue.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005123; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005124; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005125; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005126; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005127; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005129; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005130; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005131; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005132; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005133; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005134; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005135; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005136; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005156; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005174; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005179; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005180; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005181; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005182; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005183; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005184; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005206; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!296&authkey=adsdrrjllbu1nwa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!297&authkey=am7nspchat4aqtw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21296&authkey=adsdrrjllbu1nwa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=80dabacd46496407&resid=80dabacd46496407%21124&authkey=abnj7t59iwijpdy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005522; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1045&authkey=aetgoeo_eku-6ba"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211045&authkey=aetgoeo_eku-6ba"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005560; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005561; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21122&authkey=ajqq2okqxfq8iuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005562; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005568; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005573; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774!124&authkey=afq42wqejwvcv8o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774%21124&authkey=afq42wqejwvcv8o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4a3bd996f92bf71&resid=e4a3bd996f92bf71%211944&authkey=ao3lztaialsza88"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f8d2350982acb14f&resid=f8d2350982acb14f%21140&authkey=ajo86idqg2jvzfq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!196&authkey=amm2av5ubkbhoru"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!197&authkey=apnt4trskzjga_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21196&authkey=amm2av5ubkbhoru"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21197&authkey=apnt4trskzjga_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/yqvsvlvq"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/llc/mwcacs65xienqdp/"; http_uri; nocase; content:"pierreconsulting.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100005677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; http_uri; nocase; content:"pioneiraagronegocio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100005678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skoda22.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; http_uri; nocase; content:"qjbutterflyevents.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100005681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/maersk-bl+draft-copy-shipping-documents.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/purchasing+ordersigned+contractinv-30067121.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/myqseeaccount/one/main/one.htm"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tennc/webshell/master/other/small_shell.txt"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; http_uri; nocase; content:"res.yeshen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/q05z91"; http_uri; nocase; content:"sendspace.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a-nurse-ss8d9/z/"; http_uri; nocase; content:"technologydistilled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/databases/merit.php"; http_uri; nocase; content:"truemerit.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100005710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/23.exe"; http_uri; nocase; content:"tsrv4.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100005711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/crisanar/defis/jek_crackme1.7.zip"; http_uri; nocase; content:"users.skynet.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100005712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/amowvegfrt9ja/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100005713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100005714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100005715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100005716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb%5efr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb^fr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/151_155/tidex_-_short_stuff.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/syria-files/attach/222/222051_instruction.zip"; http_uri; nocase; content:"wikileaks.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005722; rev:1;)
diff --git a/urlhaus-filter-snort3-online.rules b/urlhaus-filter-snort3-online.rules
index 7e174a17..e66c61eb 100644
--- a/urlhaus-filter-snort3-online.rules
+++ b/urlhaus-filter-snort3-online.rules
@@ -1,5 +1,5 @@
 # Title: Online Malicious URL Snort3 Ruleset
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -7,5778 +7,5722 @@
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"0-24bpautomentes.hu",nocase; classtype:trojan-activity; sid:100000001; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"0cl.sldov.ru",nocase; classtype:trojan-activity; sid:100000002; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.11.234.99",nocase; classtype:trojan-activity; sid:100000003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.222.140.251",nocase; classtype:trojan-activity; sid:100000004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.222.166.69",nocase; classtype:trojan-activity; sid:100000005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.186.151.219",nocase; classtype:trojan-activity; sid:100000004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.222.140.251",nocase; classtype:trojan-activity; sid:100000005; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.222.196.60",nocase; classtype:trojan-activity; sid:100000006; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.245.4.163",nocase; classtype:trojan-activity; sid:100000007; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.107",nocase; classtype:trojan-activity; sid:100000008; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.109",nocase; classtype:trojan-activity; sid:100000009; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.113",nocase; classtype:trojan-activity; sid:100000010; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.127",nocase; classtype:trojan-activity; sid:100000011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.134",nocase; classtype:trojan-activity; sid:100000012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.14",nocase; classtype:trojan-activity; sid:100000012; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.153",nocase; classtype:trojan-activity; sid:100000013; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.16",nocase; classtype:trojan-activity; sid:100000014; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.165",nocase; classtype:trojan-activity; sid:100000015; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.228",nocase; classtype:trojan-activity; sid:100000016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.234",nocase; classtype:trojan-activity; sid:100000017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.237",nocase; classtype:trojan-activity; sid:100000018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.245",nocase; classtype:trojan-activity; sid:100000019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.249",nocase; classtype:trojan-activity; sid:100000020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.25",nocase; classtype:trojan-activity; sid:100000021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.38",nocase; classtype:trojan-activity; sid:100000022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.41",nocase; classtype:trojan-activity; sid:100000023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.43",nocase; classtype:trojan-activity; sid:100000024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.45",nocase; classtype:trojan-activity; sid:100000025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.56",nocase; classtype:trojan-activity; sid:100000026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.69",nocase; classtype:trojan-activity; sid:100000027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.8",nocase; classtype:trojan-activity; sid:100000028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.80",nocase; classtype:trojan-activity; sid:100000029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.98",nocase; classtype:trojan-activity; sid:100000030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.10",nocase; classtype:trojan-activity; sid:100000031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.103",nocase; classtype:trojan-activity; sid:100000032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.105",nocase; classtype:trojan-activity; sid:100000033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.126",nocase; classtype:trojan-activity; sid:100000034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.127",nocase; classtype:trojan-activity; sid:100000035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.130",nocase; classtype:trojan-activity; sid:100000036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.146",nocase; classtype:trojan-activity; sid:100000037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.148",nocase; classtype:trojan-activity; sid:100000038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.15",nocase; classtype:trojan-activity; sid:100000039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.151",nocase; classtype:trojan-activity; sid:100000040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.18",nocase; classtype:trojan-activity; sid:100000041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.32",nocase; classtype:trojan-activity; sid:100000042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.35",nocase; classtype:trojan-activity; sid:100000043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.4",nocase; classtype:trojan-activity; sid:100000044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.48",nocase; classtype:trojan-activity; sid:100000045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.49",nocase; classtype:trojan-activity; sid:100000046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.54",nocase; classtype:trojan-activity; sid:100000047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.59",nocase; classtype:trojan-activity; sid:100000048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.6",nocase; classtype:trojan-activity; sid:100000049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.61",nocase; classtype:trojan-activity; sid:100000050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.71",nocase; classtype:trojan-activity; sid:100000051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.83",nocase; classtype:trojan-activity; sid:100000052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.94",nocase; classtype:trojan-activity; sid:100000053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.247.221.141",nocase; classtype:trojan-activity; sid:100000054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.247.221.142",nocase; classtype:trojan-activity; sid:100000055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.250.159.41",nocase; classtype:trojan-activity; sid:100000056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.252.102.28",nocase; classtype:trojan-activity; sid:100000057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.254.250.52",nocase; classtype:trojan-activity; sid:100000058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.60.77.53",nocase; classtype:trojan-activity; sid:100000059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.65.166.225",nocase; classtype:trojan-activity; sid:100000060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.82.104.89",nocase; classtype:trojan-activity; sid:100000061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.12.184.63",nocase; classtype:trojan-activity; sid:100000062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.2.131.143",nocase; classtype:trojan-activity; sid:100000063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.8.77.4",nocase; classtype:trojan-activity; sid:100000064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1008691.com",nocase; classtype:trojan-activity; sid:100000065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.130.108",nocase; classtype:trojan-activity; sid:100000066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.109.246.33",nocase; classtype:trojan-activity; sid:100000067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.16.183.179",nocase; classtype:trojan-activity; sid:100000068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.16.98.170",nocase; classtype:trojan-activity; sid:100000069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.229.85.127",nocase; classtype:trojan-activity; sid:100000070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.255.36.154",nocase; classtype:trojan-activity; sid:100000071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.105.132",nocase; classtype:trojan-activity; sid:100000072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.106.134",nocase; classtype:trojan-activity; sid:100000073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.145.2",nocase; classtype:trojan-activity; sid:100000074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.76.34",nocase; classtype:trojan-activity; sid:100000075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.30.128.184",nocase; classtype:trojan-activity; sid:100000076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.30.38.204",nocase; classtype:trojan-activity; sid:100000077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.64.119.250",nocase; classtype:trojan-activity; sid:100000078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.64.161.70",nocase; classtype:trojan-activity; sid:100000079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.75.157.99",nocase; classtype:trojan-activity; sid:100000080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.130.115.14",nocase; classtype:trojan-activity; sid:100000081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.141.240.139",nocase; classtype:trojan-activity; sid:100000082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.107.113.22",nocase; classtype:trojan-activity; sid:100000083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.124.104.118",nocase; classtype:trojan-activity; sid:100000084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.125.218.107",nocase; classtype:trojan-activity; sid:100000085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.139.89.205",nocase; classtype:trojan-activity; sid:100000086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.141.138.12",nocase; classtype:trojan-activity; sid:100000087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.145.13.24",nocase; classtype:trojan-activity; sid:100000088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.146.174.208",nocase; classtype:trojan-activity; sid:100000089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.156.221.66",nocase; classtype:trojan-activity; sid:100000090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.159.155.214",nocase; classtype:trojan-activity; sid:100000091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.16.145.25",nocase; classtype:trojan-activity; sid:100000092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.207.1.146",nocase; classtype:trojan-activity; sid:100000093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.217.215.21",nocase; classtype:trojan-activity; sid:100000094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.40",nocase; classtype:trojan-activity; sid:100000095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.3",nocase; classtype:trojan-activity; sid:100000096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.4",nocase; classtype:trojan-activity; sid:100000097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.240.249.121",nocase; classtype:trojan-activity; sid:100000098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.4.117.26",nocase; classtype:trojan-activity; sid:100000099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.66.78.171",nocase; classtype:trojan-activity; sid:100000100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.79.112.254",nocase; classtype:trojan-activity; sid:100000101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.145.111",nocase; classtype:trojan-activity; sid:100000102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.98.170",nocase; classtype:trojan-activity; sid:100000103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.240.130",nocase; classtype:trojan-activity; sid:100000104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.240.228",nocase; classtype:trojan-activity; sid:100000105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.241.123",nocase; classtype:trojan-activity; sid:100000106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.241.94",nocase; classtype:trojan-activity; sid:100000107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.12",nocase; classtype:trojan-activity; sid:100000108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.16",nocase; classtype:trojan-activity; sid:100000109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.17",nocase; classtype:trojan-activity; sid:100000110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.19",nocase; classtype:trojan-activity; sid:100000111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.20",nocase; classtype:trojan-activity; sid:100000112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.27",nocase; classtype:trojan-activity; sid:100000113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.28",nocase; classtype:trojan-activity; sid:100000114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.3",nocase; classtype:trojan-activity; sid:100000115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.30",nocase; classtype:trojan-activity; sid:100000116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.36",nocase; classtype:trojan-activity; sid:100000117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.41",nocase; classtype:trojan-activity; sid:100000118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.46",nocase; classtype:trojan-activity; sid:100000119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.90",nocase; classtype:trojan-activity; sid:100000120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.95",nocase; classtype:trojan-activity; sid:100000121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.184.75.123",nocase; classtype:trojan-activity; sid:100000122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.33.52.85",nocase; classtype:trojan-activity; sid:100000123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.61.86.37",nocase; classtype:trojan-activity; sid:100000124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.1.112.12",nocase; classtype:trojan-activity; sid:100000125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.172.178",nocase; classtype:trojan-activity; sid:100000126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.193.155",nocase; classtype:trojan-activity; sid:100000127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.105.33.43",nocase; classtype:trojan-activity; sid:100000128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.113.177.60",nocase; classtype:trojan-activity; sid:100000129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.165.234",nocase; classtype:trojan-activity; sid:100000130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.193.132",nocase; classtype:trojan-activity; sid:100000131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.249.148",nocase; classtype:trojan-activity; sid:100000132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.155.54",nocase; classtype:trojan-activity; sid:100000133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.219.80",nocase; classtype:trojan-activity; sid:100000134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.144.195",nocase; classtype:trojan-activity; sid:100000135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.250.107",nocase; classtype:trojan-activity; sid:100000136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.197.135",nocase; classtype:trojan-activity; sid:100000137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.31.130",nocase; classtype:trojan-activity; sid:100000138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.181.136.96",nocase; classtype:trojan-activity; sid:100000139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.189.8.75",nocase; classtype:trojan-activity; sid:100000140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.194.242.170",nocase; classtype:trojan-activity; sid:100000141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.219.185.75",nocase; classtype:trojan-activity; sid:100000142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.220.119.25",nocase; classtype:trojan-activity; sid:100000143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.221.96.202",nocase; classtype:trojan-activity; sid:100000144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.201.37",nocase; classtype:trojan-activity; sid:100000145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.250.48",nocase; classtype:trojan-activity; sid:100000146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.55.199.65",nocase; classtype:trojan-activity; sid:100000147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.104.151.108",nocase; classtype:trojan-activity; sid:100000148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.124.90.229",nocase; classtype:trojan-activity; sid:100000149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.233.196.232",nocase; classtype:trojan-activity; sid:100000150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.235.7.228",nocase; classtype:trojan-activity; sid:100000151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.248.58.238",nocase; classtype:trojan-activity; sid:100000152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.86.85.253",nocase; classtype:trojan-activity; sid:100000153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.102",nocase; classtype:trojan-activity; sid:100000154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.230",nocase; classtype:trojan-activity; sid:100000155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.127.90",nocase; classtype:trojan-activity; sid:100000156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.57.246",nocase; classtype:trojan-activity; sid:100000157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.99.37.97",nocase; classtype:trojan-activity; sid:100000158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.10.58.38",nocase; classtype:trojan-activity; sid:100000159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.12.123.11",nocase; classtype:trojan-activity; sid:100000160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.14.58.190",nocase; classtype:trojan-activity; sid:100000161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.187.229.182",nocase; classtype:trojan-activity; sid:100000162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.190.50",nocase; classtype:trojan-activity; sid:100000163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.195.46",nocase; classtype:trojan-activity; sid:100000164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.241.119.168",nocase; classtype:trojan-activity; sid:100000165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.241.23.107",nocase; classtype:trojan-activity; sid:100000166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.247.151.4",nocase; classtype:trojan-activity; sid:100000167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.247.153.186",nocase; classtype:trojan-activity; sid:100000168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.124.254",nocase; classtype:trojan-activity; sid:100000169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.175.141",nocase; classtype:trojan-activity; sid:100000170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.251.194",nocase; classtype:trojan-activity; sid:100000171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.251.10.18",nocase; classtype:trojan-activity; sid:100000172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.213.198",nocase; classtype:trojan-activity; sid:100000173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.51.112",nocase; classtype:trojan-activity; sid:100000174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.255.101.184",nocase; classtype:trojan-activity; sid:100000175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.255.167.147",nocase; classtype:trojan-activity; sid:100000176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.145.127",nocase; classtype:trojan-activity; sid:100000177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.208.21",nocase; classtype:trojan-activity; sid:100000178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.221.77",nocase; classtype:trojan-activity; sid:100000179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.223.92",nocase; classtype:trojan-activity; sid:100000180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.225.24",nocase; classtype:trojan-activity; sid:100000181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.233.147",nocase; classtype:trojan-activity; sid:100000182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.235.57",nocase; classtype:trojan-activity; sid:100000183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.4.2",nocase; classtype:trojan-activity; sid:100000184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110fss.net",nocase; classtype:trojan-activity; sid:100000185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.88.61",nocase; classtype:trojan-activity; sid:100000186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.119.245.114",nocase; classtype:trojan-activity; sid:100000187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.125.67.125",nocase; classtype:trojan-activity; sid:100000188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.162.224.14",nocase; classtype:trojan-activity; sid:100000189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.163.50.120",nocase; classtype:trojan-activity; sid:100000190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.165.21.195",nocase; classtype:trojan-activity; sid:100000191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.165.28.234",nocase; classtype:trojan-activity; sid:100000192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.84.182",nocase; classtype:trojan-activity; sid:100000193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.86.133",nocase; classtype:trojan-activity; sid:100000194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.172.164.104",nocase; classtype:trojan-activity; sid:100000195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.176.182.149",nocase; classtype:trojan-activity; sid:100000196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.179.153.69",nocase; classtype:trojan-activity; sid:100000197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.179.243.126",nocase; classtype:trojan-activity; sid:100000198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.182.232.18",nocase; classtype:trojan-activity; sid:100000199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.177.85",nocase; classtype:trojan-activity; sid:100000200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.23.84",nocase; classtype:trojan-activity; sid:100000201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.230.136",nocase; classtype:trojan-activity; sid:100000202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.27.9",nocase; classtype:trojan-activity; sid:100000203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.48.248",nocase; classtype:trojan-activity; sid:100000204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.114",nocase; classtype:trojan-activity; sid:100000205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.122",nocase; classtype:trojan-activity; sid:100000206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.13",nocase; classtype:trojan-activity; sid:100000207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.66",nocase; classtype:trojan-activity; sid:100000208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.141",nocase; classtype:trojan-activity; sid:100000209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.165",nocase; classtype:trojan-activity; sid:100000210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.128",nocase; classtype:trojan-activity; sid:100000211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.19",nocase; classtype:trojan-activity; sid:100000212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.48",nocase; classtype:trojan-activity; sid:100000213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.222",nocase; classtype:trojan-activity; sid:100000214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.223",nocase; classtype:trojan-activity; sid:100000215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.228",nocase; classtype:trojan-activity; sid:100000216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.15",nocase; classtype:trojan-activity; sid:100000217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.184",nocase; classtype:trojan-activity; sid:100000218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.197",nocase; classtype:trojan-activity; sid:100000219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.200",nocase; classtype:trojan-activity; sid:100000220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.23",nocase; classtype:trojan-activity; sid:100000221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.26.243",nocase; classtype:trojan-activity; sid:100000222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.8.81",nocase; classtype:trojan-activity; sid:100000223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.61.52.53",nocase; classtype:trojan-activity; sid:100000224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.105.117.227",nocase; classtype:trojan-activity; sid:100000225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.100.236",nocase; classtype:trojan-activity; sid:100000226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.108.184",nocase; classtype:trojan-activity; sid:100000227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.31.175",nocase; classtype:trojan-activity; sid:100000228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.122.62.224",nocase; classtype:trojan-activity; sid:100000229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.123.200.47",nocase; classtype:trojan-activity; sid:100000230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.132.134.106",nocase; classtype:trojan-activity; sid:100000231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.132.147.102",nocase; classtype:trojan-activity; sid:100000232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.159.108.96",nocase; classtype:trojan-activity; sid:100000233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.124.75",nocase; classtype:trojan-activity; sid:100000234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.219.168",nocase; classtype:trojan-activity; sid:100000235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.233.9",nocase; classtype:trojan-activity; sid:100000236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.210.211",nocase; classtype:trojan-activity; sid:100000237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.96.252",nocase; classtype:trojan-activity; sid:100000238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.187.91.117",nocase; classtype:trojan-activity; sid:100000239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.214.127.42",nocase; classtype:trojan-activity; sid:100000240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.187.19",nocase; classtype:trojan-activity; sid:100000241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.236.77",nocase; classtype:trojan-activity; sid:100000242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.43.27",nocase; classtype:trojan-activity; sid:100000243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.52.145",nocase; classtype:trojan-activity; sid:100000244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.82.4",nocase; classtype:trojan-activity; sid:100000245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.118.229",nocase; classtype:trojan-activity; sid:100000246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.176.167",nocase; classtype:trojan-activity; sid:100000247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.195.104",nocase; classtype:trojan-activity; sid:100000248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.202.111",nocase; classtype:trojan-activity; sid:100000249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.205.96",nocase; classtype:trojan-activity; sid:100000250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.67.193",nocase; classtype:trojan-activity; sid:100000251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.92.34",nocase; classtype:trojan-activity; sid:100000252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.180.95",nocase; classtype:trojan-activity; sid:100000253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.114",nocase; classtype:trojan-activity; sid:100000254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.137",nocase; classtype:trojan-activity; sid:100000255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.178.109",nocase; classtype:trojan-activity; sid:100000256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.188.28",nocase; classtype:trojan-activity; sid:100000257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.199.19",nocase; classtype:trojan-activity; sid:100000258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.230.251.85",nocase; classtype:trojan-activity; sid:100000259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.121.107",nocase; classtype:trojan-activity; sid:100000260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.134.244",nocase; classtype:trojan-activity; sid:100000261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.16.252",nocase; classtype:trojan-activity; sid:100000262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.194.178",nocase; classtype:trojan-activity; sid:100000263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.216.151",nocase; classtype:trojan-activity; sid:100000264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.218.202",nocase; classtype:trojan-activity; sid:100000265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.149.73",nocase; classtype:trojan-activity; sid:100000266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.188.86",nocase; classtype:trojan-activity; sid:100000267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.126.177",nocase; classtype:trojan-activity; sid:100000268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.171.69",nocase; classtype:trojan-activity; sid:100000269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.228.21",nocase; classtype:trojan-activity; sid:100000270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.141.241",nocase; classtype:trojan-activity; sid:100000271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.144.226",nocase; classtype:trojan-activity; sid:100000272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.172.106",nocase; classtype:trojan-activity; sid:100000273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.197.144",nocase; classtype:trojan-activity; sid:100000274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.230.192",nocase; classtype:trojan-activity; sid:100000275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.75.157",nocase; classtype:trojan-activity; sid:100000276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.143.135",nocase; classtype:trojan-activity; sid:100000277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.17.120",nocase; classtype:trojan-activity; sid:100000278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.190.207",nocase; classtype:trojan-activity; sid:100000279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.194.18",nocase; classtype:trojan-activity; sid:100000280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.227.228",nocase; classtype:trojan-activity; sid:100000281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.39.2",nocase; classtype:trojan-activity; sid:100000282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.73.181",nocase; classtype:trojan-activity; sid:100000283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.184.162",nocase; classtype:trojan-activity; sid:100000284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.216.17",nocase; classtype:trojan-activity; sid:100000285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.241.187.165",nocase; classtype:trojan-activity; sid:100000286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.106.228",nocase; classtype:trojan-activity; sid:100000287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.18.128",nocase; classtype:trojan-activity; sid:100000288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.2.247",nocase; classtype:trojan-activity; sid:100000289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.243.115.183",nocase; classtype:trojan-activity; sid:100000290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.12.89",nocase; classtype:trojan-activity; sid:100000291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.5.141",nocase; classtype:trojan-activity; sid:100000292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.8.24",nocase; classtype:trojan-activity; sid:100000293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.162.50",nocase; classtype:trojan-activity; sid:100000294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.180.49",nocase; classtype:trojan-activity; sid:100000295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.100.14",nocase; classtype:trojan-activity; sid:100000296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.14.135",nocase; classtype:trojan-activity; sid:100000297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.161.45",nocase; classtype:trojan-activity; sid:100000298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.191.118",nocase; classtype:trojan-activity; sid:100000299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.214.146",nocase; classtype:trojan-activity; sid:100000300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.240.226",nocase; classtype:trojan-activity; sid:100000301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.81.173",nocase; classtype:trojan-activity; sid:100000302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.82.122",nocase; classtype:trojan-activity; sid:100000303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.148.90",nocase; classtype:trojan-activity; sid:100000304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.179.239",nocase; classtype:trojan-activity; sid:100000305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.197.164",nocase; classtype:trojan-activity; sid:100000306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.44.153",nocase; classtype:trojan-activity; sid:100000307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.109.217",nocase; classtype:trojan-activity; sid:100000308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.118.157",nocase; classtype:trojan-activity; sid:100000309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.165.240",nocase; classtype:trojan-activity; sid:100000310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.206.69",nocase; classtype:trojan-activity; sid:100000311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.26.129",nocase; classtype:trojan-activity; sid:100000312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.41.142",nocase; classtype:trojan-activity; sid:100000313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.79.98",nocase; classtype:trojan-activity; sid:100000314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.102.173",nocase; classtype:trojan-activity; sid:100000315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.57.99",nocase; classtype:trojan-activity; sid:100000316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.17.5",nocase; classtype:trojan-activity; sid:100000317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.218.210",nocase; classtype:trojan-activity; sid:100000318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.23.55",nocase; classtype:trojan-activity; sid:100000319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.136.84",nocase; classtype:trojan-activity; sid:100000320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.199.150",nocase; classtype:trojan-activity; sid:100000321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.221.244",nocase; classtype:trojan-activity; sid:100000322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.239.103",nocase; classtype:trojan-activity; sid:100000323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.245.249",nocase; classtype:trojan-activity; sid:100000324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.46.212",nocase; classtype:trojan-activity; sid:100000325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.208.123",nocase; classtype:trojan-activity; sid:100000326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.32.5",nocase; classtype:trojan-activity; sid:100000327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.127.212",nocase; classtype:trojan-activity; sid:100000328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.38.10",nocase; classtype:trojan-activity; sid:100000329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.6.129",nocase; classtype:trojan-activity; sid:100000330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.8.235",nocase; classtype:trojan-activity; sid:100000331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.121.163",nocase; classtype:trojan-activity; sid:100000332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.123.174",nocase; classtype:trojan-activity; sid:100000333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.109",nocase; classtype:trojan-activity; sid:100000334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.110",nocase; classtype:trojan-activity; sid:100000335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.111",nocase; classtype:trojan-activity; sid:100000336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.112",nocase; classtype:trojan-activity; sid:100000337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.113",nocase; classtype:trojan-activity; sid:100000338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.117",nocase; classtype:trojan-activity; sid:100000339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.119",nocase; classtype:trojan-activity; sid:100000340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.120",nocase; classtype:trojan-activity; sid:100000341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.122",nocase; classtype:trojan-activity; sid:100000342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.124",nocase; classtype:trojan-activity; sid:100000343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.127",nocase; classtype:trojan-activity; sid:100000344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.128",nocase; classtype:trojan-activity; sid:100000345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.130",nocase; classtype:trojan-activity; sid:100000346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.131",nocase; classtype:trojan-activity; sid:100000347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.132",nocase; classtype:trojan-activity; sid:100000348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.133",nocase; classtype:trojan-activity; sid:100000349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.136",nocase; classtype:trojan-activity; sid:100000350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.138",nocase; classtype:trojan-activity; sid:100000351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.139",nocase; classtype:trojan-activity; sid:100000352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.140",nocase; classtype:trojan-activity; sid:100000353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.142",nocase; classtype:trojan-activity; sid:100000354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.143",nocase; classtype:trojan-activity; sid:100000355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.146",nocase; classtype:trojan-activity; sid:100000356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.149",nocase; classtype:trojan-activity; sid:100000357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.150",nocase; classtype:trojan-activity; sid:100000358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.151",nocase; classtype:trojan-activity; sid:100000359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.155",nocase; classtype:trojan-activity; sid:100000360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.158",nocase; classtype:trojan-activity; sid:100000361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.160",nocase; classtype:trojan-activity; sid:100000362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.162",nocase; classtype:trojan-activity; sid:100000363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.163",nocase; classtype:trojan-activity; sid:100000364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.165",nocase; classtype:trojan-activity; sid:100000365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.168",nocase; classtype:trojan-activity; sid:100000366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.171",nocase; classtype:trojan-activity; sid:100000367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.172",nocase; classtype:trojan-activity; sid:100000368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.175",nocase; classtype:trojan-activity; sid:100000369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.176",nocase; classtype:trojan-activity; sid:100000370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.178",nocase; classtype:trojan-activity; sid:100000371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.179",nocase; classtype:trojan-activity; sid:100000372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.71",nocase; classtype:trojan-activity; sid:100000373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.126.243",nocase; classtype:trojan-activity; sid:100000374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.127.155",nocase; classtype:trojan-activity; sid:100000375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.120",nocase; classtype:trojan-activity; sid:100000376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.121",nocase; classtype:trojan-activity; sid:100000377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.82.29",nocase; classtype:trojan-activity; sid:100000378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.182",nocase; classtype:trojan-activity; sid:100000379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.23",nocase; classtype:trojan-activity; sid:100000380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.85.113",nocase; classtype:trojan-activity; sid:100000381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.87.203",nocase; classtype:trojan-activity; sid:100000382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.87.213",nocase; classtype:trojan-activity; sid:100000383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.88.116",nocase; classtype:trojan-activity; sid:100000384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.212",nocase; classtype:trojan-activity; sid:100000385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.247",nocase; classtype:trojan-activity; sid:100000386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.149",nocase; classtype:trojan-activity; sid:100000387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.150",nocase; classtype:trojan-activity; sid:100000388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.158",nocase; classtype:trojan-activity; sid:100000389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.159",nocase; classtype:trojan-activity; sid:100000390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.168",nocase; classtype:trojan-activity; sid:100000391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.177",nocase; classtype:trojan-activity; sid:100000392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.178",nocase; classtype:trojan-activity; sid:100000393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.181",nocase; classtype:trojan-activity; sid:100000394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.188",nocase; classtype:trojan-activity; sid:100000395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.190",nocase; classtype:trojan-activity; sid:100000396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.197",nocase; classtype:trojan-activity; sid:100000397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.211",nocase; classtype:trojan-activity; sid:100000398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.219",nocase; classtype:trojan-activity; sid:100000399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.229",nocase; classtype:trojan-activity; sid:100000400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.230",nocase; classtype:trojan-activity; sid:100000401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.245",nocase; classtype:trojan-activity; sid:100000402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.247",nocase; classtype:trojan-activity; sid:100000403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.54",nocase; classtype:trojan-activity; sid:100000404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.55",nocase; classtype:trojan-activity; sid:100000405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.57",nocase; classtype:trojan-activity; sid:100000406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.60",nocase; classtype:trojan-activity; sid:100000407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.90",nocase; classtype:trojan-activity; sid:100000408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.91",nocase; classtype:trojan-activity; sid:100000409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.100.228",nocase; classtype:trojan-activity; sid:100000410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.27",nocase; classtype:trojan-activity; sid:100000411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.30",nocase; classtype:trojan-activity; sid:100000412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.31",nocase; classtype:trojan-activity; sid:100000413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.37",nocase; classtype:trojan-activity; sid:100000414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.38",nocase; classtype:trojan-activity; sid:100000415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.41",nocase; classtype:trojan-activity; sid:100000416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.42",nocase; classtype:trojan-activity; sid:100000417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.43",nocase; classtype:trojan-activity; sid:100000418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.45",nocase; classtype:trojan-activity; sid:100000419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.52",nocase; classtype:trojan-activity; sid:100000420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.57",nocase; classtype:trojan-activity; sid:100000421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.58",nocase; classtype:trojan-activity; sid:100000422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.60",nocase; classtype:trojan-activity; sid:100000423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.62",nocase; classtype:trojan-activity; sid:100000424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.126.156",nocase; classtype:trojan-activity; sid:100000425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.35.237",nocase; classtype:trojan-activity; sid:100000426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.38.100",nocase; classtype:trojan-activity; sid:100000427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.38.19",nocase; classtype:trojan-activity; sid:100000428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.118",nocase; classtype:trojan-activity; sid:100000429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.119",nocase; classtype:trojan-activity; sid:100000430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.121",nocase; classtype:trojan-activity; sid:100000431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.136",nocase; classtype:trojan-activity; sid:100000432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.37",nocase; classtype:trojan-activity; sid:100000433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.52",nocase; classtype:trojan-activity; sid:100000434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.57",nocase; classtype:trojan-activity; sid:100000435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.61",nocase; classtype:trojan-activity; sid:100000436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.70",nocase; classtype:trojan-activity; sid:100000437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.73",nocase; classtype:trojan-activity; sid:100000438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.77",nocase; classtype:trojan-activity; sid:100000439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.90",nocase; classtype:trojan-activity; sid:100000440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.176.16",nocase; classtype:trojan-activity; sid:100000441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.211.135",nocase; classtype:trojan-activity; sid:100000442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.82.160",nocase; classtype:trojan-activity; sid:100000443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.224.79",nocase; classtype:trojan-activity; sid:100000444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.65.53.175",nocase; classtype:trojan-activity; sid:100000445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.153.37",nocase; classtype:trojan-activity; sid:100000446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.159",nocase; classtype:trojan-activity; sid:100000447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.49",nocase; classtype:trojan-activity; sid:100000448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.53",nocase; classtype:trojan-activity; sid:100000449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.112",nocase; classtype:trojan-activity; sid:100000450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.84",nocase; classtype:trojan-activity; sid:100000451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.78.45.158",nocase; classtype:trojan-activity; sid:100000452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.118.16",nocase; classtype:trojan-activity; sid:100000453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.127.91",nocase; classtype:trojan-activity; sid:100000454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.215.101",nocase; classtype:trojan-activity; sid:100000455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.81.161.10",nocase; classtype:trojan-activity; sid:100000456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.81.199.218",nocase; classtype:trojan-activity; sid:100000457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.131.124",nocase; classtype:trojan-activity; sid:100000458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.146.253",nocase; classtype:trojan-activity; sid:100000459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.18.255",nocase; classtype:trojan-activity; sid:100000460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.224.139",nocase; classtype:trojan-activity; sid:100000461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.227.41",nocase; classtype:trojan-activity; sid:100000462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.228.175",nocase; classtype:trojan-activity; sid:100000463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.83.118.203",nocase; classtype:trojan-activity; sid:100000464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.83.230.37",nocase; classtype:trojan-activity; sid:100000465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.86.133.125",nocase; classtype:trojan-activity; sid:100000466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.9.140.247",nocase; classtype:trojan-activity; sid:100000467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.91.219.195",nocase; classtype:trojan-activity; sid:100000468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.93.29.211",nocase; classtype:trojan-activity; sid:100000469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.95.80.165",nocase; classtype:trojan-activity; sid:100000470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.0.74.25",nocase; classtype:trojan-activity; sid:100000471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.11.95.254",nocase; classtype:trojan-activity; sid:100000472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.110.204.254",nocase; classtype:trojan-activity; sid:100000473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.110.243.79",nocase; classtype:trojan-activity; sid:100000474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.150.147",nocase; classtype:trojan-activity; sid:100000475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.176.26",nocase; classtype:trojan-activity; sid:100000476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.44.33",nocase; classtype:trojan-activity; sid:100000477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.89.82",nocase; classtype:trojan-activity; sid:100000478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.118.13.194",nocase; classtype:trojan-activity; sid:100000479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.118.133.113",nocase; classtype:trojan-activity; sid:100000480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.118.250.227",nocase; classtype:trojan-activity; sid:100000481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.118.6.104",nocase; classtype:trojan-activity; sid:100000482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.238.68",nocase; classtype:trojan-activity; sid:100000483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.59.84",nocase; classtype:trojan-activity; sid:100000484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.58.249",nocase; classtype:trojan-activity; sid:100000485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.172.250.35",nocase; classtype:trojan-activity; sid:100000486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.189.243.248",nocase; classtype:trojan-activity; sid:100000487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.194.133.9",nocase; classtype:trojan-activity; sid:100000488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.194.135.154",nocase; classtype:trojan-activity; sid:100000489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.163.26",nocase; classtype:trojan-activity; sid:100000490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.166.46",nocase; classtype:trojan-activity; sid:100000491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.168.190",nocase; classtype:trojan-activity; sid:100000492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.201.219.47",nocase; classtype:trojan-activity; sid:100000493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.225.171.27",nocase; classtype:trojan-activity; sid:100000494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.226.42.250",nocase; classtype:trojan-activity; sid:100000495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.128.9",nocase; classtype:trojan-activity; sid:100000496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.169.170",nocase; classtype:trojan-activity; sid:100000497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.194.172",nocase; classtype:trojan-activity; sid:100000498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.35.229",nocase; classtype:trojan-activity; sid:100000499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.211.131",nocase; classtype:trojan-activity; sid:100000500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.93.142",nocase; classtype:trojan-activity; sid:100000501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.232.211.182",nocase; classtype:trojan-activity; sid:100000502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.234.224.130",nocase; classtype:trojan-activity; sid:100000503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.235.116.209",nocase; classtype:trojan-activity; sid:100000504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.253.144.141",nocase; classtype:trojan-activity; sid:100000505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.254.169.251",nocase; classtype:trojan-activity; sid:100000506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.128.133",nocase; classtype:trojan-activity; sid:100000507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.133.16",nocase; classtype:trojan-activity; sid:100000508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.144.42",nocase; classtype:trojan-activity; sid:100000509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.154.21",nocase; classtype:trojan-activity; sid:100000510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.191.47",nocase; classtype:trojan-activity; sid:100000511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.61.204.205",nocase; classtype:trojan-activity; sid:100000512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.86.204.13",nocase; classtype:trojan-activity; sid:100000513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.87.203.239",nocase; classtype:trojan-activity; sid:100000514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.87.227.222",nocase; classtype:trojan-activity; sid:100000515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.100.120",nocase; classtype:trojan-activity; sid:100000516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.104.194",nocase; classtype:trojan-activity; sid:100000517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.111.36",nocase; classtype:trojan-activity; sid:100000518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.209.47",nocase; classtype:trojan-activity; sid:100000519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.232.36",nocase; classtype:trojan-activity; sid:100000520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.38.232",nocase; classtype:trojan-activity; sid:100000521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.232",nocase; classtype:trojan-activity; sid:100000017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.234",nocase; classtype:trojan-activity; sid:100000018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.237",nocase; classtype:trojan-activity; sid:100000019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.245",nocase; classtype:trojan-activity; sid:100000020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.249",nocase; classtype:trojan-activity; sid:100000021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.25",nocase; classtype:trojan-activity; sid:100000022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.38",nocase; classtype:trojan-activity; sid:100000023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.41",nocase; classtype:trojan-activity; sid:100000024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.43",nocase; classtype:trojan-activity; sid:100000025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.45",nocase; classtype:trojan-activity; sid:100000026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.56",nocase; classtype:trojan-activity; sid:100000027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.69",nocase; classtype:trojan-activity; sid:100000028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.8",nocase; classtype:trojan-activity; sid:100000029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.80",nocase; classtype:trojan-activity; sid:100000030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.94",nocase; classtype:trojan-activity; sid:100000031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.98",nocase; classtype:trojan-activity; sid:100000032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.10",nocase; classtype:trojan-activity; sid:100000033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.103",nocase; classtype:trojan-activity; sid:100000034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.105",nocase; classtype:trojan-activity; sid:100000035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.126",nocase; classtype:trojan-activity; sid:100000036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.127",nocase; classtype:trojan-activity; sid:100000037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.130",nocase; classtype:trojan-activity; sid:100000038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.146",nocase; classtype:trojan-activity; sid:100000039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.148",nocase; classtype:trojan-activity; sid:100000040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.15",nocase; classtype:trojan-activity; sid:100000041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.151",nocase; classtype:trojan-activity; sid:100000042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.18",nocase; classtype:trojan-activity; sid:100000043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.32",nocase; classtype:trojan-activity; sid:100000044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.35",nocase; classtype:trojan-activity; sid:100000045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.4",nocase; classtype:trojan-activity; sid:100000046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.49",nocase; classtype:trojan-activity; sid:100000047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.54",nocase; classtype:trojan-activity; sid:100000048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.58",nocase; classtype:trojan-activity; sid:100000049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.59",nocase; classtype:trojan-activity; sid:100000050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.6",nocase; classtype:trojan-activity; sid:100000051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.61",nocase; classtype:trojan-activity; sid:100000052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.71",nocase; classtype:trojan-activity; sid:100000053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.83",nocase; classtype:trojan-activity; sid:100000054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.94",nocase; classtype:trojan-activity; sid:100000055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.247.221.141",nocase; classtype:trojan-activity; sid:100000056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.247.221.142",nocase; classtype:trojan-activity; sid:100000057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.250.159.41",nocase; classtype:trojan-activity; sid:100000058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.252.102.28",nocase; classtype:trojan-activity; sid:100000059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.254.250.52",nocase; classtype:trojan-activity; sid:100000060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.60.77.53",nocase; classtype:trojan-activity; sid:100000061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.65.166.225",nocase; classtype:trojan-activity; sid:100000062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.82.104.89",nocase; classtype:trojan-activity; sid:100000063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.12.184.63",nocase; classtype:trojan-activity; sid:100000064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.2.131.143",nocase; classtype:trojan-activity; sid:100000065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.8.77.4",nocase; classtype:trojan-activity; sid:100000066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1008691.com",nocase; classtype:trojan-activity; sid:100000067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.130.108",nocase; classtype:trojan-activity; sid:100000068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.16.183.179",nocase; classtype:trojan-activity; sid:100000069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.16.98.170",nocase; classtype:trojan-activity; sid:100000070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.229.85.127",nocase; classtype:trojan-activity; sid:100000071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.255.36.154",nocase; classtype:trojan-activity; sid:100000072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.105.132",nocase; classtype:trojan-activity; sid:100000073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.106.134",nocase; classtype:trojan-activity; sid:100000074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.145.2",nocase; classtype:trojan-activity; sid:100000075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.76.34",nocase; classtype:trojan-activity; sid:100000076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.30.128.184",nocase; classtype:trojan-activity; sid:100000077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.30.38.204",nocase; classtype:trojan-activity; sid:100000078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.64.119.250",nocase; classtype:trojan-activity; sid:100000079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.64.161.70",nocase; classtype:trojan-activity; sid:100000080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.66.81.70",nocase; classtype:trojan-activity; sid:100000081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.75.157.99",nocase; classtype:trojan-activity; sid:100000082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.130.115.14",nocase; classtype:trojan-activity; sid:100000083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.141.240.139",nocase; classtype:trojan-activity; sid:100000084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.107.113.22",nocase; classtype:trojan-activity; sid:100000085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.124.104.118",nocase; classtype:trojan-activity; sid:100000086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.125.218.107",nocase; classtype:trojan-activity; sid:100000087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.126.35.40",nocase; classtype:trojan-activity; sid:100000088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.139.89.205",nocase; classtype:trojan-activity; sid:100000089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.141.138.12",nocase; classtype:trojan-activity; sid:100000090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.145.13.24",nocase; classtype:trojan-activity; sid:100000091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.146.174.208",nocase; classtype:trojan-activity; sid:100000092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.153.92.76",nocase; classtype:trojan-activity; sid:100000093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.156.221.66",nocase; classtype:trojan-activity; sid:100000094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.159.155.214",nocase; classtype:trojan-activity; sid:100000095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.16.145.25",nocase; classtype:trojan-activity; sid:100000096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.207.1.146",nocase; classtype:trojan-activity; sid:100000097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.214.191.141",nocase; classtype:trojan-activity; sid:100000098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.217.215.21",nocase; classtype:trojan-activity; sid:100000099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.40",nocase; classtype:trojan-activity; sid:100000100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.3",nocase; classtype:trojan-activity; sid:100000101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.4",nocase; classtype:trojan-activity; sid:100000102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.240.249.121",nocase; classtype:trojan-activity; sid:100000103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.245.49.180",nocase; classtype:trojan-activity; sid:100000104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.4.117.26",nocase; classtype:trojan-activity; sid:100000105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.66.78.171",nocase; classtype:trojan-activity; sid:100000106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.79.112.254",nocase; classtype:trojan-activity; sid:100000107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.98.170",nocase; classtype:trojan-activity; sid:100000108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.240.130",nocase; classtype:trojan-activity; sid:100000109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.240.228",nocase; classtype:trojan-activity; sid:100000110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.241.123",nocase; classtype:trojan-activity; sid:100000111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.241.94",nocase; classtype:trojan-activity; sid:100000112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.12",nocase; classtype:trojan-activity; sid:100000113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.14",nocase; classtype:trojan-activity; sid:100000114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.16",nocase; classtype:trojan-activity; sid:100000115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.17",nocase; classtype:trojan-activity; sid:100000116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.19",nocase; classtype:trojan-activity; sid:100000117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.20",nocase; classtype:trojan-activity; sid:100000118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.27",nocase; classtype:trojan-activity; sid:100000119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.28",nocase; classtype:trojan-activity; sid:100000120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.3",nocase; classtype:trojan-activity; sid:100000121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.30",nocase; classtype:trojan-activity; sid:100000122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.36",nocase; classtype:trojan-activity; sid:100000123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.41",nocase; classtype:trojan-activity; sid:100000124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.46",nocase; classtype:trojan-activity; sid:100000125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.49",nocase; classtype:trojan-activity; sid:100000126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.54",nocase; classtype:trojan-activity; sid:100000127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.58",nocase; classtype:trojan-activity; sid:100000128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.90",nocase; classtype:trojan-activity; sid:100000129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.95",nocase; classtype:trojan-activity; sid:100000130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.184.75.123",nocase; classtype:trojan-activity; sid:100000131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.33.52.85",nocase; classtype:trojan-activity; sid:100000132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.61.86.37",nocase; classtype:trojan-activity; sid:100000133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.1.112.12",nocase; classtype:trojan-activity; sid:100000134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.172.178",nocase; classtype:trojan-activity; sid:100000135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.193.155",nocase; classtype:trojan-activity; sid:100000136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.105.33.43",nocase; classtype:trojan-activity; sid:100000137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.113.177.60",nocase; classtype:trojan-activity; sid:100000138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.165.234",nocase; classtype:trojan-activity; sid:100000139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.193.132",nocase; classtype:trojan-activity; sid:100000140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.249.148",nocase; classtype:trojan-activity; sid:100000141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.155.54",nocase; classtype:trojan-activity; sid:100000142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.219.80",nocase; classtype:trojan-activity; sid:100000143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.144.195",nocase; classtype:trojan-activity; sid:100000144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.250.107",nocase; classtype:trojan-activity; sid:100000145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.197.135",nocase; classtype:trojan-activity; sid:100000146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.31.130",nocase; classtype:trojan-activity; sid:100000147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.181.136.96",nocase; classtype:trojan-activity; sid:100000148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.189.8.75",nocase; classtype:trojan-activity; sid:100000149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.194.242.170",nocase; classtype:trojan-activity; sid:100000150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.219.185.75",nocase; classtype:trojan-activity; sid:100000151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.220.119.25",nocase; classtype:trojan-activity; sid:100000152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.221.96.202",nocase; classtype:trojan-activity; sid:100000153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.201.37",nocase; classtype:trojan-activity; sid:100000154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.250.48",nocase; classtype:trojan-activity; sid:100000155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.55.199.65",nocase; classtype:trojan-activity; sid:100000156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.104.151.108",nocase; classtype:trojan-activity; sid:100000157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.124.90.229",nocase; classtype:trojan-activity; sid:100000158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.233.196.232",nocase; classtype:trojan-activity; sid:100000159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.235.7.228",nocase; classtype:trojan-activity; sid:100000160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.86.85.253",nocase; classtype:trojan-activity; sid:100000161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.102",nocase; classtype:trojan-activity; sid:100000162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.230",nocase; classtype:trojan-activity; sid:100000163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.127.90",nocase; classtype:trojan-activity; sid:100000164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.57.246",nocase; classtype:trojan-activity; sid:100000165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.99.37.97",nocase; classtype:trojan-activity; sid:100000166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.10.58.38",nocase; classtype:trojan-activity; sid:100000167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.12.123.11",nocase; classtype:trojan-activity; sid:100000168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.14.58.190",nocase; classtype:trojan-activity; sid:100000169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.187.229.182",nocase; classtype:trojan-activity; sid:100000170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.190.50",nocase; classtype:trojan-activity; sid:100000171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.195.46",nocase; classtype:trojan-activity; sid:100000172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.241.119.168",nocase; classtype:trojan-activity; sid:100000173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.241.23.107",nocase; classtype:trojan-activity; sid:100000174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.247.151.4",nocase; classtype:trojan-activity; sid:100000175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.247.153.186",nocase; classtype:trojan-activity; sid:100000176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.124.254",nocase; classtype:trojan-activity; sid:100000177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.175.141",nocase; classtype:trojan-activity; sid:100000178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.251.194",nocase; classtype:trojan-activity; sid:100000179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.251.10.18",nocase; classtype:trojan-activity; sid:100000180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.213.198",nocase; classtype:trojan-activity; sid:100000181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.51.112",nocase; classtype:trojan-activity; sid:100000182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.255.101.184",nocase; classtype:trojan-activity; sid:100000183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.255.167.147",nocase; classtype:trojan-activity; sid:100000184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.145.127",nocase; classtype:trojan-activity; sid:100000185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.209.175",nocase; classtype:trojan-activity; sid:100000186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.221.77",nocase; classtype:trojan-activity; sid:100000187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.235.57",nocase; classtype:trojan-activity; sid:100000188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.4.2",nocase; classtype:trojan-activity; sid:100000189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110fss.net",nocase; classtype:trojan-activity; sid:100000190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.111.207",nocase; classtype:trojan-activity; sid:100000191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.88.61",nocase; classtype:trojan-activity; sid:100000192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.119.245.114",nocase; classtype:trojan-activity; sid:100000193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.125.67.125",nocase; classtype:trojan-activity; sid:100000194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.162.224.14",nocase; classtype:trojan-activity; sid:100000195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.163.50.120",nocase; classtype:trojan-activity; sid:100000196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.165.21.195",nocase; classtype:trojan-activity; sid:100000197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.165.28.234",nocase; classtype:trojan-activity; sid:100000198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.84.182",nocase; classtype:trojan-activity; sid:100000199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.86.133",nocase; classtype:trojan-activity; sid:100000200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.172.164.104",nocase; classtype:trojan-activity; sid:100000201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.176.182.149",nocase; classtype:trojan-activity; sid:100000202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.179.153.69",nocase; classtype:trojan-activity; sid:100000203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.179.243.126",nocase; classtype:trojan-activity; sid:100000204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.182.232.18",nocase; classtype:trojan-activity; sid:100000205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.177.85",nocase; classtype:trojan-activity; sid:100000206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.23.84",nocase; classtype:trojan-activity; sid:100000207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.230.136",nocase; classtype:trojan-activity; sid:100000208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.27.9",nocase; classtype:trojan-activity; sid:100000209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.48.248",nocase; classtype:trojan-activity; sid:100000210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.114",nocase; classtype:trojan-activity; sid:100000211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.122",nocase; classtype:trojan-activity; sid:100000212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.13",nocase; classtype:trojan-activity; sid:100000213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.66",nocase; classtype:trojan-activity; sid:100000214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.141",nocase; classtype:trojan-activity; sid:100000215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.165",nocase; classtype:trojan-activity; sid:100000216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.128",nocase; classtype:trojan-activity; sid:100000217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.19",nocase; classtype:trojan-activity; sid:100000218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.48",nocase; classtype:trojan-activity; sid:100000219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.222",nocase; classtype:trojan-activity; sid:100000220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.223",nocase; classtype:trojan-activity; sid:100000221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.228",nocase; classtype:trojan-activity; sid:100000222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.15",nocase; classtype:trojan-activity; sid:100000223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.184",nocase; classtype:trojan-activity; sid:100000224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.197",nocase; classtype:trojan-activity; sid:100000225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.200",nocase; classtype:trojan-activity; sid:100000226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.23",nocase; classtype:trojan-activity; sid:100000227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.26.243",nocase; classtype:trojan-activity; sid:100000228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.8.81",nocase; classtype:trojan-activity; sid:100000229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.61.52.53",nocase; classtype:trojan-activity; sid:100000230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.108.184",nocase; classtype:trojan-activity; sid:100000231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.31.175",nocase; classtype:trojan-activity; sid:100000232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.122.62.224",nocase; classtype:trojan-activity; sid:100000233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.122.63.70",nocase; classtype:trojan-activity; sid:100000234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.132.134.106",nocase; classtype:trojan-activity; sid:100000235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.132.147.102",nocase; classtype:trojan-activity; sid:100000236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.159.108.96",nocase; classtype:trojan-activity; sid:100000237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.167.165.139",nocase; classtype:trojan-activity; sid:100000238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.124.75",nocase; classtype:trojan-activity; sid:100000239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.233.9",nocase; classtype:trojan-activity; sid:100000240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.210.211",nocase; classtype:trojan-activity; sid:100000241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.96.252",nocase; classtype:trojan-activity; sid:100000242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.187.91.117",nocase; classtype:trojan-activity; sid:100000243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.214.127.42",nocase; classtype:trojan-activity; sid:100000244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.187.19",nocase; classtype:trojan-activity; sid:100000245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.236.77",nocase; classtype:trojan-activity; sid:100000246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.43.27",nocase; classtype:trojan-activity; sid:100000247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.52.145",nocase; classtype:trojan-activity; sid:100000248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.82.4",nocase; classtype:trojan-activity; sid:100000249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.118.229",nocase; classtype:trojan-activity; sid:100000250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.195.104",nocase; classtype:trojan-activity; sid:100000251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.202.111",nocase; classtype:trojan-activity; sid:100000252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.67.193",nocase; classtype:trojan-activity; sid:100000253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.92.34",nocase; classtype:trojan-activity; sid:100000254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.180.95",nocase; classtype:trojan-activity; sid:100000255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.114",nocase; classtype:trojan-activity; sid:100000256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.137",nocase; classtype:trojan-activity; sid:100000257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.178.109",nocase; classtype:trojan-activity; sid:100000258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.188.28",nocase; classtype:trojan-activity; sid:100000259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.199.19",nocase; classtype:trojan-activity; sid:100000260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.230.251.85",nocase; classtype:trojan-activity; sid:100000261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.134.244",nocase; classtype:trojan-activity; sid:100000262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.16.252",nocase; classtype:trojan-activity; sid:100000263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.194.178",nocase; classtype:trojan-activity; sid:100000264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.216.151",nocase; classtype:trojan-activity; sid:100000265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.218.202",nocase; classtype:trojan-activity; sid:100000266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.149.73",nocase; classtype:trojan-activity; sid:100000267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.188.86",nocase; classtype:trojan-activity; sid:100000268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.126.177",nocase; classtype:trojan-activity; sid:100000269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.171.69",nocase; classtype:trojan-activity; sid:100000270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.228.21",nocase; classtype:trojan-activity; sid:100000271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.141.241",nocase; classtype:trojan-activity; sid:100000272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.144.226",nocase; classtype:trojan-activity; sid:100000273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.172.106",nocase; classtype:trojan-activity; sid:100000274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.197.144",nocase; classtype:trojan-activity; sid:100000275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.230.192",nocase; classtype:trojan-activity; sid:100000276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.75.157",nocase; classtype:trojan-activity; sid:100000277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.143.135",nocase; classtype:trojan-activity; sid:100000278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.17.120",nocase; classtype:trojan-activity; sid:100000279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.190.207",nocase; classtype:trojan-activity; sid:100000280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.194.18",nocase; classtype:trojan-activity; sid:100000281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.227.228",nocase; classtype:trojan-activity; sid:100000282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.39.2",nocase; classtype:trojan-activity; sid:100000283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.73.181",nocase; classtype:trojan-activity; sid:100000284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.184.162",nocase; classtype:trojan-activity; sid:100000285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.216.17",nocase; classtype:trojan-activity; sid:100000286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.241.187.165",nocase; classtype:trojan-activity; sid:100000287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.106.228",nocase; classtype:trojan-activity; sid:100000288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.18.128",nocase; classtype:trojan-activity; sid:100000289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.2.247",nocase; classtype:trojan-activity; sid:100000290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.97.131",nocase; classtype:trojan-activity; sid:100000291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.243.115.183",nocase; classtype:trojan-activity; sid:100000292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.12.89",nocase; classtype:trojan-activity; sid:100000293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.178.153",nocase; classtype:trojan-activity; sid:100000294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.5.141",nocase; classtype:trojan-activity; sid:100000295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.8.24",nocase; classtype:trojan-activity; sid:100000296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.162.50",nocase; classtype:trojan-activity; sid:100000297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.180.49",nocase; classtype:trojan-activity; sid:100000298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.100.14",nocase; classtype:trojan-activity; sid:100000299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.16.222",nocase; classtype:trojan-activity; sid:100000300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.161.45",nocase; classtype:trojan-activity; sid:100000301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.191.118",nocase; classtype:trojan-activity; sid:100000302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.214.146",nocase; classtype:trojan-activity; sid:100000303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.240.226",nocase; classtype:trojan-activity; sid:100000304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.25.42",nocase; classtype:trojan-activity; sid:100000305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.81.173",nocase; classtype:trojan-activity; sid:100000306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.82.122",nocase; classtype:trojan-activity; sid:100000307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.148.90",nocase; classtype:trojan-activity; sid:100000308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.179.239",nocase; classtype:trojan-activity; sid:100000309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.197.164",nocase; classtype:trojan-activity; sid:100000310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.44.153",nocase; classtype:trojan-activity; sid:100000311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.109.217",nocase; classtype:trojan-activity; sid:100000312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.118.157",nocase; classtype:trojan-activity; sid:100000313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.165.240",nocase; classtype:trojan-activity; sid:100000314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.206.69",nocase; classtype:trojan-activity; sid:100000315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.26.129",nocase; classtype:trojan-activity; sid:100000316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.41.142",nocase; classtype:trojan-activity; sid:100000317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.79.98",nocase; classtype:trojan-activity; sid:100000318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.102.173",nocase; classtype:trojan-activity; sid:100000319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.57.99",nocase; classtype:trojan-activity; sid:100000320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.17.5",nocase; classtype:trojan-activity; sid:100000321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.218.210",nocase; classtype:trojan-activity; sid:100000322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.23.55",nocase; classtype:trojan-activity; sid:100000323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.136.84",nocase; classtype:trojan-activity; sid:100000324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.199.150",nocase; classtype:trojan-activity; sid:100000325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.221.244",nocase; classtype:trojan-activity; sid:100000326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.239.103",nocase; classtype:trojan-activity; sid:100000327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.245.249",nocase; classtype:trojan-activity; sid:100000328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.46.212",nocase; classtype:trojan-activity; sid:100000329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.128.160",nocase; classtype:trojan-activity; sid:100000330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.188.228",nocase; classtype:trojan-activity; sid:100000331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.208.123",nocase; classtype:trojan-activity; sid:100000332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.32.5",nocase; classtype:trojan-activity; sid:100000333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.127.212",nocase; classtype:trojan-activity; sid:100000334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.38.10",nocase; classtype:trojan-activity; sid:100000335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.6.129",nocase; classtype:trojan-activity; sid:100000336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.8.235",nocase; classtype:trojan-activity; sid:100000337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.121.163",nocase; classtype:trojan-activity; sid:100000338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.123.174",nocase; classtype:trojan-activity; sid:100000339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.109",nocase; classtype:trojan-activity; sid:100000340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.110",nocase; classtype:trojan-activity; sid:100000341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.111",nocase; classtype:trojan-activity; sid:100000342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.112",nocase; classtype:trojan-activity; sid:100000343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.113",nocase; classtype:trojan-activity; sid:100000344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.117",nocase; classtype:trojan-activity; sid:100000345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.119",nocase; classtype:trojan-activity; sid:100000346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.122",nocase; classtype:trojan-activity; sid:100000347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.124",nocase; classtype:trojan-activity; sid:100000348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.127",nocase; classtype:trojan-activity; sid:100000349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.128",nocase; classtype:trojan-activity; sid:100000350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.130",nocase; classtype:trojan-activity; sid:100000351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.131",nocase; classtype:trojan-activity; sid:100000352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.132",nocase; classtype:trojan-activity; sid:100000353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.133",nocase; classtype:trojan-activity; sid:100000354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.136",nocase; classtype:trojan-activity; sid:100000355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.138",nocase; classtype:trojan-activity; sid:100000356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.139",nocase; classtype:trojan-activity; sid:100000357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.142",nocase; classtype:trojan-activity; sid:100000358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.143",nocase; classtype:trojan-activity; sid:100000359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.146",nocase; classtype:trojan-activity; sid:100000360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.149",nocase; classtype:trojan-activity; sid:100000361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.150",nocase; classtype:trojan-activity; sid:100000362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.151",nocase; classtype:trojan-activity; sid:100000363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.155",nocase; classtype:trojan-activity; sid:100000364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.158",nocase; classtype:trojan-activity; sid:100000365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.160",nocase; classtype:trojan-activity; sid:100000366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.162",nocase; classtype:trojan-activity; sid:100000367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.163",nocase; classtype:trojan-activity; sid:100000368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.165",nocase; classtype:trojan-activity; sid:100000369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.168",nocase; classtype:trojan-activity; sid:100000370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.171",nocase; classtype:trojan-activity; sid:100000371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.172",nocase; classtype:trojan-activity; sid:100000372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.174",nocase; classtype:trojan-activity; sid:100000373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.175",nocase; classtype:trojan-activity; sid:100000374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.176",nocase; classtype:trojan-activity; sid:100000375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.178",nocase; classtype:trojan-activity; sid:100000376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.179",nocase; classtype:trojan-activity; sid:100000377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.71",nocase; classtype:trojan-activity; sid:100000378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.126.243",nocase; classtype:trojan-activity; sid:100000379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.127.155",nocase; classtype:trojan-activity; sid:100000380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.120",nocase; classtype:trojan-activity; sid:100000381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.121",nocase; classtype:trojan-activity; sid:100000382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.82.29",nocase; classtype:trojan-activity; sid:100000383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.182",nocase; classtype:trojan-activity; sid:100000384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.23",nocase; classtype:trojan-activity; sid:100000385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.85.113",nocase; classtype:trojan-activity; sid:100000386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.87.203",nocase; classtype:trojan-activity; sid:100000387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.87.213",nocase; classtype:trojan-activity; sid:100000388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.88.116",nocase; classtype:trojan-activity; sid:100000389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.212",nocase; classtype:trojan-activity; sid:100000390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.247",nocase; classtype:trojan-activity; sid:100000391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.133",nocase; classtype:trojan-activity; sid:100000392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.149",nocase; classtype:trojan-activity; sid:100000393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.150",nocase; classtype:trojan-activity; sid:100000394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.158",nocase; classtype:trojan-activity; sid:100000395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.164",nocase; classtype:trojan-activity; sid:100000396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.168",nocase; classtype:trojan-activity; sid:100000397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.177",nocase; classtype:trojan-activity; sid:100000398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.178",nocase; classtype:trojan-activity; sid:100000399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.181",nocase; classtype:trojan-activity; sid:100000400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.182",nocase; classtype:trojan-activity; sid:100000401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.188",nocase; classtype:trojan-activity; sid:100000402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.190",nocase; classtype:trojan-activity; sid:100000403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.194",nocase; classtype:trojan-activity; sid:100000404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.197",nocase; classtype:trojan-activity; sid:100000405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.211",nocase; classtype:trojan-activity; sid:100000406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.219",nocase; classtype:trojan-activity; sid:100000407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.229",nocase; classtype:trojan-activity; sid:100000408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.230",nocase; classtype:trojan-activity; sid:100000409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.245",nocase; classtype:trojan-activity; sid:100000410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.247",nocase; classtype:trojan-activity; sid:100000411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.54",nocase; classtype:trojan-activity; sid:100000412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.55",nocase; classtype:trojan-activity; sid:100000413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.57",nocase; classtype:trojan-activity; sid:100000414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.60",nocase; classtype:trojan-activity; sid:100000415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.90",nocase; classtype:trojan-activity; sid:100000416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.91",nocase; classtype:trojan-activity; sid:100000417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.100.228",nocase; classtype:trojan-activity; sid:100000418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.30",nocase; classtype:trojan-activity; sid:100000419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.31",nocase; classtype:trojan-activity; sid:100000420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.36",nocase; classtype:trojan-activity; sid:100000421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.37",nocase; classtype:trojan-activity; sid:100000422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.38",nocase; classtype:trojan-activity; sid:100000423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.41",nocase; classtype:trojan-activity; sid:100000424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.42",nocase; classtype:trojan-activity; sid:100000425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.43",nocase; classtype:trojan-activity; sid:100000426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.51",nocase; classtype:trojan-activity; sid:100000427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.52",nocase; classtype:trojan-activity; sid:100000428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.57",nocase; classtype:trojan-activity; sid:100000429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.58",nocase; classtype:trojan-activity; sid:100000430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.60",nocase; classtype:trojan-activity; sid:100000431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.62",nocase; classtype:trojan-activity; sid:100000432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.126.156",nocase; classtype:trojan-activity; sid:100000433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.35.237",nocase; classtype:trojan-activity; sid:100000434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.38.100",nocase; classtype:trojan-activity; sid:100000435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.38.19",nocase; classtype:trojan-activity; sid:100000436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.118",nocase; classtype:trojan-activity; sid:100000437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.119",nocase; classtype:trojan-activity; sid:100000438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.121",nocase; classtype:trojan-activity; sid:100000439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.136",nocase; classtype:trojan-activity; sid:100000440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.37",nocase; classtype:trojan-activity; sid:100000441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.52",nocase; classtype:trojan-activity; sid:100000442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.53",nocase; classtype:trojan-activity; sid:100000443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.57",nocase; classtype:trojan-activity; sid:100000444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.61",nocase; classtype:trojan-activity; sid:100000445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.70",nocase; classtype:trojan-activity; sid:100000446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.73",nocase; classtype:trojan-activity; sid:100000447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.77",nocase; classtype:trojan-activity; sid:100000448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.90",nocase; classtype:trojan-activity; sid:100000449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.176.16",nocase; classtype:trojan-activity; sid:100000450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.211.135",nocase; classtype:trojan-activity; sid:100000451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.82.160",nocase; classtype:trojan-activity; sid:100000452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.87.98",nocase; classtype:trojan-activity; sid:100000453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.224.79",nocase; classtype:trojan-activity; sid:100000454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.65.53.175",nocase; classtype:trojan-activity; sid:100000455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.153.37",nocase; classtype:trojan-activity; sid:100000456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.159",nocase; classtype:trojan-activity; sid:100000457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.49",nocase; classtype:trojan-activity; sid:100000458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.53",nocase; classtype:trojan-activity; sid:100000459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.112",nocase; classtype:trojan-activity; sid:100000460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.84",nocase; classtype:trojan-activity; sid:100000461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.226.202",nocase; classtype:trojan-activity; sid:100000462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.231.35",nocase; classtype:trojan-activity; sid:100000463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.78.45.158",nocase; classtype:trojan-activity; sid:100000464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.118.16",nocase; classtype:trojan-activity; sid:100000465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.127.91",nocase; classtype:trojan-activity; sid:100000466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.215.101",nocase; classtype:trojan-activity; sid:100000467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.81.161.10",nocase; classtype:trojan-activity; sid:100000468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.81.199.218",nocase; classtype:trojan-activity; sid:100000469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.131.124",nocase; classtype:trojan-activity; sid:100000470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.146.253",nocase; classtype:trojan-activity; sid:100000471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.18.255",nocase; classtype:trojan-activity; sid:100000472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.224.139",nocase; classtype:trojan-activity; sid:100000473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.227.41",nocase; classtype:trojan-activity; sid:100000474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.228.175",nocase; classtype:trojan-activity; sid:100000475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.83.118.203",nocase; classtype:trojan-activity; sid:100000476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.83.230.37",nocase; classtype:trojan-activity; sid:100000477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.86.133.125",nocase; classtype:trojan-activity; sid:100000478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.9.140.247",nocase; classtype:trojan-activity; sid:100000479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.91.219.195",nocase; classtype:trojan-activity; sid:100000480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.93.29.211",nocase; classtype:trojan-activity; sid:100000481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.0.74.25",nocase; classtype:trojan-activity; sid:100000482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.11.95.254",nocase; classtype:trojan-activity; sid:100000483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.110.204.254",nocase; classtype:trojan-activity; sid:100000484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.118.13.194",nocase; classtype:trojan-activity; sid:100000485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.118.159.178",nocase; classtype:trojan-activity; sid:100000486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.119.37.141",nocase; classtype:trojan-activity; sid:100000487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.238.68",nocase; classtype:trojan-activity; sid:100000488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.59.84",nocase; classtype:trojan-activity; sid:100000489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.58.249",nocase; classtype:trojan-activity; sid:100000490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.172.250.35",nocase; classtype:trojan-activity; sid:100000491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.189.243.248",nocase; classtype:trojan-activity; sid:100000492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.193.29.42",nocase; classtype:trojan-activity; sid:100000493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.194.133.9",nocase; classtype:trojan-activity; sid:100000494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.194.135.154",nocase; classtype:trojan-activity; sid:100000495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.163.26",nocase; classtype:trojan-activity; sid:100000496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.166.46",nocase; classtype:trojan-activity; sid:100000497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.168.190",nocase; classtype:trojan-activity; sid:100000498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.201.219.47",nocase; classtype:trojan-activity; sid:100000499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.226.42.250",nocase; classtype:trojan-activity; sid:100000500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.128.9",nocase; classtype:trojan-activity; sid:100000501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.169.170",nocase; classtype:trojan-activity; sid:100000502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.194.172",nocase; classtype:trojan-activity; sid:100000503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.35.229",nocase; classtype:trojan-activity; sid:100000504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.211.131",nocase; classtype:trojan-activity; sid:100000505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.93.142",nocase; classtype:trojan-activity; sid:100000506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.232.156.157",nocase; classtype:trojan-activity; sid:100000507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.234.224.130",nocase; classtype:trojan-activity; sid:100000508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.235.116.209",nocase; classtype:trojan-activity; sid:100000509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.253.144.141",nocase; classtype:trojan-activity; sid:100000510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.254.169.251",nocase; classtype:trojan-activity; sid:100000511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.128.133",nocase; classtype:trojan-activity; sid:100000512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.154.21",nocase; classtype:trojan-activity; sid:100000513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.191.47",nocase; classtype:trojan-activity; sid:100000514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.61.204.205",nocase; classtype:trojan-activity; sid:100000515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.86.204.13",nocase; classtype:trojan-activity; sid:100000516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.87.203.239",nocase; classtype:trojan-activity; sid:100000517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.232.36",nocase; classtype:trojan-activity; sid:100000518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.38.232",nocase; classtype:trojan-activity; sid:100000519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.39.21",nocase; classtype:trojan-activity; sid:100000520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.90.27.218",nocase; classtype:trojan-activity; sid:100000521; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.92.93.208",nocase; classtype:trojan-activity; sid:100000522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.199.204.37",nocase; classtype:trojan-activity; sid:100000523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.199.253.235",nocase; classtype:trojan-activity; sid:100000524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.224.203.128",nocase; classtype:trojan-activity; sid:100000525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.226.100.56",nocase; classtype:trojan-activity; sid:100000526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.227.156.119",nocase; classtype:trojan-activity; sid:100000527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.228.205.101",nocase; classtype:trojan-activity; sid:100000528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.228.242.109",nocase; classtype:trojan-activity; sid:100000529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.229.165.194",nocase; classtype:trojan-activity; sid:100000530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.229.52.14",nocase; classtype:trojan-activity; sid:100000531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.234.189.154",nocase; classtype:trojan-activity; sid:100000532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.235.115.236",nocase; classtype:trojan-activity; sid:100000533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.30.54.64",nocase; classtype:trojan-activity; sid:100000534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.161.94",nocase; classtype:trojan-activity; sid:100000535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.172.42",nocase; classtype:trojan-activity; sid:100000536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.165.216.112",nocase; classtype:trojan-activity; sid:100000537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.171.239.28",nocase; classtype:trojan-activity; sid:100000538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.193.83.0",nocase; classtype:trojan-activity; sid:100000539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.201.38.185",nocase; classtype:trojan-activity; sid:100000540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.201.98.176",nocase; classtype:trojan-activity; sid:100000541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.208.97.42",nocase; classtype:trojan-activity; sid:100000542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.209.234.226",nocase; classtype:trojan-activity; sid:100000543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.223.159.80",nocase; classtype:trojan-activity; sid:100000544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.229.250.130",nocase; classtype:trojan-activity; sid:100000545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.23.88.135",nocase; classtype:trojan-activity; sid:100000546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.42.47.36",nocase; classtype:trojan-activity; sid:100000547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.163.47",nocase; classtype:trojan-activity; sid:100000548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.179.43",nocase; classtype:trojan-activity; sid:100000549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.188.17",nocase; classtype:trojan-activity; sid:100000550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.200.115",nocase; classtype:trojan-activity; sid:100000551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.49.84",nocase; classtype:trojan-activity; sid:100000552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.124.80",nocase; classtype:trojan-activity; sid:100000553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.158.175",nocase; classtype:trojan-activity; sid:100000554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.36.220",nocase; classtype:trojan-activity; sid:100000555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.43.52",nocase; classtype:trojan-activity; sid:100000556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.80.117",nocase; classtype:trojan-activity; sid:100000557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.96.88",nocase; classtype:trojan-activity; sid:100000558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.15.24",nocase; classtype:trojan-activity; sid:100000559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.199.253.235",nocase; classtype:trojan-activity; sid:100000523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.224.203.128",nocase; classtype:trojan-activity; sid:100000524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.226.100.56",nocase; classtype:trojan-activity; sid:100000525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.227.156.119",nocase; classtype:trojan-activity; sid:100000526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.228.205.101",nocase; classtype:trojan-activity; sid:100000527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.228.242.109",nocase; classtype:trojan-activity; sid:100000528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.229.165.194",nocase; classtype:trojan-activity; sid:100000529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.229.52.14",nocase; classtype:trojan-activity; sid:100000530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.234.189.154",nocase; classtype:trojan-activity; sid:100000531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.235.115.236",nocase; classtype:trojan-activity; sid:100000532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.161.94",nocase; classtype:trojan-activity; sid:100000533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.172.42",nocase; classtype:trojan-activity; sid:100000534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.165.216.112",nocase; classtype:trojan-activity; sid:100000535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.171.239.28",nocase; classtype:trojan-activity; sid:100000536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.193.83.0",nocase; classtype:trojan-activity; sid:100000537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.201.38.185",nocase; classtype:trojan-activity; sid:100000538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.201.98.176",nocase; classtype:trojan-activity; sid:100000539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.205.197.221",nocase; classtype:trojan-activity; sid:100000540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.208.97.42",nocase; classtype:trojan-activity; sid:100000541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.209.234.226",nocase; classtype:trojan-activity; sid:100000542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.223.159.80",nocase; classtype:trojan-activity; sid:100000543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.229.250.130",nocase; classtype:trojan-activity; sid:100000544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.42.47.36",nocase; classtype:trojan-activity; sid:100000545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.163.47",nocase; classtype:trojan-activity; sid:100000546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.179.43",nocase; classtype:trojan-activity; sid:100000547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.188.17",nocase; classtype:trojan-activity; sid:100000548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.201.26",nocase; classtype:trojan-activity; sid:100000549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.41.101",nocase; classtype:trojan-activity; sid:100000550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.124.80",nocase; classtype:trojan-activity; sid:100000551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.158.175",nocase; classtype:trojan-activity; sid:100000552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.24.63",nocase; classtype:trojan-activity; sid:100000553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.36.220",nocase; classtype:trojan-activity; sid:100000554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.79.131",nocase; classtype:trojan-activity; sid:100000555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.1.41",nocase; classtype:trojan-activity; sid:100000556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.168.160",nocase; classtype:trojan-activity; sid:100000557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.171.192",nocase; classtype:trojan-activity; sid:100000558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.175.205",nocase; classtype:trojan-activity; sid:100000559; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.19.136",nocase; classtype:trojan-activity; sid:100000560; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.20.73",nocase; classtype:trojan-activity; sid:100000561; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.206.128",nocase; classtype:trojan-activity; sid:100000562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.226.30",nocase; classtype:trojan-activity; sid:100000563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.228.168",nocase; classtype:trojan-activity; sid:100000564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.238.227",nocase; classtype:trojan-activity; sid:100000565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.239.77",nocase; classtype:trojan-activity; sid:100000566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.240.72",nocase; classtype:trojan-activity; sid:100000567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.211.74",nocase; classtype:trojan-activity; sid:100000563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.238.227",nocase; classtype:trojan-activity; sid:100000564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.239.77",nocase; classtype:trojan-activity; sid:100000565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.242.7",nocase; classtype:trojan-activity; sid:100000566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.247.46",nocase; classtype:trojan-activity; sid:100000567; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.61.82",nocase; classtype:trojan-activity; sid:100000568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.91.30",nocase; classtype:trojan-activity; sid:100000569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.96.254",nocase; classtype:trojan-activity; sid:100000570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.104.85",nocase; classtype:trojan-activity; sid:100000571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.106.209",nocase; classtype:trojan-activity; sid:100000572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.79.78",nocase; classtype:trojan-activity; sid:100000569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.91.30",nocase; classtype:trojan-activity; sid:100000570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.96.254",nocase; classtype:trojan-activity; sid:100000571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.7.254",nocase; classtype:trojan-activity; sid:100000572; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.17.196",nocase; classtype:trojan-activity; sid:100000573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.53.200.130",nocase; classtype:trojan-activity; sid:100000574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.53.224.134",nocase; classtype:trojan-activity; sid:100000575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.53.234.210",nocase; classtype:trojan-activity; sid:100000576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.53.238.224",nocase; classtype:trojan-activity; sid:100000577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.123.147",nocase; classtype:trojan-activity; sid:100000578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.70.108",nocase; classtype:trojan-activity; sid:100000579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.105.154",nocase; classtype:trojan-activity; sid:100000580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.144.42",nocase; classtype:trojan-activity; sid:100000581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.145.147",nocase; classtype:trojan-activity; sid:100000582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.157.96",nocase; classtype:trojan-activity; sid:100000583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.158.230",nocase; classtype:trojan-activity; sid:100000584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.158.250",nocase; classtype:trojan-activity; sid:100000585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.161.38",nocase; classtype:trojan-activity; sid:100000586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.179.168",nocase; classtype:trojan-activity; sid:100000587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.206.35",nocase; classtype:trojan-activity; sid:100000588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.206.78",nocase; classtype:trojan-activity; sid:100000589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.26.94",nocase; classtype:trojan-activity; sid:100000590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.42.200",nocase; classtype:trojan-activity; sid:100000591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.111.63",nocase; classtype:trojan-activity; sid:100000592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.114.17",nocase; classtype:trojan-activity; sid:100000593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.132.61",nocase; classtype:trojan-activity; sid:100000594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.133.96",nocase; classtype:trojan-activity; sid:100000595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.134.79",nocase; classtype:trojan-activity; sid:100000596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.137.48",nocase; classtype:trojan-activity; sid:100000597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.139.122",nocase; classtype:trojan-activity; sid:100000598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.143.241",nocase; classtype:trojan-activity; sid:100000599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.145.102",nocase; classtype:trojan-activity; sid:100000600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.148.22",nocase; classtype:trojan-activity; sid:100000601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.151.65",nocase; classtype:trojan-activity; sid:100000602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.151.68",nocase; classtype:trojan-activity; sid:100000603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.154.147",nocase; classtype:trojan-activity; sid:100000604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.175.2",nocase; classtype:trojan-activity; sid:100000605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.189.162",nocase; classtype:trojan-activity; sid:100000606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.31.54",nocase; classtype:trojan-activity; sid:100000607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.98.205",nocase; classtype:trojan-activity; sid:100000608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.99.235",nocase; classtype:trojan-activity; sid:100000609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.132.199",nocase; classtype:trojan-activity; sid:100000610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.134.143",nocase; classtype:trojan-activity; sid:100000611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.161.17",nocase; classtype:trojan-activity; sid:100000612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.90.143",nocase; classtype:trojan-activity; sid:100000613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.198.69",nocase; classtype:trojan-activity; sid:100000614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.209.196",nocase; classtype:trojan-activity; sid:100000615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.212.193",nocase; classtype:trojan-activity; sid:100000616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.214.107",nocase; classtype:trojan-activity; sid:100000617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.228.237",nocase; classtype:trojan-activity; sid:100000618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.235.229",nocase; classtype:trojan-activity; sid:100000619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.253.202",nocase; classtype:trojan-activity; sid:100000620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.57.171",nocase; classtype:trojan-activity; sid:100000621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.82.123",nocase; classtype:trojan-activity; sid:100000622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.102.110",nocase; classtype:trojan-activity; sid:100000623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.118.201",nocase; classtype:trojan-activity; sid:100000624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.118.90",nocase; classtype:trojan-activity; sid:100000625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.139.74",nocase; classtype:trojan-activity; sid:100000626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.152.207",nocase; classtype:trojan-activity; sid:100000627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.155.83",nocase; classtype:trojan-activity; sid:100000628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.26.39",nocase; classtype:trojan-activity; sid:100000629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.139.175",nocase; classtype:trojan-activity; sid:100000630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.141.147",nocase; classtype:trojan-activity; sid:100000631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.180.149",nocase; classtype:trojan-activity; sid:100000632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.189.77",nocase; classtype:trojan-activity; sid:100000633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.21.130",nocase; classtype:trojan-activity; sid:100000634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.37.6",nocase; classtype:trojan-activity; sid:100000635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.53.188",nocase; classtype:trojan-activity; sid:100000636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.73.3.11",nocase; classtype:trojan-activity; sid:100000637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.75.217.79",nocase; classtype:trojan-activity; sid:100000638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.78.133.146",nocase; classtype:trojan-activity; sid:100000639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.92.174.231",nocase; classtype:trojan-activity; sid:100000640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.96.61.246",nocase; classtype:trojan-activity; sid:100000641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.97.136.10",nocase; classtype:trojan-activity; sid:100000642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.124.219.2",nocase; classtype:trojan-activity; sid:100000643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.149.243.14",nocase; classtype:trojan-activity; sid:100000644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.2.100.221",nocase; classtype:trojan-activity; sid:100000645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.206.164.46",nocase; classtype:trojan-activity; sid:100000646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.207.71.237",nocase; classtype:trojan-activity; sid:100000647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.211.100.26",nocase; classtype:trojan-activity; sid:100000648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.212.132.119",nocase; classtype:trojan-activity; sid:100000649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.212.142.215",nocase; classtype:trojan-activity; sid:100000650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.30.4.2",nocase; classtype:trojan-activity; sid:100000651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.30.95.156",nocase; classtype:trojan-activity; sid:100000652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.72.51.230",nocase; classtype:trojan-activity; sid:100000653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.73.222.118",nocase; classtype:trojan-activity; sid:100000654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.75.199.105",nocase; classtype:trojan-activity; sid:100000655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.75.212.119",nocase; classtype:trojan-activity; sid:100000656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.76.114.71",nocase; classtype:trojan-activity; sid:100000657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.11.234.35",nocase; classtype:trojan-activity; sid:100000658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.12.48.157",nocase; classtype:trojan-activity; sid:100000659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.156.69.22",nocase; classtype:trojan-activity; sid:100000660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.192.224.103",nocase; classtype:trojan-activity; sid:100000661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.192.225.161",nocase; classtype:trojan-activity; sid:100000662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.192.225.195",nocase; classtype:trojan-activity; sid:100000663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.192.227.137",nocase; classtype:trojan-activity; sid:100000664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.160.78",nocase; classtype:trojan-activity; sid:100000665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.163.210",nocase; classtype:trojan-activity; sid:100000666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.166.103",nocase; classtype:trojan-activity; sid:100000667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.166.20",nocase; classtype:trojan-activity; sid:100000668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.138",nocase; classtype:trojan-activity; sid:100000669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.5",nocase; classtype:trojan-activity; sid:100000670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.210.52",nocase; classtype:trojan-activity; sid:100000671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.236.14",nocase; classtype:trojan-activity; sid:100000672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.243.40",nocase; classtype:trojan-activity; sid:100000673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.200.76.54",nocase; classtype:trojan-activity; sid:100000674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.200.76.60",nocase; classtype:trojan-activity; sid:100000675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.67.238",nocase; classtype:trojan-activity; sid:100000676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.67.246",nocase; classtype:trojan-activity; sid:100000677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.67.4",nocase; classtype:trojan-activity; sid:100000678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.70.96",nocase; classtype:trojan-activity; sid:100000679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.71.179",nocase; classtype:trojan-activity; sid:100000680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.207.5.156",nocase; classtype:trojan-activity; sid:100000681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.208.134.226",nocase; classtype:trojan-activity; sid:100000682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.208.134.64",nocase; classtype:trojan-activity; sid:100000683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.11.104",nocase; classtype:trojan-activity; sid:100000684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.14.17",nocase; classtype:trojan-activity; sid:100000685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.14.30",nocase; classtype:trojan-activity; sid:100000686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.14.62",nocase; classtype:trojan-activity; sid:100000687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.15.179",nocase; classtype:trojan-activity; sid:100000688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.43.219",nocase; classtype:trojan-activity; sid:100000689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.44.116",nocase; classtype:trojan-activity; sid:100000690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.46.160",nocase; classtype:trojan-activity; sid:100000691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.47.183",nocase; classtype:trojan-activity; sid:100000692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.8.163",nocase; classtype:trojan-activity; sid:100000693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.215.248.14",nocase; classtype:trojan-activity; sid:100000694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.215.251.253",nocase; classtype:trojan-activity; sid:100000695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.160.108",nocase; classtype:trojan-activity; sid:100000696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.162.50",nocase; classtype:trojan-activity; sid:100000697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.164.19",nocase; classtype:trojan-activity; sid:100000698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.164.21",nocase; classtype:trojan-activity; sid:100000699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.169.141",nocase; classtype:trojan-activity; sid:100000700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.172.16",nocase; classtype:trojan-activity; sid:100000701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.174.16",nocase; classtype:trojan-activity; sid:100000702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.241.64.105",nocase; classtype:trojan-activity; sid:100000703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.241.67.141",nocase; classtype:trojan-activity; sid:100000704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.242.208.153",nocase; classtype:trojan-activity; sid:100000705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.242.208.95",nocase; classtype:trojan-activity; sid:100000706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.247.200.129",nocase; classtype:trojan-activity; sid:100000707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.247.202.150",nocase; classtype:trojan-activity; sid:100000708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.247.203.156",nocase; classtype:trojan-activity; sid:100000709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.247.204.118",nocase; classtype:trojan-activity; sid:100000710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.247.204.66",nocase; classtype:trojan-activity; sid:100000711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.60.194",nocase; classtype:trojan-activity; sid:100000712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.26.235.164",nocase; classtype:trojan-activity; sid:100000713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.27.10.73",nocase; classtype:trojan-activity; sid:100000714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.60.204.190",nocase; classtype:trojan-activity; sid:100000715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.113.146",nocase; classtype:trojan-activity; sid:100000716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.195.140",nocase; classtype:trojan-activity; sid:100000717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.252.82",nocase; classtype:trojan-activity; sid:100000718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.53.15",nocase; classtype:trojan-activity; sid:100000719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.86.105.110",nocase; classtype:trojan-activity; sid:100000720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.91.240.50",nocase; classtype:trojan-activity; sid:100000721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.93.115.242",nocase; classtype:trojan-activity; sid:100000722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.93.79.40",nocase; classtype:trojan-activity; sid:100000723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.172.80.79",nocase; classtype:trojan-activity; sid:100000724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.104.35",nocase; classtype:trojan-activity; sid:100000725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.157.64",nocase; classtype:trojan-activity; sid:100000726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.7.132",nocase; classtype:trojan-activity; sid:100000727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.211.38.112",nocase; classtype:trojan-activity; sid:100000728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.32.74",nocase; classtype:trojan-activity; sid:100000729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.5.149",nocase; classtype:trojan-activity; sid:100000730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.72.141",nocase; classtype:trojan-activity; sid:100000731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.12.130",nocase; classtype:trojan-activity; sid:100000732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.128.147",nocase; classtype:trojan-activity; sid:100000733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.208.215",nocase; classtype:trojan-activity; sid:100000734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.209.108",nocase; classtype:trojan-activity; sid:100000735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.214.72",nocase; classtype:trojan-activity; sid:100000736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.88.146",nocase; classtype:trojan-activity; sid:100000737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.150",nocase; classtype:trojan-activity; sid:100000738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.6",nocase; classtype:trojan-activity; sid:100000739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.221.162",nocase; classtype:trojan-activity; sid:100000740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.63.194",nocase; classtype:trojan-activity; sid:100000741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.65.93",nocase; classtype:trojan-activity; sid:100000742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.250.51.192",nocase; classtype:trojan-activity; sid:100000743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.42.125.246",nocase; classtype:trojan-activity; sid:100000744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.43.180.33",nocase; classtype:trojan-activity; sid:100000745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.68.245.69",nocase; classtype:trojan-activity; sid:100000746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.70.83.140",nocase; classtype:trojan-activity; sid:100000747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.120.136",nocase; classtype:trojan-activity; sid:100000748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.200.198",nocase; classtype:trojan-activity; sid:100000749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.240.136",nocase; classtype:trojan-activity; sid:100000750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.240.239",nocase; classtype:trojan-activity; sid:100000751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.50.253",nocase; classtype:trojan-activity; sid:100000752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.70.70",nocase; classtype:trojan-activity; sid:100000753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.125.92",nocase; classtype:trojan-activity; sid:100000754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.161.110",nocase; classtype:trojan-activity; sid:100000755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.164.102",nocase; classtype:trojan-activity; sid:100000756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.218.157",nocase; classtype:trojan-activity; sid:100000757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.50.203",nocase; classtype:trojan-activity; sid:100000758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.58.82",nocase; classtype:trojan-activity; sid:100000759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.83.79.43",nocase; classtype:trojan-activity; sid:100000760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.91.24.27",nocase; classtype:trojan-activity; sid:100000761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.179.164",nocase; classtype:trojan-activity; sid:100000762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.183.235",nocase; classtype:trojan-activity; sid:100000763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.239.217",nocase; classtype:trojan-activity; sid:100000764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.100.40.250",nocase; classtype:trojan-activity; sid:100000765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.108.251.176",nocase; classtype:trojan-activity; sid:100000766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.109.34.245",nocase; classtype:trojan-activity; sid:100000767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.112.22.58",nocase; classtype:trojan-activity; sid:100000768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.112.27.20",nocase; classtype:trojan-activity; sid:100000769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.115.247.23",nocase; classtype:trojan-activity; sid:100000770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.119.52.202",nocase; classtype:trojan-activity; sid:100000771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.123.125.139",nocase; classtype:trojan-activity; sid:100000772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.123.216.42",nocase; classtype:trojan-activity; sid:100000773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.123.218.76",nocase; classtype:trojan-activity; sid:100000774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.123.221.158",nocase; classtype:trojan-activity; sid:100000775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.123.237.218",nocase; classtype:trojan-activity; sid:100000776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.14.143.145",nocase; classtype:trojan-activity; sid:100000777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.147.213.57",nocase; classtype:trojan-activity; sid:100000778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.162.109.111",nocase; classtype:trojan-activity; sid:100000779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.144.208",nocase; classtype:trojan-activity; sid:100000780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.207.197",nocase; classtype:trojan-activity; sid:100000781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.93.191",nocase; classtype:trojan-activity; sid:100000782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.18.235",nocase; classtype:trojan-activity; sid:100000783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.31.76",nocase; classtype:trojan-activity; sid:100000784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.107.93",nocase; classtype:trojan-activity; sid:100000785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.163.220",nocase; classtype:trojan-activity; sid:100000786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.174.63",nocase; classtype:trojan-activity; sid:100000787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.241.222",nocase; classtype:trojan-activity; sid:100000788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.27.77",nocase; classtype:trojan-activity; sid:100000789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.68.145",nocase; classtype:trojan-activity; sid:100000790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.170.241",nocase; classtype:trojan-activity; sid:100000791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.19.254",nocase; classtype:trojan-activity; sid:100000792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.97.6",nocase; classtype:trojan-activity; sid:100000793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.1.13",nocase; classtype:trojan-activity; sid:100000794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.2.214",nocase; classtype:trojan-activity; sid:100000795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.26.33",nocase; classtype:trojan-activity; sid:100000796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.63.195",nocase; classtype:trojan-activity; sid:100000797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.201.188",nocase; classtype:trojan-activity; sid:100000798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.248.123",nocase; classtype:trojan-activity; sid:100000799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.249.140",nocase; classtype:trojan-activity; sid:100000800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.120.180",nocase; classtype:trojan-activity; sid:100000801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.157.219",nocase; classtype:trojan-activity; sid:100000802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.16.149",nocase; classtype:trojan-activity; sid:100000803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.170.212",nocase; classtype:trojan-activity; sid:100000804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.190.180",nocase; classtype:trojan-activity; sid:100000805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.43.1",nocase; classtype:trojan-activity; sid:100000806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.75.8",nocase; classtype:trojan-activity; sid:100000807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.18.38.144",nocase; classtype:trojan-activity; sid:100000808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.101.151",nocase; classtype:trojan-activity; sid:100000809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.106.217",nocase; classtype:trojan-activity; sid:100000810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.227",nocase; classtype:trojan-activity; sid:100000811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.79",nocase; classtype:trojan-activity; sid:100000812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.11.29",nocase; classtype:trojan-activity; sid:100000813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.231.79",nocase; classtype:trojan-activity; sid:100000814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.33.161",nocase; classtype:trojan-activity; sid:100000815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.9.35",nocase; classtype:trojan-activity; sid:100000816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.94.80",nocase; classtype:trojan-activity; sid:100000817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.119.21",nocase; classtype:trojan-activity; sid:100000818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.124.203",nocase; classtype:trojan-activity; sid:100000819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.115.103",nocase; classtype:trojan-activity; sid:100000820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.9.82",nocase; classtype:trojan-activity; sid:100000821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.14.112",nocase; classtype:trojan-activity; sid:100000822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.172.199",nocase; classtype:trojan-activity; sid:100000823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.237.89",nocase; classtype:trojan-activity; sid:100000824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.43.193",nocase; classtype:trojan-activity; sid:100000825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.186.140.160",nocase; classtype:trojan-activity; sid:100000826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.186.22.245",nocase; classtype:trojan-activity; sid:100000827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.195.161",nocase; classtype:trojan-activity; sid:100000828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.220.115",nocase; classtype:trojan-activity; sid:100000829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.137.195",nocase; classtype:trojan-activity; sid:100000830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.227.244",nocase; classtype:trojan-activity; sid:100000831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.190.211.99",nocase; classtype:trojan-activity; sid:100000832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.190.234.181",nocase; classtype:trojan-activity; sid:100000833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.190.240.238",nocase; classtype:trojan-activity; sid:100000834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.150.85",nocase; classtype:trojan-activity; sid:100000835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.187.206",nocase; classtype:trojan-activity; sid:100000836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.215.221",nocase; classtype:trojan-activity; sid:100000837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.240.20",nocase; classtype:trojan-activity; sid:100000838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.253.206",nocase; classtype:trojan-activity; sid:100000839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.204.30.144",nocase; classtype:trojan-activity; sid:100000840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.250.129.231",nocase; classtype:trojan-activity; sid:100000841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.105.221",nocase; classtype:trojan-activity; sid:100000842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.12.85",nocase; classtype:trojan-activity; sid:100000843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.14.251",nocase; classtype:trojan-activity; sid:100000844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.131.155",nocase; classtype:trojan-activity; sid:100000845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.46",nocase; classtype:trojan-activity; sid:100000846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.71",nocase; classtype:trojan-activity; sid:100000847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.144.75",nocase; classtype:trojan-activity; sid:100000848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.148.115",nocase; classtype:trojan-activity; sid:100000849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.155.57",nocase; classtype:trojan-activity; sid:100000850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.172.28",nocase; classtype:trojan-activity; sid:100000851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.195.90",nocase; classtype:trojan-activity; sid:100000852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.96.37.55",nocase; classtype:trojan-activity; sid:100000853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.96.70.116",nocase; classtype:trojan-activity; sid:100000854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.188.187",nocase; classtype:trojan-activity; sid:100000855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.190.152",nocase; classtype:trojan-activity; sid:100000856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.232.62",nocase; classtype:trojan-activity; sid:100000857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.132.113.2",nocase; classtype:trojan-activity; sid:100000858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.15.69.83",nocase; classtype:trojan-activity; sid:100000859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.6",nocase; classtype:trojan-activity; sid:100000860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.7",nocase; classtype:trojan-activity; sid:100000861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.8",nocase; classtype:trojan-activity; sid:100000862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.9",nocase; classtype:trojan-activity; sid:100000863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.207.39.227",nocase; classtype:trojan-activity; sid:100000864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.153.54",nocase; classtype:trojan-activity; sid:100000865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.212.5",nocase; classtype:trojan-activity; sid:100000866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.142.222.22",nocase; classtype:trojan-activity; sid:100000867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.150.213.110",nocase; classtype:trojan-activity; sid:100000868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.151.248.134",nocase; classtype:trojan-activity; sid:100000869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.177",nocase; classtype:trojan-activity; sid:100000870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.178",nocase; classtype:trojan-activity; sid:100000871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.180",nocase; classtype:trojan-activity; sid:100000872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.181",nocase; classtype:trojan-activity; sid:100000873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.183",nocase; classtype:trojan-activity; sid:100000874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.184",nocase; classtype:trojan-activity; sid:100000875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.185",nocase; classtype:trojan-activity; sid:100000876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.186",nocase; classtype:trojan-activity; sid:100000877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.188",nocase; classtype:trojan-activity; sid:100000878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.191",nocase; classtype:trojan-activity; sid:100000879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.193",nocase; classtype:trojan-activity; sid:100000880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.196",nocase; classtype:trojan-activity; sid:100000881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.197",nocase; classtype:trojan-activity; sid:100000882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.198",nocase; classtype:trojan-activity; sid:100000883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.199",nocase; classtype:trojan-activity; sid:100000884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.200",nocase; classtype:trojan-activity; sid:100000885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.201",nocase; classtype:trojan-activity; sid:100000886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.202",nocase; classtype:trojan-activity; sid:100000887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.204",nocase; classtype:trojan-activity; sid:100000888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.207",nocase; classtype:trojan-activity; sid:100000889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.208",nocase; classtype:trojan-activity; sid:100000890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.212",nocase; classtype:trojan-activity; sid:100000891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.213",nocase; classtype:trojan-activity; sid:100000892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.215",nocase; classtype:trojan-activity; sid:100000893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.233",nocase; classtype:trojan-activity; sid:100000894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.93.227",nocase; classtype:trojan-activity; sid:100000895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.121.243",nocase; classtype:trojan-activity; sid:100000896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.206",nocase; classtype:trojan-activity; sid:100000897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.225",nocase; classtype:trojan-activity; sid:100000898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.235",nocase; classtype:trojan-activity; sid:100000899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.240",nocase; classtype:trojan-activity; sid:100000900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.243",nocase; classtype:trojan-activity; sid:100000901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.60",nocase; classtype:trojan-activity; sid:100000902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.127.187",nocase; classtype:trojan-activity; sid:100000903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.99.127",nocase; classtype:trojan-activity; sid:100000904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.210.89.79",nocase; classtype:trojan-activity; sid:100000905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.43.34.242",nocase; classtype:trojan-activity; sid:100000906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.5.15.95",nocase; classtype:trojan-activity; sid:100000907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.66.60",nocase; classtype:trojan-activity; sid:100000908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.93.115",nocase; classtype:trojan-activity; sid:100000909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.57.98.208",nocase; classtype:trojan-activity; sid:100000910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.141.142",nocase; classtype:trojan-activity; sid:100000911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.8.11",nocase; classtype:trojan-activity; sid:100000912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.69.131.51",nocase; classtype:trojan-activity; sid:100000913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.7.75.99",nocase; classtype:trojan-activity; sid:100000914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.7.90.104",nocase; classtype:trojan-activity; sid:100000915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.83.189.232",nocase; classtype:trojan-activity; sid:100000916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.165.112",nocase; classtype:trojan-activity; sid:100000917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.169.113",nocase; classtype:trojan-activity; sid:100000918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.170.109",nocase; classtype:trojan-activity; sid:100000919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.173.234",nocase; classtype:trojan-activity; sid:100000920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.185.141",nocase; classtype:trojan-activity; sid:100000921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.236.95",nocase; classtype:trojan-activity; sid:100000922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.238.10",nocase; classtype:trojan-activity; sid:100000923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.238.244",nocase; classtype:trojan-activity; sid:100000924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.9.32.51",nocase; classtype:trojan-activity; sid:100000925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.114.164",nocase; classtype:trojan-activity; sid:100000926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.96.8",nocase; classtype:trojan-activity; sid:100000927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.121.44.222",nocase; classtype:trojan-activity; sid:100000928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.123.53.25",nocase; classtype:trojan-activity; sid:100000929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.127.155.220",nocase; classtype:trojan-activity; sid:100000930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.136.249.5",nocase; classtype:trojan-activity; sid:100000931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.141.11.56",nocase; classtype:trojan-activity; sid:100000932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.15.142.137",nocase; classtype:trojan-activity; sid:100000933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.151.78.190",nocase; classtype:trojan-activity; sid:100000934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.159.22.144",nocase; classtype:trojan-activity; sid:100000935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.17.103.176",nocase; classtype:trojan-activity; sid:100000936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.170.234.142",nocase; classtype:trojan-activity; sid:100000937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.185.31.2",nocase; classtype:trojan-activity; sid:100000938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.190.36.8",nocase; classtype:trojan-activity; sid:100000939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.225.11.163",nocase; classtype:trojan-activity; sid:100000940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.226.82.202",nocase; classtype:trojan-activity; sid:100000941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.23.57.130",nocase; classtype:trojan-activity; sid:100000942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.230.171.198",nocase; classtype:trojan-activity; sid:100000943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.231.103.95",nocase; classtype:trojan-activity; sid:100000944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.233.18.172",nocase; classtype:trojan-activity; sid:100000945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.238.175.87",nocase; classtype:trojan-activity; sid:100000946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.239.15.74",nocase; classtype:trojan-activity; sid:100000947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.24.116.173",nocase; classtype:trojan-activity; sid:100000948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.25.101.86",nocase; classtype:trojan-activity; sid:100000949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.254.43.215",nocase; classtype:trojan-activity; sid:100000950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.254.76.17",nocase; classtype:trojan-activity; sid:100000951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.101.93",nocase; classtype:trojan-activity; sid:100000952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.102.1",nocase; classtype:trojan-activity; sid:100000953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.107.189",nocase; classtype:trojan-activity; sid:100000954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.97.195",nocase; classtype:trojan-activity; sid:100000955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.98.151",nocase; classtype:trojan-activity; sid:100000956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.88.99.236",nocase; classtype:trojan-activity; sid:100000957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.100.150.204",nocase; classtype:trojan-activity; sid:100000958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.137.52.122",nocase; classtype:trojan-activity; sid:100000959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.160.147.53",nocase; classtype:trojan-activity; sid:100000960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.176.44.34",nocase; classtype:trojan-activity; sid:100000961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.188.86.225",nocase; classtype:trojan-activity; sid:100000962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.190.19.204",nocase; classtype:trojan-activity; sid:100000963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.192.190.203",nocase; classtype:trojan-activity; sid:100000964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.66.28",nocase; classtype:trojan-activity; sid:100000965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.72.23",nocase; classtype:trojan-activity; sid:100000966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.79.27",nocase; classtype:trojan-activity; sid:100000967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.37.85",nocase; classtype:trojan-activity; sid:100000968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.41.23",nocase; classtype:trojan-activity; sid:100000969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.252.199.3",nocase; classtype:trojan-activity; sid:100000970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.252.250.22",nocase; classtype:trojan-activity; sid:100000971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.183.207",nocase; classtype:trojan-activity; sid:100000972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.29.37",nocase; classtype:trojan-activity; sid:100000973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.33.214",nocase; classtype:trojan-activity; sid:100000974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.0.240.58",nocase; classtype:trojan-activity; sid:100000975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.131.225",nocase; classtype:trojan-activity; sid:100000976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.41.32",nocase; classtype:trojan-activity; sid:100000977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.83.136",nocase; classtype:trojan-activity; sid:100000978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.11.207",nocase; classtype:trojan-activity; sid:100000979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.4.168",nocase; classtype:trojan-activity; sid:100000980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.7.1",nocase; classtype:trojan-activity; sid:100000981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.71.166",nocase; classtype:trojan-activity; sid:100000982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.238",nocase; classtype:trojan-activity; sid:100000983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.244",nocase; classtype:trojan-activity; sid:100000984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.170.237",nocase; classtype:trojan-activity; sid:100000985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.182.187",nocase; classtype:trojan-activity; sid:100000986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.19.248",nocase; classtype:trojan-activity; sid:100000987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.200.98",nocase; classtype:trojan-activity; sid:100000988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.238.188",nocase; classtype:trojan-activity; sid:100000989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.12.7.82",nocase; classtype:trojan-activity; sid:100000990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.128.205",nocase; classtype:trojan-activity; sid:100000991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.133.91",nocase; classtype:trojan-activity; sid:100000992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.177.161",nocase; classtype:trojan-activity; sid:100000993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.84.36",nocase; classtype:trojan-activity; sid:100000994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.88.123",nocase; classtype:trojan-activity; sid:100000995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.13.44.60",nocase; classtype:trojan-activity; sid:100000996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.202.8",nocase; classtype:trojan-activity; sid:100000997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.208.52",nocase; classtype:trojan-activity; sid:100000998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.23.110",nocase; classtype:trojan-activity; sid:100000999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.37.182",nocase; classtype:trojan-activity; sid:100001000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.61.210",nocase; classtype:trojan-activity; sid:100001001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.77.225",nocase; classtype:trojan-activity; sid:100001002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.131.186.250",nocase; classtype:trojan-activity; sid:100001003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.132.219.147",nocase; classtype:trojan-activity; sid:100001004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.125.77",nocase; classtype:trojan-activity; sid:100001005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.144.138",nocase; classtype:trojan-activity; sid:100001006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.184.77",nocase; classtype:trojan-activity; sid:100001007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.98.135",nocase; classtype:trojan-activity; sid:100001008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.14.130",nocase; classtype:trojan-activity; sid:100001009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.50.186",nocase; classtype:trojan-activity; sid:100001010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.157.193",nocase; classtype:trojan-activity; sid:100001011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.39.36",nocase; classtype:trojan-activity; sid:100001012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.71.150",nocase; classtype:trojan-activity; sid:100001013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.172.149",nocase; classtype:trojan-activity; sid:100001014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.86.82",nocase; classtype:trojan-activity; sid:100001015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.93.154",nocase; classtype:trojan-activity; sid:100001016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.144.211.86",nocase; classtype:trojan-activity; sid:100001017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.152.42.4",nocase; classtype:trojan-activity; sid:100001018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.152.43.21",nocase; classtype:trojan-activity; sid:100001019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.153.80.178",nocase; classtype:trojan-activity; sid:100001020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.236.114",nocase; classtype:trojan-activity; sid:100001021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.94.1",nocase; classtype:trojan-activity; sid:100001022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.155.118.36",nocase; classtype:trojan-activity; sid:100001023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.156.136.21",nocase; classtype:trojan-activity; sid:100001024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.137.101",nocase; classtype:trojan-activity; sid:100001025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.31.110",nocase; classtype:trojan-activity; sid:100001026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.8.100",nocase; classtype:trojan-activity; sid:100001027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.101.163",nocase; classtype:trojan-activity; sid:100001028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.194.233",nocase; classtype:trojan-activity; sid:100001029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.149.235",nocase; classtype:trojan-activity; sid:100001030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.53.237",nocase; classtype:trojan-activity; sid:100001031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.235.37",nocase; classtype:trojan-activity; sid:100001032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.35.146",nocase; classtype:trojan-activity; sid:100001033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.52.79",nocase; classtype:trojan-activity; sid:100001034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.60.238",nocase; classtype:trojan-activity; sid:100001035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.112.240",nocase; classtype:trojan-activity; sid:100001036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.184.191",nocase; classtype:trojan-activity; sid:100001037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.98.141",nocase; classtype:trojan-activity; sid:100001038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.212.29.154",nocase; classtype:trojan-activity; sid:100001039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.213.225.130",nocase; classtype:trojan-activity; sid:100001040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.130.162",nocase; classtype:trojan-activity; sid:100001041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.152.249",nocase; classtype:trojan-activity; sid:100001042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.100.219",nocase; classtype:trojan-activity; sid:100001043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.116.110",nocase; classtype:trojan-activity; sid:100001044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.184.57",nocase; classtype:trojan-activity; sid:100001045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.246.103",nocase; classtype:trojan-activity; sid:100001046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.235.226.3",nocase; classtype:trojan-activity; sid:100001047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.103.89",nocase; classtype:trojan-activity; sid:100001048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.181.57",nocase; classtype:trojan-activity; sid:100001049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.79.61",nocase; classtype:trojan-activity; sid:100001050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.148.58",nocase; classtype:trojan-activity; sid:100001051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.184.124",nocase; classtype:trojan-activity; sid:100001052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.27.44.219",nocase; classtype:trojan-activity; sid:100001053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.28.217.23",nocase; classtype:trojan-activity; sid:100001054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.11.40",nocase; classtype:trojan-activity; sid:100001055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.166.2",nocase; classtype:trojan-activity; sid:100001056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.176.22",nocase; classtype:trojan-activity; sid:100001057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.177.93",nocase; classtype:trojan-activity; sid:100001058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.193.171",nocase; classtype:trojan-activity; sid:100001059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.209.154",nocase; classtype:trojan-activity; sid:100001060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.241.118",nocase; classtype:trojan-activity; sid:100001061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.76.117",nocase; classtype:trojan-activity; sid:100001062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.83.66",nocase; classtype:trojan-activity; sid:100001063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.85.149",nocase; classtype:trojan-activity; sid:100001064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.123.60",nocase; classtype:trojan-activity; sid:100001065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.143.203",nocase; classtype:trojan-activity; sid:100001066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.146.238",nocase; classtype:trojan-activity; sid:100001067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.190.167",nocase; classtype:trojan-activity; sid:100001068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.5.242",nocase; classtype:trojan-activity; sid:100001069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.8.211",nocase; classtype:trojan-activity; sid:100001070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.56.94",nocase; classtype:trojan-activity; sid:100001071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.194.169",nocase; classtype:trojan-activity; sid:100001072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.245.207",nocase; classtype:trojan-activity; sid:100001073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.105.105.222",nocase; classtype:trojan-activity; sid:100001074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.162.169",nocase; classtype:trojan-activity; sid:100001075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.221.150",nocase; classtype:trojan-activity; sid:100001076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.76.230",nocase; classtype:trojan-activity; sid:100001077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.167.20",nocase; classtype:trojan-activity; sid:100001078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.40.31",nocase; classtype:trojan-activity; sid:100001079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.104.82",nocase; classtype:trojan-activity; sid:100001080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.130.95",nocase; classtype:trojan-activity; sid:100001081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.131.71",nocase; classtype:trojan-activity; sid:100001082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.136.75",nocase; classtype:trojan-activity; sid:100001083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.151.135",nocase; classtype:trojan-activity; sid:100001084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.26.243",nocase; classtype:trojan-activity; sid:100001085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.26.78",nocase; classtype:trojan-activity; sid:100001086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.41.48",nocase; classtype:trojan-activity; sid:100001087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.54.33",nocase; classtype:trojan-activity; sid:100001088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.72.208",nocase; classtype:trojan-activity; sid:100001089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.132.110.150",nocase; classtype:trojan-activity; sid:100001090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.135.34.157",nocase; classtype:trojan-activity; sid:100001091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.135.34.49",nocase; classtype:trojan-activity; sid:100001092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.136.175",nocase; classtype:trojan-activity; sid:100001093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.236.6",nocase; classtype:trojan-activity; sid:100001094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.160.126.238",nocase; classtype:trojan-activity; sid:100001095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.154.237",nocase; classtype:trojan-activity; sid:100001096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.65.64",nocase; classtype:trojan-activity; sid:100001097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.65.98",nocase; classtype:trojan-activity; sid:100001098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.72.102",nocase; classtype:trojan-activity; sid:100001099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.77.191",nocase; classtype:trojan-activity; sid:100001100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.89.212",nocase; classtype:trojan-activity; sid:100001101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.90.243",nocase; classtype:trojan-activity; sid:100001102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.165.123.7",nocase; classtype:trojan-activity; sid:100001103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.187.111.160",nocase; classtype:trojan-activity; sid:100001104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.199.56.198",nocase; classtype:trojan-activity; sid:100001105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.226.24.117",nocase; classtype:trojan-activity; sid:100001106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.230.174.233",nocase; classtype:trojan-activity; sid:100001107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.234.6.130",nocase; classtype:trojan-activity; sid:100001108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.254.254.61",nocase; classtype:trojan-activity; sid:100001109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.5.92.20",nocase; classtype:trojan-activity; sid:100001110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.6.0.4",nocase; classtype:trojan-activity; sid:100001111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.67.89.28",nocase; classtype:trojan-activity; sid:100001112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.7.254.85",nocase; classtype:trojan-activity; sid:100001113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.80.46.73",nocase; classtype:trojan-activity; sid:100001114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.91.237.147",nocase; classtype:trojan-activity; sid:100001115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.93.94.207",nocase; classtype:trojan-activity; sid:100001116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.95.17.41",nocase; classtype:trojan-activity; sid:100001117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.105.219.169",nocase; classtype:trojan-activity; sid:100001118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.126.69.95",nocase; classtype:trojan-activity; sid:100001119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.128.28.161",nocase; classtype:trojan-activity; sid:100001120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.142.93.34",nocase; classtype:trojan-activity; sid:100001121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.168.10.234",nocase; classtype:trojan-activity; sid:100001122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.191.113.212",nocase; classtype:trojan-activity; sid:100001123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.209.71.6",nocase; classtype:trojan-activity; sid:100001124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.36.148.42",nocase; classtype:trojan-activity; sid:100001125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.1.127",nocase; classtype:trojan-activity; sid:100001126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.113.66",nocase; classtype:trojan-activity; sid:100001127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.160.116",nocase; classtype:trojan-activity; sid:100001128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.17.14",nocase; classtype:trojan-activity; sid:100001129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.237.130",nocase; classtype:trojan-activity; sid:100001130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.25.140",nocase; classtype:trojan-activity; sid:100001131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.65.120",nocase; classtype:trojan-activity; sid:100001132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.73.6",nocase; classtype:trojan-activity; sid:100001133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.74.153",nocase; classtype:trojan-activity; sid:100001134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.75.22",nocase; classtype:trojan-activity; sid:100001135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.208.139",nocase; classtype:trojan-activity; sid:100001136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.244.43",nocase; classtype:trojan-activity; sid:100001137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.6.192",nocase; classtype:trojan-activity; sid:100001138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.7.204",nocase; classtype:trojan-activity; sid:100001139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.74.22",nocase; classtype:trojan-activity; sid:100001140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.96.238",nocase; classtype:trojan-activity; sid:100001141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.96.33",nocase; classtype:trojan-activity; sid:100001142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.97.81",nocase; classtype:trojan-activity; sid:100001143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.107.136",nocase; classtype:trojan-activity; sid:100001144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.124.114",nocase; classtype:trojan-activity; sid:100001145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.98.24",nocase; classtype:trojan-activity; sid:100001146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.98.35",nocase; classtype:trojan-activity; sid:100001147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.112.123",nocase; classtype:trojan-activity; sid:100001148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.112.182",nocase; classtype:trojan-activity; sid:100001149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.133.130",nocase; classtype:trojan-activity; sid:100001150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.167.192",nocase; classtype:trojan-activity; sid:100001151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.2.169",nocase; classtype:trojan-activity; sid:100001152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.21.157",nocase; classtype:trojan-activity; sid:100001153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.215.244",nocase; classtype:trojan-activity; sid:100001154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.26.36",nocase; classtype:trojan-activity; sid:100001155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.33.20",nocase; classtype:trojan-activity; sid:100001156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.37.138",nocase; classtype:trojan-activity; sid:100001157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.53.50",nocase; classtype:trojan-activity; sid:100001158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.53.9",nocase; classtype:trojan-activity; sid:100001159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.60.218",nocase; classtype:trojan-activity; sid:100001160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.73.19",nocase; classtype:trojan-activity; sid:100001161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.92.62",nocase; classtype:trojan-activity; sid:100001162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.10.125",nocase; classtype:trojan-activity; sid:100001163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.107.182",nocase; classtype:trojan-activity; sid:100001164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.175.118",nocase; classtype:trojan-activity; sid:100001165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.198.62",nocase; classtype:trojan-activity; sid:100001166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.212.131",nocase; classtype:trojan-activity; sid:100001167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.243.220",nocase; classtype:trojan-activity; sid:100001168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.31.79",nocase; classtype:trojan-activity; sid:100001169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.8.227",nocase; classtype:trojan-activity; sid:100001170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.153.91",nocase; classtype:trojan-activity; sid:100001171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.55.146",nocase; classtype:trojan-activity; sid:100001172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.138.117",nocase; classtype:trojan-activity; sid:100001173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.166.125",nocase; classtype:trojan-activity; sid:100001174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.205.88",nocase; classtype:trojan-activity; sid:100001175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.206.160",nocase; classtype:trojan-activity; sid:100001176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.217.52",nocase; classtype:trojan-activity; sid:100001177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.241.237",nocase; classtype:trojan-activity; sid:100001178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.241.188",nocase; classtype:trojan-activity; sid:100001179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.245.200",nocase; classtype:trojan-activity; sid:100001180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.250.98",nocase; classtype:trojan-activity; sid:100001181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.252.106",nocase; classtype:trojan-activity; sid:100001182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.254.154",nocase; classtype:trojan-activity; sid:100001183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.254.44",nocase; classtype:trojan-activity; sid:100001184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.28.18",nocase; classtype:trojan-activity; sid:100001185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.45.218",nocase; classtype:trojan-activity; sid:100001186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.57.80",nocase; classtype:trojan-activity; sid:100001187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.91.51",nocase; classtype:trojan-activity; sid:100001188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.79.192.197",nocase; classtype:trojan-activity; sid:100001189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"128.116.133.92",nocase; classtype:trojan-activity; sid:100001190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"130.255.159.133",nocase; classtype:trojan-activity; sid:100001191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"134.195.139.4",nocase; classtype:trojan-activity; sid:100001192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"134.255.93.203",nocase; classtype:trojan-activity; sid:100001193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"135.181.192.170",nocase; classtype:trojan-activity; sid:100001194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"138.99.204.224",nocase; classtype:trojan-activity; sid:100001195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.159.226.180",nocase; classtype:trojan-activity; sid:100001196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.173.198",nocase; classtype:trojan-activity; sid:100001197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.174.162",nocase; classtype:trojan-activity; sid:100001198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.216.102.151",nocase; classtype:trojan-activity; sid:100001199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.227.46.137",nocase; classtype:trojan-activity; sid:100001200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.102.17.222",nocase; classtype:trojan-activity; sid:100001201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.102.97.204",nocase; classtype:trojan-activity; sid:100001202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.136.80.242",nocase; classtype:trojan-activity; sid:100001203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.109.129",nocase; classtype:trojan-activity; sid:100001204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.109.26",nocase; classtype:trojan-activity; sid:100001205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.215",nocase; classtype:trojan-activity; sid:100001206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.51",nocase; classtype:trojan-activity; sid:100001207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.155.220.240",nocase; classtype:trojan-activity; sid:100001208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.160.24.71",nocase; classtype:trojan-activity; sid:100001209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.169.164.77",nocase; classtype:trojan-activity; sid:100001210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.181.64.108",nocase; classtype:trojan-activity; sid:100001211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.189.247.118",nocase; classtype:trojan-activity; sid:100001212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.205.201.192",nocase; classtype:trojan-activity; sid:100001213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.248.187.0",nocase; classtype:trojan-activity; sid:100001214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.37.222.190",nocase; classtype:trojan-activity; sid:100001215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.45.127.110",nocase; classtype:trojan-activity; sid:100001216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.25.17",nocase; classtype:trojan-activity; sid:100001217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.98.241",nocase; classtype:trojan-activity; sid:100001218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.55.29.2",nocase; classtype:trojan-activity; sid:100001219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.98.184.178",nocase; classtype:trojan-activity; sid:100001220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"140.237.30.113",nocase; classtype:trojan-activity; sid:100001221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"140.237.5.43",nocase; classtype:trojan-activity; sid:100001222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.11.216.5",nocase; classtype:trojan-activity; sid:100001223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.177.56.127",nocase; classtype:trojan-activity; sid:100001224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"146.71.79.230",nocase; classtype:trojan-activity; sid:100001225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"148.69.108.177",nocase; classtype:trojan-activity; sid:100001226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.20.176.179",nocase; classtype:trojan-activity; sid:100001227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.112",nocase; classtype:trojan-activity; sid:100001228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.134",nocase; classtype:trojan-activity; sid:100001229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.180",nocase; classtype:trojan-activity; sid:100001230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.182",nocase; classtype:trojan-activity; sid:100001231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.184",nocase; classtype:trojan-activity; sid:100001232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.191",nocase; classtype:trojan-activity; sid:100001233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.213",nocase; classtype:trojan-activity; sid:100001234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.235",nocase; classtype:trojan-activity; sid:100001235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.27",nocase; classtype:trojan-activity; sid:100001236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.43",nocase; classtype:trojan-activity; sid:100001237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.87",nocase; classtype:trojan-activity; sid:100001238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.99",nocase; classtype:trojan-activity; sid:100001239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.124.194",nocase; classtype:trojan-activity; sid:100001240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.36.210",nocase; classtype:trojan-activity; sid:100001241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.85.55",nocase; classtype:trojan-activity; sid:100001242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"150.116.207.99",nocase; classtype:trojan-activity; sid:100001243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.177.163.87",nocase; classtype:trojan-activity; sid:100001244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.33.230.191",nocase; classtype:trojan-activity; sid:100001245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.73.124.231",nocase; classtype:trojan-activity; sid:100001246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.225.96",nocase; classtype:trojan-activity; sid:100001247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.234.167",nocase; classtype:trojan-activity; sid:100001248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.40.207",nocase; classtype:trojan-activity; sid:100001249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.43.136",nocase; classtype:trojan-activity; sid:100001250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.44.44",nocase; classtype:trojan-activity; sid:100001251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.135.92",nocase; classtype:trojan-activity; sid:100001252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.23.76",nocase; classtype:trojan-activity; sid:100001253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.29.28",nocase; classtype:trojan-activity; sid:100001254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.35.111.46",nocase; classtype:trojan-activity; sid:100001255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.35.27.49",nocase; classtype:trojan-activity; sid:100001256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.36.126.35",nocase; classtype:trojan-activity; sid:100001257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.101.165.14",nocase; classtype:trojan-activity; sid:100001258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.174.213.128",nocase; classtype:trojan-activity; sid:100001259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.51.125.115",nocase; classtype:trojan-activity; sid:100001260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"159.224.74.112",nocase; classtype:trojan-activity; sid:100001261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.165.238",nocase; classtype:trojan-activity; sid:100001262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.205.175",nocase; classtype:trojan-activity; sid:100001263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.194.28.60",nocase; classtype:trojan-activity; sid:100001264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.209.98.174",nocase; classtype:trojan-activity; sid:100001265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.125.6",nocase; classtype:trojan-activity; sid:100001266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.157.64",nocase; classtype:trojan-activity; sid:100001267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.18.93",nocase; classtype:trojan-activity; sid:100001268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.193.148",nocase; classtype:trojan-activity; sid:100001269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.195.248",nocase; classtype:trojan-activity; sid:100001270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.200.199",nocase; classtype:trojan-activity; sid:100001271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.202.193",nocase; classtype:trojan-activity; sid:100001272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.202.195",nocase; classtype:trojan-activity; sid:100001273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.202.21",nocase; classtype:trojan-activity; sid:100001274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.203.198",nocase; classtype:trojan-activity; sid:100001275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.204.156",nocase; classtype:trojan-activity; sid:100001276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.204.244",nocase; classtype:trojan-activity; sid:100001277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.204.34",nocase; classtype:trojan-activity; sid:100001278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.207.61",nocase; classtype:trojan-activity; sid:100001279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.243.131",nocase; classtype:trojan-activity; sid:100001280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.255.165",nocase; classtype:trojan-activity; sid:100001281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.204.208.169",nocase; classtype:trojan-activity; sid:100001282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.204.211.228",nocase; classtype:trojan-activity; sid:100001283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.204.211.58",nocase; classtype:trojan-activity; sid:100001284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.53.206.228",nocase; classtype:trojan-activity; sid:100001285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"165.90.16.5",nocase; classtype:trojan-activity; sid:100001286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"168.90.204.207",nocase; classtype:trojan-activity; sid:100001287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"170.81.238.178",nocase; classtype:trojan-activity; sid:100001288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.113.36.216",nocase; classtype:trojan-activity; sid:100001289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.118.18.184",nocase; classtype:trojan-activity; sid:100001290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.118.210.67",nocase; classtype:trojan-activity; sid:100001291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.217.149",nocase; classtype:trojan-activity; sid:100001292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.218.208",nocase; classtype:trojan-activity; sid:100001293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.219.150",nocase; classtype:trojan-activity; sid:100001294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.248.222",nocase; classtype:trojan-activity; sid:100001295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.255.96",nocase; classtype:trojan-activity; sid:100001296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.120.125.147",nocase; classtype:trojan-activity; sid:100001297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.121.6.162",nocase; classtype:trojan-activity; sid:100001298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.123.134.239",nocase; classtype:trojan-activity; sid:100001299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.242.71",nocase; classtype:trojan-activity; sid:100001300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.30.233",nocase; classtype:trojan-activity; sid:100001301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.30.93",nocase; classtype:trojan-activity; sid:100001302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.64.223",nocase; classtype:trojan-activity; sid:100001303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.65.22",nocase; classtype:trojan-activity; sid:100001304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.75.68",nocase; classtype:trojan-activity; sid:100001305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.126.70.133",nocase; classtype:trojan-activity; sid:100001306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.223.72.123",nocase; classtype:trojan-activity; sid:100001307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.112.42",nocase; classtype:trojan-activity; sid:100001308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.114.181",nocase; classtype:trojan-activity; sid:100001309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.179.178",nocase; classtype:trojan-activity; sid:100001310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.160.138",nocase; classtype:trojan-activity; sid:100001311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.161.234",nocase; classtype:trojan-activity; sid:100001312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.162.156",nocase; classtype:trojan-activity; sid:100001313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.174.198",nocase; classtype:trojan-activity; sid:100001314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.36.249.91",nocase; classtype:trojan-activity; sid:100001315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.145.146",nocase; classtype:trojan-activity; sid:100001316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.148.69",nocase; classtype:trojan-activity; sid:100001317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.217.222",nocase; classtype:trojan-activity; sid:100001318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.219.189",nocase; classtype:trojan-activity; sid:100001319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.223.110",nocase; classtype:trojan-activity; sid:100001320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.223.213",nocase; classtype:trojan-activity; sid:100001321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.105.36.168",nocase; classtype:trojan-activity; sid:100001322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.114.244.127",nocase; classtype:trojan-activity; sid:100001323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.185",nocase; classtype:trojan-activity; sid:100001324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.190",nocase; classtype:trojan-activity; sid:100001325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.81.19",nocase; classtype:trojan-activity; sid:100001326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.167.85.89",nocase; classtype:trojan-activity; sid:100001327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.169.46.85",nocase; classtype:trojan-activity; sid:100001328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.19.58.108",nocase; classtype:trojan-activity; sid:100001329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.233.85.171",nocase; classtype:trojan-activity; sid:100001330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.235.209.70",nocase; classtype:trojan-activity; sid:100001331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.25.113.8",nocase; classtype:trojan-activity; sid:100001332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.95.134",nocase; classtype:trojan-activity; sid:100001333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.97.25",nocase; classtype:trojan-activity; sid:100001334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.119.108",nocase; classtype:trojan-activity; sid:100001335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.92.166",nocase; classtype:trojan-activity; sid:100001336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.106.33.85",nocase; classtype:trojan-activity; sid:100001337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.48.181.23",nocase; classtype:trojan-activity; sid:100001338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.61.3.149",nocase; classtype:trojan-activity; sid:100001339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.73.246.193",nocase; classtype:trojan-activity; sid:100001340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.81.78.7",nocase; classtype:trojan-activity; sid:100001341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.83.73.163",nocase; classtype:trojan-activity; sid:100001342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.10.147.167",nocase; classtype:trojan-activity; sid:100001343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.11.193.66",nocase; classtype:trojan-activity; sid:100001344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.115.241.87",nocase; classtype:trojan-activity; sid:100001345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.117.66.74",nocase; classtype:trojan-activity; sid:100001346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.145.200.216",nocase; classtype:trojan-activity; sid:100001347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.146.17.227",nocase; classtype:trojan-activity; sid:100001348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.150.168.92",nocase; classtype:trojan-activity; sid:100001349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.153.144.2",nocase; classtype:trojan-activity; sid:100001350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.162.137.166",nocase; classtype:trojan-activity; sid:100001351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.162.195.27",nocase; classtype:trojan-activity; sid:100001352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.162.69.13",nocase; classtype:trojan-activity; sid:100001353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.165.90.198",nocase; classtype:trojan-activity; sid:100001354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.168.139.182",nocase; classtype:trojan-activity; sid:100001355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.17.90.14",nocase; classtype:trojan-activity; sid:100001356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.174.93.57",nocase; classtype:trojan-activity; sid:100001357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.199.33.139",nocase; classtype:trojan-activity; sid:100001358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.201.104.192",nocase; classtype:trojan-activity; sid:100001359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.208.230.8",nocase; classtype:trojan-activity; sid:100001360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.212.6.169",nocase; classtype:trojan-activity; sid:100001361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.42.46.118",nocase; classtype:trojan-activity; sid:100001362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.8.113.55",nocase; classtype:trojan-activity; sid:100001363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.9.24.110",nocase; classtype:trojan-activity; sid:100001364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.14",nocase; classtype:trojan-activity; sid:100001365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.35",nocase; classtype:trojan-activity; sid:100001366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.63",nocase; classtype:trojan-activity; sid:100001367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.66",nocase; classtype:trojan-activity; sid:100001368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.67",nocase; classtype:trojan-activity; sid:100001369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.104",nocase; classtype:trojan-activity; sid:100001370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.113",nocase; classtype:trojan-activity; sid:100001371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.120",nocase; classtype:trojan-activity; sid:100001372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.128",nocase; classtype:trojan-activity; sid:100001373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.138",nocase; classtype:trojan-activity; sid:100001374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.59",nocase; classtype:trojan-activity; sid:100001375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.65",nocase; classtype:trojan-activity; sid:100001376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.66",nocase; classtype:trojan-activity; sid:100001377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.76",nocase; classtype:trojan-activity; sid:100001378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.84",nocase; classtype:trojan-activity; sid:100001379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.88",nocase; classtype:trojan-activity; sid:100001380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.93",nocase; classtype:trojan-activity; sid:100001381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.174.139",nocase; classtype:trojan-activity; sid:100001382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.12.117.70",nocase; classtype:trojan-activity; sid:100001383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.4.115",nocase; classtype:trojan-activity; sid:100001384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.115",nocase; classtype:trojan-activity; sid:100001385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.127",nocase; classtype:trojan-activity; sid:100001386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.9.243",nocase; classtype:trojan-activity; sid:100001387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.124.7.225",nocase; classtype:trojan-activity; sid:100001388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.40.142",nocase; classtype:trojan-activity; sid:100001389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.84.106",nocase; classtype:trojan-activity; sid:100001390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.11.92.78",nocase; classtype:trojan-activity; sid:100001391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.131.226.235",nocase; classtype:trojan-activity; sid:100001392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.229.64.218",nocase; classtype:trojan-activity; sid:100001393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.44.61.243",nocase; classtype:trojan-activity; sid:100001394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.86.235.143",nocase; classtype:trojan-activity; sid:100001395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.124.182.187",nocase; classtype:trojan-activity; sid:100001396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.125.98",nocase; classtype:trojan-activity; sid:100001397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.25.82",nocase; classtype:trojan-activity; sid:100001398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.45.2",nocase; classtype:trojan-activity; sid:100001399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.57.166",nocase; classtype:trojan-activity; sid:100001400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.150.174.65",nocase; classtype:trojan-activity; sid:100001401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.151.143.2",nocase; classtype:trojan-activity; sid:100001402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.165.122.141",nocase; classtype:trojan-activity; sid:100001403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.0.140",nocase; classtype:trojan-activity; sid:100001404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.0.42",nocase; classtype:trojan-activity; sid:100001405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.0.47",nocase; classtype:trojan-activity; sid:100001406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.139",nocase; classtype:trojan-activity; sid:100001407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.143",nocase; classtype:trojan-activity; sid:100001408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.153",nocase; classtype:trojan-activity; sid:100001409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.182",nocase; classtype:trojan-activity; sid:100001410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.224",nocase; classtype:trojan-activity; sid:100001411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.244",nocase; classtype:trojan-activity; sid:100001412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.247",nocase; classtype:trojan-activity; sid:100001413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.249",nocase; classtype:trojan-activity; sid:100001414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.250",nocase; classtype:trojan-activity; sid:100001415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.252",nocase; classtype:trojan-activity; sid:100001416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.80",nocase; classtype:trojan-activity; sid:100001417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.99",nocase; classtype:trojan-activity; sid:100001418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.102",nocase; classtype:trojan-activity; sid:100001419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.34",nocase; classtype:trojan-activity; sid:100001420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.42",nocase; classtype:trojan-activity; sid:100001421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.71",nocase; classtype:trojan-activity; sid:100001422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.78",nocase; classtype:trojan-activity; sid:100001423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.110",nocase; classtype:trojan-activity; sid:100001424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.129",nocase; classtype:trojan-activity; sid:100001425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.180",nocase; classtype:trojan-activity; sid:100001426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.187",nocase; classtype:trojan-activity; sid:100001427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.190",nocase; classtype:trojan-activity; sid:100001428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.218",nocase; classtype:trojan-activity; sid:100001429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.34",nocase; classtype:trojan-activity; sid:100001430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.4",nocase; classtype:trojan-activity; sid:100001431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.87",nocase; classtype:trojan-activity; sid:100001432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.110",nocase; classtype:trojan-activity; sid:100001433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.243",nocase; classtype:trojan-activity; sid:100001434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.134",nocase; classtype:trojan-activity; sid:100001435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.152",nocase; classtype:trojan-activity; sid:100001436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.190",nocase; classtype:trojan-activity; sid:100001437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.221",nocase; classtype:trojan-activity; sid:100001438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.228",nocase; classtype:trojan-activity; sid:100001439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.245",nocase; classtype:trojan-activity; sid:100001440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.35",nocase; classtype:trojan-activity; sid:100001441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.53",nocase; classtype:trojan-activity; sid:100001442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.172",nocase; classtype:trojan-activity; sid:100001443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.195",nocase; classtype:trojan-activity; sid:100001444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.27",nocase; classtype:trojan-activity; sid:100001445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.106",nocase; classtype:trojan-activity; sid:100001446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.110",nocase; classtype:trojan-activity; sid:100001447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.120",nocase; classtype:trojan-activity; sid:100001448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.140",nocase; classtype:trojan-activity; sid:100001449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.155",nocase; classtype:trojan-activity; sid:100001450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.16",nocase; classtype:trojan-activity; sid:100001451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.169",nocase; classtype:trojan-activity; sid:100001452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.183",nocase; classtype:trojan-activity; sid:100001453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.196",nocase; classtype:trojan-activity; sid:100001454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.206",nocase; classtype:trojan-activity; sid:100001455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.49",nocase; classtype:trojan-activity; sid:100001456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.125",nocase; classtype:trojan-activity; sid:100001457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.146",nocase; classtype:trojan-activity; sid:100001458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.197",nocase; classtype:trojan-activity; sid:100001459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.217",nocase; classtype:trojan-activity; sid:100001460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.220",nocase; classtype:trojan-activity; sid:100001461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.245",nocase; classtype:trojan-activity; sid:100001462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.104",nocase; classtype:trojan-activity; sid:100001463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.106",nocase; classtype:trojan-activity; sid:100001464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.118",nocase; classtype:trojan-activity; sid:100001465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.18",nocase; classtype:trojan-activity; sid:100001466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.193",nocase; classtype:trojan-activity; sid:100001467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.37",nocase; classtype:trojan-activity; sid:100001468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.77",nocase; classtype:trojan-activity; sid:100001469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.0",nocase; classtype:trojan-activity; sid:100001470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.133",nocase; classtype:trojan-activity; sid:100001471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.149",nocase; classtype:trojan-activity; sid:100001472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.240",nocase; classtype:trojan-activity; sid:100001473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.245",nocase; classtype:trojan-activity; sid:100001474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.83",nocase; classtype:trojan-activity; sid:100001475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.87",nocase; classtype:trojan-activity; sid:100001476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.94",nocase; classtype:trojan-activity; sid:100001477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.132",nocase; classtype:trojan-activity; sid:100001478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.140",nocase; classtype:trojan-activity; sid:100001479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.37",nocase; classtype:trojan-activity; sid:100001480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.77",nocase; classtype:trojan-activity; sid:100001481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.109",nocase; classtype:trojan-activity; sid:100001482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.165",nocase; classtype:trojan-activity; sid:100001483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.176",nocase; classtype:trojan-activity; sid:100001484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.184",nocase; classtype:trojan-activity; sid:100001485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.204",nocase; classtype:trojan-activity; sid:100001486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.57",nocase; classtype:trojan-activity; sid:100001487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.6",nocase; classtype:trojan-activity; sid:100001488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.155",nocase; classtype:trojan-activity; sid:100001489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.169",nocase; classtype:trojan-activity; sid:100001490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.197",nocase; classtype:trojan-activity; sid:100001491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.198",nocase; classtype:trojan-activity; sid:100001492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.221",nocase; classtype:trojan-activity; sid:100001493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.250",nocase; classtype:trojan-activity; sid:100001494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.105",nocase; classtype:trojan-activity; sid:100001495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.159",nocase; classtype:trojan-activity; sid:100001496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.187",nocase; classtype:trojan-activity; sid:100001497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.190",nocase; classtype:trojan-activity; sid:100001498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.203",nocase; classtype:trojan-activity; sid:100001499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.206",nocase; classtype:trojan-activity; sid:100001500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.36",nocase; classtype:trojan-activity; sid:100001501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.98",nocase; classtype:trojan-activity; sid:100001502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.139",nocase; classtype:trojan-activity; sid:100001503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.147",nocase; classtype:trojan-activity; sid:100001504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.159",nocase; classtype:trojan-activity; sid:100001505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.4",nocase; classtype:trojan-activity; sid:100001506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.46",nocase; classtype:trojan-activity; sid:100001507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.59",nocase; classtype:trojan-activity; sid:100001508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.66",nocase; classtype:trojan-activity; sid:100001509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.85",nocase; classtype:trojan-activity; sid:100001510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.174",nocase; classtype:trojan-activity; sid:100001511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.200",nocase; classtype:trojan-activity; sid:100001512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.254",nocase; classtype:trojan-activity; sid:100001513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.29",nocase; classtype:trojan-activity; sid:100001514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.51",nocase; classtype:trojan-activity; sid:100001515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.55",nocase; classtype:trojan-activity; sid:100001516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.63",nocase; classtype:trojan-activity; sid:100001517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.90",nocase; classtype:trojan-activity; sid:100001518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.99",nocase; classtype:trojan-activity; sid:100001519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.138",nocase; classtype:trojan-activity; sid:100001520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.206",nocase; classtype:trojan-activity; sid:100001521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.208",nocase; classtype:trojan-activity; sid:100001522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.188",nocase; classtype:trojan-activity; sid:100001523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.200",nocase; classtype:trojan-activity; sid:100001524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.227",nocase; classtype:trojan-activity; sid:100001525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.48",nocase; classtype:trojan-activity; sid:100001526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.64",nocase; classtype:trojan-activity; sid:100001527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.209",nocase; classtype:trojan-activity; sid:100001528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.215",nocase; classtype:trojan-activity; sid:100001529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.39",nocase; classtype:trojan-activity; sid:100001530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.51",nocase; classtype:trojan-activity; sid:100001531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.112",nocase; classtype:trojan-activity; sid:100001532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.113",nocase; classtype:trojan-activity; sid:100001533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.165",nocase; classtype:trojan-activity; sid:100001534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.192",nocase; classtype:trojan-activity; sid:100001535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.198",nocase; classtype:trojan-activity; sid:100001536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.47",nocase; classtype:trojan-activity; sid:100001537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.60",nocase; classtype:trojan-activity; sid:100001538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.215",nocase; classtype:trojan-activity; sid:100001539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.237",nocase; classtype:trojan-activity; sid:100001540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.26",nocase; classtype:trojan-activity; sid:100001541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.56",nocase; classtype:trojan-activity; sid:100001542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.73",nocase; classtype:trojan-activity; sid:100001543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.86",nocase; classtype:trojan-activity; sid:100001544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.138",nocase; classtype:trojan-activity; sid:100001545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.151",nocase; classtype:trojan-activity; sid:100001546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.40",nocase; classtype:trojan-activity; sid:100001547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.53",nocase; classtype:trojan-activity; sid:100001548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.70",nocase; classtype:trojan-activity; sid:100001549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.97",nocase; classtype:trojan-activity; sid:100001550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.133",nocase; classtype:trojan-activity; sid:100001551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.162",nocase; classtype:trojan-activity; sid:100001552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.184",nocase; classtype:trojan-activity; sid:100001553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.196",nocase; classtype:trojan-activity; sid:100001554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.203",nocase; classtype:trojan-activity; sid:100001555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.231",nocase; classtype:trojan-activity; sid:100001556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.4",nocase; classtype:trojan-activity; sid:100001557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.116",nocase; classtype:trojan-activity; sid:100001558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.122",nocase; classtype:trojan-activity; sid:100001559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.123",nocase; classtype:trojan-activity; sid:100001560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.155",nocase; classtype:trojan-activity; sid:100001561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.190",nocase; classtype:trojan-activity; sid:100001562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.229",nocase; classtype:trojan-activity; sid:100001563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.63",nocase; classtype:trojan-activity; sid:100001564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.83",nocase; classtype:trojan-activity; sid:100001565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.123",nocase; classtype:trojan-activity; sid:100001566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.130",nocase; classtype:trojan-activity; sid:100001567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.168",nocase; classtype:trojan-activity; sid:100001568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.201",nocase; classtype:trojan-activity; sid:100001569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.217",nocase; classtype:trojan-activity; sid:100001570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.245",nocase; classtype:trojan-activity; sid:100001571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.26",nocase; classtype:trojan-activity; sid:100001572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.28",nocase; classtype:trojan-activity; sid:100001573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.191",nocase; classtype:trojan-activity; sid:100001574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.196",nocase; classtype:trojan-activity; sid:100001575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.2",nocase; classtype:trojan-activity; sid:100001576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.30",nocase; classtype:trojan-activity; sid:100001577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.40",nocase; classtype:trojan-activity; sid:100001578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.56",nocase; classtype:trojan-activity; sid:100001579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.7",nocase; classtype:trojan-activity; sid:100001580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.90",nocase; classtype:trojan-activity; sid:100001581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.109",nocase; classtype:trojan-activity; sid:100001582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.122",nocase; classtype:trojan-activity; sid:100001583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.131",nocase; classtype:trojan-activity; sid:100001584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.197",nocase; classtype:trojan-activity; sid:100001585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.4",nocase; classtype:trojan-activity; sid:100001586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.79",nocase; classtype:trojan-activity; sid:100001587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.89",nocase; classtype:trojan-activity; sid:100001588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.9",nocase; classtype:trojan-activity; sid:100001589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.14",nocase; classtype:trojan-activity; sid:100001590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.153",nocase; classtype:trojan-activity; sid:100001591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.174",nocase; classtype:trojan-activity; sid:100001592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.227",nocase; classtype:trojan-activity; sid:100001593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.39",nocase; classtype:trojan-activity; sid:100001594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.167",nocase; classtype:trojan-activity; sid:100001595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.171",nocase; classtype:trojan-activity; sid:100001596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.220",nocase; classtype:trojan-activity; sid:100001597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.222",nocase; classtype:trojan-activity; sid:100001598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.237",nocase; classtype:trojan-activity; sid:100001599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.61",nocase; classtype:trojan-activity; sid:100001600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.62",nocase; classtype:trojan-activity; sid:100001601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.83",nocase; classtype:trojan-activity; sid:100001602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.93",nocase; classtype:trojan-activity; sid:100001603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.10",nocase; classtype:trojan-activity; sid:100001604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.119",nocase; classtype:trojan-activity; sid:100001605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.122",nocase; classtype:trojan-activity; sid:100001606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.15",nocase; classtype:trojan-activity; sid:100001607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.159",nocase; classtype:trojan-activity; sid:100001608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.166",nocase; classtype:trojan-activity; sid:100001609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.176",nocase; classtype:trojan-activity; sid:100001610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.230",nocase; classtype:trojan-activity; sid:100001611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.231",nocase; classtype:trojan-activity; sid:100001612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.236",nocase; classtype:trojan-activity; sid:100001613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.237",nocase; classtype:trojan-activity; sid:100001614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.63",nocase; classtype:trojan-activity; sid:100001615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.64",nocase; classtype:trojan-activity; sid:100001616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.75",nocase; classtype:trojan-activity; sid:100001617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.1",nocase; classtype:trojan-activity; sid:100001618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.157",nocase; classtype:trojan-activity; sid:100001619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.19",nocase; classtype:trojan-activity; sid:100001620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.220",nocase; classtype:trojan-activity; sid:100001621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.237",nocase; classtype:trojan-activity; sid:100001622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.250",nocase; classtype:trojan-activity; sid:100001623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.178",nocase; classtype:trojan-activity; sid:100001624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.185",nocase; classtype:trojan-activity; sid:100001625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.230",nocase; classtype:trojan-activity; sid:100001626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.60",nocase; classtype:trojan-activity; sid:100001627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.69",nocase; classtype:trojan-activity; sid:100001628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.166",nocase; classtype:trojan-activity; sid:100001629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.199",nocase; classtype:trojan-activity; sid:100001630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.215",nocase; classtype:trojan-activity; sid:100001631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.217",nocase; classtype:trojan-activity; sid:100001632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.253",nocase; classtype:trojan-activity; sid:100001633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.35",nocase; classtype:trojan-activity; sid:100001634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.45",nocase; classtype:trojan-activity; sid:100001635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.5",nocase; classtype:trojan-activity; sid:100001636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.85",nocase; classtype:trojan-activity; sid:100001637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.1",nocase; classtype:trojan-activity; sid:100001638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.108",nocase; classtype:trojan-activity; sid:100001639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.114",nocase; classtype:trojan-activity; sid:100001640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.123",nocase; classtype:trojan-activity; sid:100001641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.179",nocase; classtype:trojan-activity; sid:100001642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.221",nocase; classtype:trojan-activity; sid:100001643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.49",nocase; classtype:trojan-activity; sid:100001644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.59",nocase; classtype:trojan-activity; sid:100001645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.73",nocase; classtype:trojan-activity; sid:100001646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.97",nocase; classtype:trojan-activity; sid:100001647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.245",nocase; classtype:trojan-activity; sid:100001648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.93",nocase; classtype:trojan-activity; sid:100001649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.163",nocase; classtype:trojan-activity; sid:100001650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.174",nocase; classtype:trojan-activity; sid:100001651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.229",nocase; classtype:trojan-activity; sid:100001652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.44",nocase; classtype:trojan-activity; sid:100001653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.108",nocase; classtype:trojan-activity; sid:100001654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.110",nocase; classtype:trojan-activity; sid:100001655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.123",nocase; classtype:trojan-activity; sid:100001656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.188",nocase; classtype:trojan-activity; sid:100001657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.237",nocase; classtype:trojan-activity; sid:100001658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.41",nocase; classtype:trojan-activity; sid:100001659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.47",nocase; classtype:trojan-activity; sid:100001660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.5",nocase; classtype:trojan-activity; sid:100001661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.54",nocase; classtype:trojan-activity; sid:100001662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.117",nocase; classtype:trojan-activity; sid:100001663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.170",nocase; classtype:trojan-activity; sid:100001664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.225",nocase; classtype:trojan-activity; sid:100001665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.237",nocase; classtype:trojan-activity; sid:100001666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.24",nocase; classtype:trojan-activity; sid:100001667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.70",nocase; classtype:trojan-activity; sid:100001668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.149",nocase; classtype:trojan-activity; sid:100001669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.170",nocase; classtype:trojan-activity; sid:100001670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.184",nocase; classtype:trojan-activity; sid:100001671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.233",nocase; classtype:trojan-activity; sid:100001672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.238",nocase; classtype:trojan-activity; sid:100001673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.76",nocase; classtype:trojan-activity; sid:100001674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.8",nocase; classtype:trojan-activity; sid:100001675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.110",nocase; classtype:trojan-activity; sid:100001676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.147",nocase; classtype:trojan-activity; sid:100001677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.237",nocase; classtype:trojan-activity; sid:100001678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.247",nocase; classtype:trojan-activity; sid:100001679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.102",nocase; classtype:trojan-activity; sid:100001680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.156",nocase; classtype:trojan-activity; sid:100001681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.228",nocase; classtype:trojan-activity; sid:100001682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.250",nocase; classtype:trojan-activity; sid:100001683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.36",nocase; classtype:trojan-activity; sid:100001684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.138",nocase; classtype:trojan-activity; sid:100001685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.170",nocase; classtype:trojan-activity; sid:100001686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.171",nocase; classtype:trojan-activity; sid:100001687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.172",nocase; classtype:trojan-activity; sid:100001688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.177",nocase; classtype:trojan-activity; sid:100001689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.216",nocase; classtype:trojan-activity; sid:100001690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.218",nocase; classtype:trojan-activity; sid:100001691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.238",nocase; classtype:trojan-activity; sid:100001692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.243",nocase; classtype:trojan-activity; sid:100001693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.77",nocase; classtype:trojan-activity; sid:100001694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.113",nocase; classtype:trojan-activity; sid:100001695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.117",nocase; classtype:trojan-activity; sid:100001696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.169",nocase; classtype:trojan-activity; sid:100001697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.177",nocase; classtype:trojan-activity; sid:100001698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.28",nocase; classtype:trojan-activity; sid:100001699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.46",nocase; classtype:trojan-activity; sid:100001700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.56",nocase; classtype:trojan-activity; sid:100001701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.64",nocase; classtype:trojan-activity; sid:100001702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.75",nocase; classtype:trojan-activity; sid:100001703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.77",nocase; classtype:trojan-activity; sid:100001704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.112",nocase; classtype:trojan-activity; sid:100001705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.116",nocase; classtype:trojan-activity; sid:100001706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.164",nocase; classtype:trojan-activity; sid:100001707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.165",nocase; classtype:trojan-activity; sid:100001708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.209",nocase; classtype:trojan-activity; sid:100001709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.215",nocase; classtype:trojan-activity; sid:100001710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.219",nocase; classtype:trojan-activity; sid:100001711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.224",nocase; classtype:trojan-activity; sid:100001712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.246",nocase; classtype:trojan-activity; sid:100001713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.34",nocase; classtype:trojan-activity; sid:100001714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.106",nocase; classtype:trojan-activity; sid:100001715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.122",nocase; classtype:trojan-activity; sid:100001716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.138",nocase; classtype:trojan-activity; sid:100001717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.14",nocase; classtype:trojan-activity; sid:100001718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.167",nocase; classtype:trojan-activity; sid:100001719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.171",nocase; classtype:trojan-activity; sid:100001720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.177",nocase; classtype:trojan-activity; sid:100001721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.179",nocase; classtype:trojan-activity; sid:100001722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.199",nocase; classtype:trojan-activity; sid:100001723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.202",nocase; classtype:trojan-activity; sid:100001724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.215",nocase; classtype:trojan-activity; sid:100001725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.225",nocase; classtype:trojan-activity; sid:100001726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.233",nocase; classtype:trojan-activity; sid:100001727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.239",nocase; classtype:trojan-activity; sid:100001728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.32",nocase; classtype:trojan-activity; sid:100001729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.37",nocase; classtype:trojan-activity; sid:100001730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.46",nocase; classtype:trojan-activity; sid:100001731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.48",nocase; classtype:trojan-activity; sid:100001732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.68",nocase; classtype:trojan-activity; sid:100001733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.69",nocase; classtype:trojan-activity; sid:100001734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.102",nocase; classtype:trojan-activity; sid:100001735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.199",nocase; classtype:trojan-activity; sid:100001736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.16",nocase; classtype:trojan-activity; sid:100001737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.173",nocase; classtype:trojan-activity; sid:100001738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.174",nocase; classtype:trojan-activity; sid:100001739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.2",nocase; classtype:trojan-activity; sid:100001740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.201",nocase; classtype:trojan-activity; sid:100001741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.207",nocase; classtype:trojan-activity; sid:100001742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.220",nocase; classtype:trojan-activity; sid:100001743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.116",nocase; classtype:trojan-activity; sid:100001744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.130",nocase; classtype:trojan-activity; sid:100001745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.166",nocase; classtype:trojan-activity; sid:100001746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.172",nocase; classtype:trojan-activity; sid:100001747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.190",nocase; classtype:trojan-activity; sid:100001748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.196",nocase; classtype:trojan-activity; sid:100001749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.214",nocase; classtype:trojan-activity; sid:100001750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.0",nocase; classtype:trojan-activity; sid:100001751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.135",nocase; classtype:trojan-activity; sid:100001752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.213",nocase; classtype:trojan-activity; sid:100001753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.252",nocase; classtype:trojan-activity; sid:100001754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.70",nocase; classtype:trojan-activity; sid:100001755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.93",nocase; classtype:trojan-activity; sid:100001756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.96",nocase; classtype:trojan-activity; sid:100001757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.171",nocase; classtype:trojan-activity; sid:100001758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.251",nocase; classtype:trojan-activity; sid:100001759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.6",nocase; classtype:trojan-activity; sid:100001760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.197",nocase; classtype:trojan-activity; sid:100001761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.198",nocase; classtype:trojan-activity; sid:100001762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.2",nocase; classtype:trojan-activity; sid:100001763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.20",nocase; classtype:trojan-activity; sid:100001764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.211",nocase; classtype:trojan-activity; sid:100001765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.229",nocase; classtype:trojan-activity; sid:100001766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.243",nocase; classtype:trojan-activity; sid:100001767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.89",nocase; classtype:trojan-activity; sid:100001768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.95",nocase; classtype:trojan-activity; sid:100001769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.112",nocase; classtype:trojan-activity; sid:100001770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.141",nocase; classtype:trojan-activity; sid:100001771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.162",nocase; classtype:trojan-activity; sid:100001772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.173",nocase; classtype:trojan-activity; sid:100001773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.181",nocase; classtype:trojan-activity; sid:100001774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.2",nocase; classtype:trojan-activity; sid:100001775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.208",nocase; classtype:trojan-activity; sid:100001776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.215",nocase; classtype:trojan-activity; sid:100001777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.228",nocase; classtype:trojan-activity; sid:100001778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.234",nocase; classtype:trojan-activity; sid:100001779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.26",nocase; classtype:trojan-activity; sid:100001780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.28",nocase; classtype:trojan-activity; sid:100001781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.63",nocase; classtype:trojan-activity; sid:100001782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.1",nocase; classtype:trojan-activity; sid:100001783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.2",nocase; classtype:trojan-activity; sid:100001784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.200",nocase; classtype:trojan-activity; sid:100001785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.243",nocase; classtype:trojan-activity; sid:100001786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.144",nocase; classtype:trojan-activity; sid:100001787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.21",nocase; classtype:trojan-activity; sid:100001788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.38",nocase; classtype:trojan-activity; sid:100001789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.83",nocase; classtype:trojan-activity; sid:100001790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.0",nocase; classtype:trojan-activity; sid:100001791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.127",nocase; classtype:trojan-activity; sid:100001792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.129",nocase; classtype:trojan-activity; sid:100001793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.218",nocase; classtype:trojan-activity; sid:100001794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.231",nocase; classtype:trojan-activity; sid:100001795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.245",nocase; classtype:trojan-activity; sid:100001796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.33",nocase; classtype:trojan-activity; sid:100001797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.107",nocase; classtype:trojan-activity; sid:100001798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.135",nocase; classtype:trojan-activity; sid:100001799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.153",nocase; classtype:trojan-activity; sid:100001800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.223",nocase; classtype:trojan-activity; sid:100001801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.26",nocase; classtype:trojan-activity; sid:100001802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.38",nocase; classtype:trojan-activity; sid:100001803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.56",nocase; classtype:trojan-activity; sid:100001804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.6",nocase; classtype:trojan-activity; sid:100001805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.81",nocase; classtype:trojan-activity; sid:100001806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.83",nocase; classtype:trojan-activity; sid:100001807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.1",nocase; classtype:trojan-activity; sid:100001808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.132",nocase; classtype:trojan-activity; sid:100001809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.141",nocase; classtype:trojan-activity; sid:100001810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.165",nocase; classtype:trojan-activity; sid:100001811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.191",nocase; classtype:trojan-activity; sid:100001812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.28",nocase; classtype:trojan-activity; sid:100001813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.98",nocase; classtype:trojan-activity; sid:100001814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.158",nocase; classtype:trojan-activity; sid:100001815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.245",nocase; classtype:trojan-activity; sid:100001816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.57",nocase; classtype:trojan-activity; sid:100001817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.144",nocase; classtype:trojan-activity; sid:100001818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.219",nocase; classtype:trojan-activity; sid:100001819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.222",nocase; classtype:trojan-activity; sid:100001820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.231",nocase; classtype:trojan-activity; sid:100001821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.95",nocase; classtype:trojan-activity; sid:100001822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.155",nocase; classtype:trojan-activity; sid:100001823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.166",nocase; classtype:trojan-activity; sid:100001824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.226",nocase; classtype:trojan-activity; sid:100001825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.228",nocase; classtype:trojan-activity; sid:100001826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.41",nocase; classtype:trojan-activity; sid:100001827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.56",nocase; classtype:trojan-activity; sid:100001828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.67",nocase; classtype:trojan-activity; sid:100001829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.82",nocase; classtype:trojan-activity; sid:100001830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.203",nocase; classtype:trojan-activity; sid:100001831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.34",nocase; classtype:trojan-activity; sid:100001832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.171",nocase; classtype:trojan-activity; sid:100001833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.1",nocase; classtype:trojan-activity; sid:100001834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.106",nocase; classtype:trojan-activity; sid:100001835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.121",nocase; classtype:trojan-activity; sid:100001836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.138",nocase; classtype:trojan-activity; sid:100001837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.147",nocase; classtype:trojan-activity; sid:100001838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.217",nocase; classtype:trojan-activity; sid:100001839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.30",nocase; classtype:trojan-activity; sid:100001840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.33",nocase; classtype:trojan-activity; sid:100001841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.69",nocase; classtype:trojan-activity; sid:100001842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.0",nocase; classtype:trojan-activity; sid:100001843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.134",nocase; classtype:trojan-activity; sid:100001844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.143",nocase; classtype:trojan-activity; sid:100001845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.155",nocase; classtype:trojan-activity; sid:100001846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.186",nocase; classtype:trojan-activity; sid:100001847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.197",nocase; classtype:trojan-activity; sid:100001848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.217",nocase; classtype:trojan-activity; sid:100001849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.22",nocase; classtype:trojan-activity; sid:100001850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.241",nocase; classtype:trojan-activity; sid:100001851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.70",nocase; classtype:trojan-activity; sid:100001852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.89",nocase; classtype:trojan-activity; sid:100001853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.90",nocase; classtype:trojan-activity; sid:100001854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.95",nocase; classtype:trojan-activity; sid:100001855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.96",nocase; classtype:trojan-activity; sid:100001856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.191",nocase; classtype:trojan-activity; sid:100001857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.205",nocase; classtype:trojan-activity; sid:100001858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.6",nocase; classtype:trojan-activity; sid:100001859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.87",nocase; classtype:trojan-activity; sid:100001860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.119",nocase; classtype:trojan-activity; sid:100001861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.187",nocase; classtype:trojan-activity; sid:100001862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.224",nocase; classtype:trojan-activity; sid:100001863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.42",nocase; classtype:trojan-activity; sid:100001864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.11",nocase; classtype:trojan-activity; sid:100001865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.141",nocase; classtype:trojan-activity; sid:100001866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.151",nocase; classtype:trojan-activity; sid:100001867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.168",nocase; classtype:trojan-activity; sid:100001868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.245",nocase; classtype:trojan-activity; sid:100001869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.110",nocase; classtype:trojan-activity; sid:100001870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.168",nocase; classtype:trojan-activity; sid:100001871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.139",nocase; classtype:trojan-activity; sid:100001872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.247",nocase; classtype:trojan-activity; sid:100001873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.3",nocase; classtype:trojan-activity; sid:100001874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.17",nocase; classtype:trojan-activity; sid:100001875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.51",nocase; classtype:trojan-activity; sid:100001876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.131",nocase; classtype:trojan-activity; sid:100001877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.177",nocase; classtype:trojan-activity; sid:100001878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.22",nocase; classtype:trojan-activity; sid:100001879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.236",nocase; classtype:trojan-activity; sid:100001880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.237",nocase; classtype:trojan-activity; sid:100001881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.27",nocase; classtype:trojan-activity; sid:100001882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.137",nocase; classtype:trojan-activity; sid:100001883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.160",nocase; classtype:trojan-activity; sid:100001884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.202",nocase; classtype:trojan-activity; sid:100001885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.66",nocase; classtype:trojan-activity; sid:100001886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.161",nocase; classtype:trojan-activity; sid:100001887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.212",nocase; classtype:trojan-activity; sid:100001888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.71",nocase; classtype:trojan-activity; sid:100001889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.94",nocase; classtype:trojan-activity; sid:100001890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.135",nocase; classtype:trojan-activity; sid:100001891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.151",nocase; classtype:trojan-activity; sid:100001892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.186",nocase; classtype:trojan-activity; sid:100001893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.217",nocase; classtype:trojan-activity; sid:100001894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.4",nocase; classtype:trojan-activity; sid:100001895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.5",nocase; classtype:trojan-activity; sid:100001896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.56",nocase; classtype:trojan-activity; sid:100001897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.58",nocase; classtype:trojan-activity; sid:100001898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.79",nocase; classtype:trojan-activity; sid:100001899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.158",nocase; classtype:trojan-activity; sid:100001900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.163",nocase; classtype:trojan-activity; sid:100001901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.205",nocase; classtype:trojan-activity; sid:100001902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.214",nocase; classtype:trojan-activity; sid:100001903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.225",nocase; classtype:trojan-activity; sid:100001904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.64",nocase; classtype:trojan-activity; sid:100001905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.103",nocase; classtype:trojan-activity; sid:100001906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.14",nocase; classtype:trojan-activity; sid:100001907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.163",nocase; classtype:trojan-activity; sid:100001908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.181",nocase; classtype:trojan-activity; sid:100001909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.25",nocase; classtype:trojan-activity; sid:100001910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.29",nocase; classtype:trojan-activity; sid:100001911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.38",nocase; classtype:trojan-activity; sid:100001912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.41",nocase; classtype:trojan-activity; sid:100001913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.47",nocase; classtype:trojan-activity; sid:100001914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.77",nocase; classtype:trojan-activity; sid:100001915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.103",nocase; classtype:trojan-activity; sid:100001916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.11",nocase; classtype:trojan-activity; sid:100001917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.120",nocase; classtype:trojan-activity; sid:100001918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.18",nocase; classtype:trojan-activity; sid:100001919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.196",nocase; classtype:trojan-activity; sid:100001920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.24",nocase; classtype:trojan-activity; sid:100001921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.252",nocase; classtype:trojan-activity; sid:100001922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.33",nocase; classtype:trojan-activity; sid:100001923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.37",nocase; classtype:trojan-activity; sid:100001924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.50",nocase; classtype:trojan-activity; sid:100001925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.54",nocase; classtype:trojan-activity; sid:100001926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.72",nocase; classtype:trojan-activity; sid:100001927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.75",nocase; classtype:trojan-activity; sid:100001928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.10",nocase; classtype:trojan-activity; sid:100001929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.141",nocase; classtype:trojan-activity; sid:100001930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.179",nocase; classtype:trojan-activity; sid:100001931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.28",nocase; classtype:trojan-activity; sid:100001932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.29",nocase; classtype:trojan-activity; sid:100001933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.74",nocase; classtype:trojan-activity; sid:100001934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.79",nocase; classtype:trojan-activity; sid:100001935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.161",nocase; classtype:trojan-activity; sid:100001936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.33",nocase; classtype:trojan-activity; sid:100001937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.47",nocase; classtype:trojan-activity; sid:100001938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.54",nocase; classtype:trojan-activity; sid:100001939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.134",nocase; classtype:trojan-activity; sid:100001940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.157",nocase; classtype:trojan-activity; sid:100001941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.189",nocase; classtype:trojan-activity; sid:100001942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.209",nocase; classtype:trojan-activity; sid:100001943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.212",nocase; classtype:trojan-activity; sid:100001944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.251",nocase; classtype:trojan-activity; sid:100001945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.156",nocase; classtype:trojan-activity; sid:100001946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.163",nocase; classtype:trojan-activity; sid:100001947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.17",nocase; classtype:trojan-activity; sid:100001948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.171",nocase; classtype:trojan-activity; sid:100001949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.219",nocase; classtype:trojan-activity; sid:100001950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.237",nocase; classtype:trojan-activity; sid:100001951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.111",nocase; classtype:trojan-activity; sid:100001952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.115",nocase; classtype:trojan-activity; sid:100001953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.166",nocase; classtype:trojan-activity; sid:100001954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.168",nocase; classtype:trojan-activity; sid:100001955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.208",nocase; classtype:trojan-activity; sid:100001956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.42",nocase; classtype:trojan-activity; sid:100001957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.43",nocase; classtype:trojan-activity; sid:100001958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.70",nocase; classtype:trojan-activity; sid:100001959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.8",nocase; classtype:trojan-activity; sid:100001960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.84",nocase; classtype:trojan-activity; sid:100001961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.167",nocase; classtype:trojan-activity; sid:100001962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.21",nocase; classtype:trojan-activity; sid:100001963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.73",nocase; classtype:trojan-activity; sid:100001964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.96",nocase; classtype:trojan-activity; sid:100001965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.12",nocase; classtype:trojan-activity; sid:100001966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.156",nocase; classtype:trojan-activity; sid:100001967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.158",nocase; classtype:trojan-activity; sid:100001968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.187",nocase; classtype:trojan-activity; sid:100001969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.22",nocase; classtype:trojan-activity; sid:100001970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.30",nocase; classtype:trojan-activity; sid:100001971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.50",nocase; classtype:trojan-activity; sid:100001972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.115",nocase; classtype:trojan-activity; sid:100001973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.202",nocase; classtype:trojan-activity; sid:100001974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.236",nocase; classtype:trojan-activity; sid:100001975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.105",nocase; classtype:trojan-activity; sid:100001976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.123",nocase; classtype:trojan-activity; sid:100001977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.186",nocase; classtype:trojan-activity; sid:100001978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.192",nocase; classtype:trojan-activity; sid:100001979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.199",nocase; classtype:trojan-activity; sid:100001980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.211",nocase; classtype:trojan-activity; sid:100001981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.228",nocase; classtype:trojan-activity; sid:100001982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.43",nocase; classtype:trojan-activity; sid:100001983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.54",nocase; classtype:trojan-activity; sid:100001984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.93",nocase; classtype:trojan-activity; sid:100001985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.0",nocase; classtype:trojan-activity; sid:100001986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.36",nocase; classtype:trojan-activity; sid:100001987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.51",nocase; classtype:trojan-activity; sid:100001988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.8",nocase; classtype:trojan-activity; sid:100001989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.81",nocase; classtype:trojan-activity; sid:100001990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.83",nocase; classtype:trojan-activity; sid:100001991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.89",nocase; classtype:trojan-activity; sid:100001992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.109",nocase; classtype:trojan-activity; sid:100001993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.44",nocase; classtype:trojan-activity; sid:100001994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.66",nocase; classtype:trojan-activity; sid:100001995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.85",nocase; classtype:trojan-activity; sid:100001996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.111",nocase; classtype:trojan-activity; sid:100001997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.112",nocase; classtype:trojan-activity; sid:100001998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.119",nocase; classtype:trojan-activity; sid:100001999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.128",nocase; classtype:trojan-activity; sid:100002000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.18",nocase; classtype:trojan-activity; sid:100002001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.4",nocase; classtype:trojan-activity; sid:100002002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.96",nocase; classtype:trojan-activity; sid:100002003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.6",nocase; classtype:trojan-activity; sid:100002004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.60",nocase; classtype:trojan-activity; sid:100002005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.71",nocase; classtype:trojan-activity; sid:100002006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.109",nocase; classtype:trojan-activity; sid:100002007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.12",nocase; classtype:trojan-activity; sid:100002008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.147",nocase; classtype:trojan-activity; sid:100002009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.18",nocase; classtype:trojan-activity; sid:100002010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.196",nocase; classtype:trojan-activity; sid:100002011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.218",nocase; classtype:trojan-activity; sid:100002012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.246",nocase; classtype:trojan-activity; sid:100002013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.38",nocase; classtype:trojan-activity; sid:100002014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.5",nocase; classtype:trojan-activity; sid:100002015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.50",nocase; classtype:trojan-activity; sid:100002016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.64",nocase; classtype:trojan-activity; sid:100002017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.71",nocase; classtype:trojan-activity; sid:100002018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.83",nocase; classtype:trojan-activity; sid:100002019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.202",nocase; classtype:trojan-activity; sid:100002020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.45",nocase; classtype:trojan-activity; sid:100002021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.55",nocase; classtype:trojan-activity; sid:100002022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.84",nocase; classtype:trojan-activity; sid:100002023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.108",nocase; classtype:trojan-activity; sid:100002024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.13",nocase; classtype:trojan-activity; sid:100002025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.222",nocase; classtype:trojan-activity; sid:100002026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.30",nocase; classtype:trojan-activity; sid:100002027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.37",nocase; classtype:trojan-activity; sid:100002028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.73.127",nocase; classtype:trojan-activity; sid:100002029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.73.77",nocase; classtype:trojan-activity; sid:100002030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.73.96",nocase; classtype:trojan-activity; sid:100002031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.182",nocase; classtype:trojan-activity; sid:100002032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.48",nocase; classtype:trojan-activity; sid:100002033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.130",nocase; classtype:trojan-activity; sid:100002034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.181",nocase; classtype:trojan-activity; sid:100002035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.19",nocase; classtype:trojan-activity; sid:100002036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.84",nocase; classtype:trojan-activity; sid:100002037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.87",nocase; classtype:trojan-activity; sid:100002038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.103",nocase; classtype:trojan-activity; sid:100002039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.109",nocase; classtype:trojan-activity; sid:100002040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.209",nocase; classtype:trojan-activity; sid:100002041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.21",nocase; classtype:trojan-activity; sid:100002042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.217",nocase; classtype:trojan-activity; sid:100002043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.83",nocase; classtype:trojan-activity; sid:100002044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.9",nocase; classtype:trojan-activity; sid:100002045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.46",nocase; classtype:trojan-activity; sid:100002046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.47",nocase; classtype:trojan-activity; sid:100002047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.71",nocase; classtype:trojan-activity; sid:100002048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.118",nocase; classtype:trojan-activity; sid:100002049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.198",nocase; classtype:trojan-activity; sid:100002050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.243",nocase; classtype:trojan-activity; sid:100002051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.46",nocase; classtype:trojan-activity; sid:100002052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.97",nocase; classtype:trojan-activity; sid:100002053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.17",nocase; classtype:trojan-activity; sid:100002054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.244",nocase; classtype:trojan-activity; sid:100002055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.247",nocase; classtype:trojan-activity; sid:100002056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.69",nocase; classtype:trojan-activity; sid:100002057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.100",nocase; classtype:trojan-activity; sid:100002058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.100",nocase; classtype:trojan-activity; sid:100002059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.114",nocase; classtype:trojan-activity; sid:100002060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.129",nocase; classtype:trojan-activity; sid:100002061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.17",nocase; classtype:trojan-activity; sid:100002062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.20",nocase; classtype:trojan-activity; sid:100002063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.35",nocase; classtype:trojan-activity; sid:100002064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.41",nocase; classtype:trojan-activity; sid:100002065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.61",nocase; classtype:trojan-activity; sid:100002066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.79",nocase; classtype:trojan-activity; sid:100002067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.86",nocase; classtype:trojan-activity; sid:100002068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.17",nocase; classtype:trojan-activity; sid:100002069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.192",nocase; classtype:trojan-activity; sid:100002070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.226",nocase; classtype:trojan-activity; sid:100002071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.232",nocase; classtype:trojan-activity; sid:100002072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.244",nocase; classtype:trojan-activity; sid:100002073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.253",nocase; classtype:trojan-activity; sid:100002074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.50",nocase; classtype:trojan-activity; sid:100002075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.82.137",nocase; classtype:trojan-activity; sid:100002076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.82.32",nocase; classtype:trojan-activity; sid:100002077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.2",nocase; classtype:trojan-activity; sid:100002078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.247",nocase; classtype:trojan-activity; sid:100002079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.102",nocase; classtype:trojan-activity; sid:100002080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.109",nocase; classtype:trojan-activity; sid:100002081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.159",nocase; classtype:trojan-activity; sid:100002082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.215",nocase; classtype:trojan-activity; sid:100002083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.42",nocase; classtype:trojan-activity; sid:100002084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.153",nocase; classtype:trojan-activity; sid:100002085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.183",nocase; classtype:trojan-activity; sid:100002086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.23",nocase; classtype:trojan-activity; sid:100002087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.55",nocase; classtype:trojan-activity; sid:100002088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.57",nocase; classtype:trojan-activity; sid:100002089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.119",nocase; classtype:trojan-activity; sid:100002090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.36",nocase; classtype:trojan-activity; sid:100002091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.59",nocase; classtype:trojan-activity; sid:100002092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.126",nocase; classtype:trojan-activity; sid:100002093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.139",nocase; classtype:trojan-activity; sid:100002094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.144",nocase; classtype:trojan-activity; sid:100002095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.253",nocase; classtype:trojan-activity; sid:100002096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.68",nocase; classtype:trojan-activity; sid:100002097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.127",nocase; classtype:trojan-activity; sid:100002098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.140",nocase; classtype:trojan-activity; sid:100002099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.166",nocase; classtype:trojan-activity; sid:100002100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.181",nocase; classtype:trojan-activity; sid:100002101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.182",nocase; classtype:trojan-activity; sid:100002102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.69",nocase; classtype:trojan-activity; sid:100002103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.157",nocase; classtype:trojan-activity; sid:100002104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.169",nocase; classtype:trojan-activity; sid:100002105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.24",nocase; classtype:trojan-activity; sid:100002106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.125",nocase; classtype:trojan-activity; sid:100002107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.139",nocase; classtype:trojan-activity; sid:100002108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.175",nocase; classtype:trojan-activity; sid:100002109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.179",nocase; classtype:trojan-activity; sid:100002110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.183",nocase; classtype:trojan-activity; sid:100002111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.198",nocase; classtype:trojan-activity; sid:100002112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.210",nocase; classtype:trojan-activity; sid:100002113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.215",nocase; classtype:trojan-activity; sid:100002114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.225",nocase; classtype:trojan-activity; sid:100002115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.84",nocase; classtype:trojan-activity; sid:100002116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.95",nocase; classtype:trojan-activity; sid:100002117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.122",nocase; classtype:trojan-activity; sid:100002118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.167",nocase; classtype:trojan-activity; sid:100002119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.172",nocase; classtype:trojan-activity; sid:100002120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.21",nocase; classtype:trojan-activity; sid:100002121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.212",nocase; classtype:trojan-activity; sid:100002122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.244",nocase; classtype:trojan-activity; sid:100002123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.4",nocase; classtype:trojan-activity; sid:100002124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.74",nocase; classtype:trojan-activity; sid:100002125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.108",nocase; classtype:trojan-activity; sid:100002126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.13",nocase; classtype:trojan-activity; sid:100002127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.15",nocase; classtype:trojan-activity; sid:100002128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.244",nocase; classtype:trojan-activity; sid:100002129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.253",nocase; classtype:trojan-activity; sid:100002130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.40",nocase; classtype:trojan-activity; sid:100002131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.96",nocase; classtype:trojan-activity; sid:100002132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.128",nocase; classtype:trojan-activity; sid:100002133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.132",nocase; classtype:trojan-activity; sid:100002134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.141",nocase; classtype:trojan-activity; sid:100002135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.186",nocase; classtype:trojan-activity; sid:100002136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.215",nocase; classtype:trojan-activity; sid:100002137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.231",nocase; classtype:trojan-activity; sid:100002138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.253",nocase; classtype:trojan-activity; sid:100002139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.45",nocase; classtype:trojan-activity; sid:100002140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.12",nocase; classtype:trojan-activity; sid:100002141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.143",nocase; classtype:trojan-activity; sid:100002142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.150",nocase; classtype:trojan-activity; sid:100002143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.159",nocase; classtype:trojan-activity; sid:100002144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.34",nocase; classtype:trojan-activity; sid:100002145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.45",nocase; classtype:trojan-activity; sid:100002146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.62",nocase; classtype:trojan-activity; sid:100002147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.93",nocase; classtype:trojan-activity; sid:100002148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.195",nocase; classtype:trojan-activity; sid:100002149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.200",nocase; classtype:trojan-activity; sid:100002150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.40",nocase; classtype:trojan-activity; sid:100002151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.55",nocase; classtype:trojan-activity; sid:100002152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.141",nocase; classtype:trojan-activity; sid:100002153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.17",nocase; classtype:trojan-activity; sid:100002154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.227",nocase; classtype:trojan-activity; sid:100002155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.237",nocase; classtype:trojan-activity; sid:100002156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.4",nocase; classtype:trojan-activity; sid:100002157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.56",nocase; classtype:trojan-activity; sid:100002158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.169",nocase; classtype:trojan-activity; sid:100002159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.192",nocase; classtype:trojan-activity; sid:100002160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.1",nocase; classtype:trojan-activity; sid:100002161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.128",nocase; classtype:trojan-activity; sid:100002162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.135",nocase; classtype:trojan-activity; sid:100002163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.143",nocase; classtype:trojan-activity; sid:100002164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.78",nocase; classtype:trojan-activity; sid:100002165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.228",nocase; classtype:trojan-activity; sid:100002166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.254",nocase; classtype:trojan-activity; sid:100002167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.29",nocase; classtype:trojan-activity; sid:100002168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.36",nocase; classtype:trojan-activity; sid:100002169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.68",nocase; classtype:trojan-activity; sid:100002170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.123",nocase; classtype:trojan-activity; sid:100002171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.130",nocase; classtype:trojan-activity; sid:100002172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.22",nocase; classtype:trojan-activity; sid:100002173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.45",nocase; classtype:trojan-activity; sid:100002174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.88",nocase; classtype:trojan-activity; sid:100002175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.91",nocase; classtype:trojan-activity; sid:100002176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.19.183.14",nocase; classtype:trojan-activity; sid:100002177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.205.101.33",nocase; classtype:trojan-activity; sid:100002178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.21.164.68",nocase; classtype:trojan-activity; sid:100002179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.217.8.194",nocase; classtype:trojan-activity; sid:100002180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.22.117.102",nocase; classtype:trojan-activity; sid:100002181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.222.252.130",nocase; classtype:trojan-activity; sid:100002182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.34.183.30",nocase; classtype:trojan-activity; sid:100002183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.48.235.59",nocase; classtype:trojan-activity; sid:100002184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.92.246.246",nocase; classtype:trojan-activity; sid:100002185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.95.115.33",nocase; classtype:trojan-activity; sid:100002186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.95.136.35",nocase; classtype:trojan-activity; sid:100002187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.159.58.134",nocase; classtype:trojan-activity; sid:100002188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.4.187.39",nocase; classtype:trojan-activity; sid:100002189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.43.157.173",nocase; classtype:trojan-activity; sid:100002190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.60.84.7",nocase; classtype:trojan-activity; sid:100002191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.99.210.161",nocase; classtype:trojan-activity; sid:100002192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.109.36.244",nocase; classtype:trojan-activity; sid:100002193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.111.101.141",nocase; classtype:trojan-activity; sid:100002194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.114.111.153",nocase; classtype:trojan-activity; sid:100002195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.116.203.220",nocase; classtype:trojan-activity; sid:100002196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.120.149.106",nocase; classtype:trojan-activity; sid:100002197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.122.13.227",nocase; classtype:trojan-activity; sid:100002198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.125.44.194",nocase; classtype:trojan-activity; sid:100002199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.157.66.204",nocase; classtype:trojan-activity; sid:100002200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.175.236.209",nocase; classtype:trojan-activity; sid:100002201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.175.93.52",nocase; classtype:trojan-activity; sid:100002202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.105.41",nocase; classtype:trojan-activity; sid:100002203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.110.243",nocase; classtype:trojan-activity; sid:100002204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.165.230",nocase; classtype:trojan-activity; sid:100002205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.214.171",nocase; classtype:trojan-activity; sid:100002206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.34.51",nocase; classtype:trojan-activity; sid:100002207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.96.248",nocase; classtype:trojan-activity; sid:100002208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.104.65",nocase; classtype:trojan-activity; sid:100002209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.242.73",nocase; classtype:trojan-activity; sid:100002210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.218.5.171",nocase; classtype:trojan-activity; sid:100002211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.248.80.38",nocase; classtype:trojan-activity; sid:100002212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.111.36",nocase; classtype:trojan-activity; sid:100002213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.53.93",nocase; classtype:trojan-activity; sid:100002214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.94.170.166",nocase; classtype:trojan-activity; sid:100002215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.138.154",nocase; classtype:trojan-activity; sid:100002216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.238",nocase; classtype:trojan-activity; sid:100002217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.6",nocase; classtype:trojan-activity; sid:100002218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.143.60.163",nocase; classtype:trojan-activity; sid:100002219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.193.107.10",nocase; classtype:trojan-activity; sid:100002220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.222",nocase; classtype:trojan-activity; sid:100002221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.230",nocase; classtype:trojan-activity; sid:100002222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.240",nocase; classtype:trojan-activity; sid:100002223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.210.45.42",nocase; classtype:trojan-activity; sid:100002224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.215.47.82",nocase; classtype:trojan-activity; sid:100002225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.224.242.131",nocase; classtype:trojan-activity; sid:100002226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.236.4",nocase; classtype:trojan-activity; sid:100002227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.59.162",nocase; classtype:trojan-activity; sid:100002228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.43.249",nocase; classtype:trojan-activity; sid:100002229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.52.131",nocase; classtype:trojan-activity; sid:100002230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.111.64",nocase; classtype:trojan-activity; sid:100002231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.24.20",nocase; classtype:trojan-activity; sid:100002232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.49.104",nocase; classtype:trojan-activity; sid:100002233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.64.27",nocase; classtype:trojan-activity; sid:100002234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.79.103",nocase; classtype:trojan-activity; sid:100002235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.83.88",nocase; classtype:trojan-activity; sid:100002236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.92.90",nocase; classtype:trojan-activity; sid:100002237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.93.96",nocase; classtype:trojan-activity; sid:100002238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.101.82",nocase; classtype:trojan-activity; sid:100002239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.103.234",nocase; classtype:trojan-activity; sid:100002240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.104.106",nocase; classtype:trojan-activity; sid:100002241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.108.180",nocase; classtype:trojan-activity; sid:100002242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.108.244",nocase; classtype:trojan-activity; sid:100002243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.118.250",nocase; classtype:trojan-activity; sid:100002244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.60.73",nocase; classtype:trojan-activity; sid:100002245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.61.252",nocase; classtype:trojan-activity; sid:100002246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.80.107",nocase; classtype:trojan-activity; sid:100002247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.94.196",nocase; classtype:trojan-activity; sid:100002248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.99.150",nocase; classtype:trojan-activity; sid:100002249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.15.172",nocase; classtype:trojan-activity; sid:100002250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.25.120",nocase; classtype:trojan-activity; sid:100002251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.26.235",nocase; classtype:trojan-activity; sid:100002252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.29.220",nocase; classtype:trojan-activity; sid:100002253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.39.51",nocase; classtype:trojan-activity; sid:100002254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.43.27",nocase; classtype:trojan-activity; sid:100002255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.118.146.181",nocase; classtype:trojan-activity; sid:100002256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.100.135",nocase; classtype:trojan-activity; sid:100002257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.109.173",nocase; classtype:trojan-activity; sid:100002258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.118.218",nocase; classtype:trojan-activity; sid:100002259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.14.252",nocase; classtype:trojan-activity; sid:100002260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.166.208",nocase; classtype:trojan-activity; sid:100002261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.176.209",nocase; classtype:trojan-activity; sid:100002262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.211.69",nocase; classtype:trojan-activity; sid:100002263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.214.120",nocase; classtype:trojan-activity; sid:100002264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.221.141",nocase; classtype:trojan-activity; sid:100002265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.225.30",nocase; classtype:trojan-activity; sid:100002266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.255.115",nocase; classtype:trojan-activity; sid:100002267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.7.54",nocase; classtype:trojan-activity; sid:100002268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.22",nocase; classtype:trojan-activity; sid:100002269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.46",nocase; classtype:trojan-activity; sid:100002270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.33.117",nocase; classtype:trojan-activity; sid:100002271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.37.251",nocase; classtype:trojan-activity; sid:100002272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.43.0",nocase; classtype:trojan-activity; sid:100002273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.11.43",nocase; classtype:trojan-activity; sid:100002274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.129.163",nocase; classtype:trojan-activity; sid:100002275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.130.67",nocase; classtype:trojan-activity; sid:100002276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.133.46",nocase; classtype:trojan-activity; sid:100002277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.134.70",nocase; classtype:trojan-activity; sid:100002278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.158.141",nocase; classtype:trojan-activity; sid:100002279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.205.201",nocase; classtype:trojan-activity; sid:100002280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.205.237",nocase; classtype:trojan-activity; sid:100002281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.207.195",nocase; classtype:trojan-activity; sid:100002282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.40.234",nocase; classtype:trojan-activity; sid:100002283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.50.111",nocase; classtype:trojan-activity; sid:100002284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.66.189",nocase; classtype:trojan-activity; sid:100002285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.9.117",nocase; classtype:trojan-activity; sid:100002286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.94.13",nocase; classtype:trojan-activity; sid:100002287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.181.105",nocase; classtype:trojan-activity; sid:100002288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.202.18",nocase; classtype:trojan-activity; sid:100002289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.123.203.21",nocase; classtype:trojan-activity; sid:100002290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.123.211.239",nocase; classtype:trojan-activity; sid:100002291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.123.107",nocase; classtype:trojan-activity; sid:100002292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.177.48",nocase; classtype:trojan-activity; sid:100002293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.19.87",nocase; classtype:trojan-activity; sid:100002294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.88.122",nocase; classtype:trojan-activity; sid:100002295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.113.127",nocase; classtype:trojan-activity; sid:100002296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.120.66",nocase; classtype:trojan-activity; sid:100002297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.126.203",nocase; classtype:trojan-activity; sid:100002298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.127.254",nocase; classtype:trojan-activity; sid:100002299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.181.121",nocase; classtype:trojan-activity; sid:100002300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.52.233",nocase; classtype:trojan-activity; sid:100002301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.67.24",nocase; classtype:trojan-activity; sid:100002302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.80.108",nocase; classtype:trojan-activity; sid:100002303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.83.79",nocase; classtype:trojan-activity; sid:100002304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.88.138",nocase; classtype:trojan-activity; sid:100002305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.103.79",nocase; classtype:trojan-activity; sid:100002306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.104.235",nocase; classtype:trojan-activity; sid:100002307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.110.147",nocase; classtype:trojan-activity; sid:100002308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.152.3",nocase; classtype:trojan-activity; sid:100002309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.155.157",nocase; classtype:trojan-activity; sid:100002310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.209.26",nocase; classtype:trojan-activity; sid:100002311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.221.243",nocase; classtype:trojan-activity; sid:100002312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.160.98.250",nocase; classtype:trojan-activity; sid:100002313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.172.36.164",nocase; classtype:trojan-activity; sid:100002314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.233.0.252",nocase; classtype:trojan-activity; sid:100002315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.235.252.31",nocase; classtype:trojan-activity; sid:100002316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.53.197.62",nocase; classtype:trojan-activity; sid:100002317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.58.219.8",nocase; classtype:trojan-activity; sid:100002318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.104.83",nocase; classtype:trojan-activity; sid:100002319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.225.154",nocase; classtype:trojan-activity; sid:100002320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.109.169.45",nocase; classtype:trojan-activity; sid:100002321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.11.238.228",nocase; classtype:trojan-activity; sid:100002322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.136.252.233",nocase; classtype:trojan-activity; sid:100002323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.150.138.131",nocase; classtype:trojan-activity; sid:100002324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.150.244.122",nocase; classtype:trojan-activity; sid:100002325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.16.208.30",nocase; classtype:trojan-activity; sid:100002326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.185.112.19",nocase; classtype:trojan-activity; sid:100002327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.187.163.176",nocase; classtype:trojan-activity; sid:100002328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.151.225",nocase; classtype:trojan-activity; sid:100002329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.180.116",nocase; classtype:trojan-activity; sid:100002330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.188.186",nocase; classtype:trojan-activity; sid:100002331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.228.38",nocase; classtype:trojan-activity; sid:100002332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.105.21",nocase; classtype:trojan-activity; sid:100002333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.125.235",nocase; classtype:trojan-activity; sid:100002334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.127.89",nocase; classtype:trojan-activity; sid:100002335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.26.115",nocase; classtype:trojan-activity; sid:100002336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.99.87",nocase; classtype:trojan-activity; sid:100002337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.92.195.140",nocase; classtype:trojan-activity; sid:100002338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.95.147.102",nocase; classtype:trojan-activity; sid:100002339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.97.22.14",nocase; classtype:trojan-activity; sid:100002340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.164.185.41",nocase; classtype:trojan-activity; sid:100002341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.175.115.10",nocase; classtype:trojan-activity; sid:100002342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.74.149.230",nocase; classtype:trojan-activity; sid:100002343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.106.209.68",nocase; classtype:trojan-activity; sid:100002344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.107.3.8",nocase; classtype:trojan-activity; sid:100002345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.172.110.235",nocase; classtype:trojan-activity; sid:100002346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.181.10.234",nocase; classtype:trojan-activity; sid:100002347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.112",nocase; classtype:trojan-activity; sid:100002348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.54",nocase; classtype:trojan-activity; sid:100002349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.77",nocase; classtype:trojan-activity; sid:100002350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.93",nocase; classtype:trojan-activity; sid:100002351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.219.133.122",nocase; classtype:trojan-activity; sid:100002352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.221.3.244",nocase; classtype:trojan-activity; sid:100002353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.228.141.74",nocase; classtype:trojan-activity; sid:100002354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.239.243.77",nocase; classtype:trojan-activity; sid:100002355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.245.96.94",nocase; classtype:trojan-activity; sid:100002356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.26.113.95",nocase; classtype:trojan-activity; sid:100002357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.34.16.231",nocase; classtype:trojan-activity; sid:100002358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.43.19.151",nocase; classtype:trojan-activity; sid:100002359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.45.103.212",nocase; classtype:trojan-activity; sid:100002360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.55.1.182",nocase; classtype:trojan-activity; sid:100002361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.68.230.207",nocase; classtype:trojan-activity; sid:100002362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.81.157.186",nocase; classtype:trojan-activity; sid:100002363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.185",nocase; classtype:trojan-activity; sid:100002364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.213",nocase; classtype:trojan-activity; sid:100002365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.160",nocase; classtype:trojan-activity; sid:100002366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.161",nocase; classtype:trojan-activity; sid:100002367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.219",nocase; classtype:trojan-activity; sid:100002368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.80",nocase; classtype:trojan-activity; sid:100002369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.90.166.56",nocase; classtype:trojan-activity; sid:100002370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.151.144.85",nocase; classtype:trojan-activity; sid:100002371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.219.164",nocase; classtype:trojan-activity; sid:100002372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.112",nocase; classtype:trojan-activity; sid:100002373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.77",nocase; classtype:trojan-activity; sid:100002374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.91",nocase; classtype:trojan-activity; sid:100002375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.253.150",nocase; classtype:trojan-activity; sid:100002376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.183.131.37",nocase; classtype:trojan-activity; sid:100002377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.225.120.173",nocase; classtype:trojan-activity; sid:100002378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.232.44.86",nocase; classtype:trojan-activity; sid:100002379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.28.60.184",nocase; classtype:trojan-activity; sid:100002380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.33.112.218",nocase; classtype:trojan-activity; sid:100002381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.33.112.228",nocase; classtype:trojan-activity; sid:100002382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.33.112.66",nocase; classtype:trojan-activity; sid:100002383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.33.113.241",nocase; classtype:trojan-activity; sid:100002384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.33.113.77",nocase; classtype:trojan-activity; sid:100002385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.4.125.48",nocase; classtype:trojan-activity; sid:100002386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.73.188.132",nocase; classtype:trojan-activity; sid:100002387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.12.10.98",nocase; classtype:trojan-activity; sid:100002388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.212.200.162",nocase; classtype:trojan-activity; sid:100002389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.233.208.103",nocase; classtype:trojan-activity; sid:100002390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.33.71.68",nocase; classtype:trojan-activity; sid:100002391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.21.14",nocase; classtype:trojan-activity; sid:100002392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.231.246",nocase; classtype:trojan-activity; sid:100002393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.113.102.18",nocase; classtype:trojan-activity; sid:100002394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.113.81.17",nocase; classtype:trojan-activity; sid:100002395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.13.179.87",nocase; classtype:trojan-activity; sid:100002396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.138.200.32",nocase; classtype:trojan-activity; sid:100002397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.152.41.141",nocase; classtype:trojan-activity; sid:100002398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.178.50",nocase; classtype:trojan-activity; sid:100002399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.199.59",nocase; classtype:trojan-activity; sid:100002400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.36.163",nocase; classtype:trojan-activity; sid:100002401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.45.140",nocase; classtype:trojan-activity; sid:100002402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.167.159",nocase; classtype:trojan-activity; sid:100002403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.242.144",nocase; classtype:trojan-activity; sid:100002404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.81.100.83",nocase; classtype:trojan-activity; sid:100002405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.83.202.25",nocase; classtype:trojan-activity; sid:100002406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"189.222.157.241",nocase; classtype:trojan-activity; sid:100002407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"19.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.0.42.106",nocase; classtype:trojan-activity; sid:100002409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.109.178.139",nocase; classtype:trojan-activity; sid:100002410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.110.161.252",nocase; classtype:trojan-activity; sid:100002411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.111.151.164",nocase; classtype:trojan-activity; sid:100002412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.119.207.58",nocase; classtype:trojan-activity; sid:100002413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.12.99.194",nocase; classtype:trojan-activity; sid:100002414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.121.194.18",nocase; classtype:trojan-activity; sid:100002415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.160",nocase; classtype:trojan-activity; sid:100002416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.3",nocase; classtype:trojan-activity; sid:100002417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.37",nocase; classtype:trojan-activity; sid:100002418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.41",nocase; classtype:trojan-activity; sid:100002419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.42",nocase; classtype:trojan-activity; sid:100002420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.15.212",nocase; classtype:trojan-activity; sid:100002421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.20.14",nocase; classtype:trojan-activity; sid:100002422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.141.117.41",nocase; classtype:trojan-activity; sid:100002423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.147.16.184",nocase; classtype:trojan-activity; sid:100002424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.159.240.9",nocase; classtype:trojan-activity; sid:100002425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.187.55.150",nocase; classtype:trojan-activity; sid:100002426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.210.214.130",nocase; classtype:trojan-activity; sid:100002427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.177.39",nocase; classtype:trojan-activity; sid:100002428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.226.63",nocase; classtype:trojan-activity; sid:100002429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.49.207",nocase; classtype:trojan-activity; sid:100002430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.214.24.194",nocase; classtype:trojan-activity; sid:100002431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.216.140.123",nocase; classtype:trojan-activity; sid:100002432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.35.225.36",nocase; classtype:trojan-activity; sid:100002433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.65.206.162",nocase; classtype:trojan-activity; sid:100002434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.92.4.231",nocase; classtype:trojan-activity; sid:100002435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.135",nocase; classtype:trojan-activity; sid:100002436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.200",nocase; classtype:trojan-activity; sid:100002437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.41.33",nocase; classtype:trojan-activity; sid:100002438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"191.255.248.220",nocase; classtype:trojan-activity; sid:100002439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.175.130",nocase; classtype:trojan-activity; sid:100002440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.241.200",nocase; classtype:trojan-activity; sid:100002441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.185.106",nocase; classtype:trojan-activity; sid:100002442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.209.27",nocase; classtype:trojan-activity; sid:100002443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.220.55",nocase; classtype:trojan-activity; sid:100002444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.228.67",nocase; classtype:trojan-activity; sid:100002445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.3.152.166",nocase; classtype:trojan-activity; sid:100002446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.3.73.205",nocase; classtype:trojan-activity; sid:100002447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.99.240.77",nocase; classtype:trojan-activity; sid:100002448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.142.146.25",nocase; classtype:trojan-activity; sid:100002449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.228.135.144",nocase; classtype:trojan-activity; sid:100002450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.91.131.237",nocase; classtype:trojan-activity; sid:100002451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.147.142.230",nocase; classtype:trojan-activity; sid:100002452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.15.36.167",nocase; classtype:trojan-activity; sid:100002453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.152.35.139",nocase; classtype:trojan-activity; sid:100002454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.38.20.199",nocase; classtype:trojan-activity; sid:100002455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.139.126.51",nocase; classtype:trojan-activity; sid:100002456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.228.231.218",nocase; classtype:trojan-activity; sid:100002457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.24.94.187",nocase; classtype:trojan-activity; sid:100002458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.202.26.182",nocase; classtype:trojan-activity; sid:100002459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.218.48.82",nocase; classtype:trojan-activity; sid:100002460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.148.90",nocase; classtype:trojan-activity; sid:100002461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.166.203",nocase; classtype:trojan-activity; sid:100002462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.159.2.106",nocase; classtype:trojan-activity; sid:100002463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.50.27.115",nocase; classtype:trojan-activity; sid:100002464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.133.218",nocase; classtype:trojan-activity; sid:100002465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.207.121",nocase; classtype:trojan-activity; sid:100002466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.213.57",nocase; classtype:trojan-activity; sid:100002467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.251.105",nocase; classtype:trojan-activity; sid:100002468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.251.72.110",nocase; classtype:trojan-activity; sid:100002469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.201.76",nocase; classtype:trojan-activity; sid:100002470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.202.7",nocase; classtype:trojan-activity; sid:100002471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"199.188.101.109",nocase; classtype:trojan-activity; sid:100002472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1am.co.nz",nocase; classtype:trojan-activity; sid:100002473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.229.89.119",nocase; classtype:trojan-activity; sid:100002474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.249.161.188",nocase; classtype:trojan-activity; sid:100002475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.111.158",nocase; classtype:trojan-activity; sid:100002476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.4.24",nocase; classtype:trojan-activity; sid:100002477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.125.182",nocase; classtype:trojan-activity; sid:100002478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.83.152.16",nocase; classtype:trojan-activity; sid:100002479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"20.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.105.167.98",nocase; classtype:trojan-activity; sid:100002481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.111.189.70",nocase; classtype:trojan-activity; sid:100002482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.194.4.24",nocase; classtype:trojan-activity; sid:100002483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.2.161.171",nocase; classtype:trojan-activity; sid:100002484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.30.132.50",nocase; classtype:trojan-activity; sid:100002485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.142.147.89",nocase; classtype:trojan-activity; sid:100002486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.163.170",nocase; classtype:trojan-activity; sid:100002487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.248.190",nocase; classtype:trojan-activity; sid:100002488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.187.102.73",nocase; classtype:trojan-activity; sid:100002489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.200.254.86",nocase; classtype:trojan-activity; sid:100002490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.203.221.20",nocase; classtype:trojan-activity; sid:100002491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.215.84.97",nocase; classtype:trojan-activity; sid:100002492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.218.97.142",nocase; classtype:trojan-activity; sid:100002493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.107.233.41",nocase; classtype:trojan-activity; sid:100002494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.164.153.80",nocase; classtype:trojan-activity; sid:100002495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.166.217.54",nocase; classtype:trojan-activity; sid:100002496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.22",nocase; classtype:trojan-activity; sid:100002497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.37",nocase; classtype:trojan-activity; sid:100002498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.47",nocase; classtype:trojan-activity; sid:100002499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.52",nocase; classtype:trojan-activity; sid:100002500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.55",nocase; classtype:trojan-activity; sid:100002501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.9",nocase; classtype:trojan-activity; sid:100002502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.29.95.12",nocase; classtype:trojan-activity; sid:100002503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.4.124.58",nocase; classtype:trojan-activity; sid:100002504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.176.114",nocase; classtype:trojan-activity; sid:100002505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.191.174",nocase; classtype:trojan-activity; sid:100002506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.74.236.9",nocase; classtype:trojan-activity; sid:100002507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.109.201.243",nocase; classtype:trojan-activity; sid:100002508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.130.69.205",nocase; classtype:trojan-activity; sid:100002509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.170.115.82",nocase; classtype:trojan-activity; sid:100002510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.189.156.107",nocase; classtype:trojan-activity; sid:100002511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.204.232.18",nocase; classtype:trojan-activity; sid:100002512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.229.21.56",nocase; classtype:trojan-activity; sid:100002513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.236.190.28",nocase; classtype:trojan-activity; sid:100002514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.238.86.202",nocase; classtype:trojan-activity; sid:100002515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.70.166.107",nocase; classtype:trojan-activity; sid:100002516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.77.80.159",nocase; classtype:trojan-activity; sid:100002517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.119.166",nocase; classtype:trojan-activity; sid:100002518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.171.138",nocase; classtype:trojan-activity; sid:100002519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.82.36.34",nocase; classtype:trojan-activity; sid:100002520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.82.49.122",nocase; classtype:trojan-activity; sid:100002521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.93.6.28",nocase; classtype:trojan-activity; sid:100002522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"204.195.116.171",nocase; classtype:trojan-activity; sid:100002523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"205.185.115.74",nocase; classtype:trojan-activity; sid:100002524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"205.185.123.217",nocase; classtype:trojan-activity; sid:100002525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.248.137.132",nocase; classtype:trojan-activity; sid:100002526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.47.41.166",nocase; classtype:trojan-activity; sid:100002527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.5.32.6",nocase; classtype:trojan-activity; sid:100002528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.163.58.18",nocase; classtype:trojan-activity; sid:100002529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.39.50",nocase; classtype:trojan-activity; sid:100002530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.190",nocase; classtype:trojan-activity; sid:100002531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.31",nocase; classtype:trojan-activity; sid:100002532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.145.60.38",nocase; classtype:trojan-activity; sid:100002533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.124.149.19",nocase; classtype:trojan-activity; sid:100002534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.152.122",nocase; classtype:trojan-activity; sid:100002535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.153.142",nocase; classtype:trojan-activity; sid:100002536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.234.93",nocase; classtype:trojan-activity; sid:100002537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.237.70",nocase; classtype:trojan-activity; sid:100002538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.245.109",nocase; classtype:trojan-activity; sid:100002539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.68.242.114",nocase; classtype:trojan-activity; sid:100002540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.96.116.236",nocase; classtype:trojan-activity; sid:100002541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.116.220.37",nocase; classtype:trojan-activity; sid:100002542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.172.11.169",nocase; classtype:trojan-activity; sid:100002543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.179.43.109",nocase; classtype:trojan-activity; sid:100002544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.132.204",nocase; classtype:trojan-activity; sid:100002545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.75.220",nocase; classtype:trojan-activity; sid:100002546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.204.215.157",nocase; classtype:trojan-activity; sid:100002547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.66.179",nocase; classtype:trojan-activity; sid:100002548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.93.93",nocase; classtype:trojan-activity; sid:100002549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.216.66.105",nocase; classtype:trojan-activity; sid:100002550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.114.96",nocase; classtype:trojan-activity; sid:100002551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.120.13",nocase; classtype:trojan-activity; sid:100002552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.246.137",nocase; classtype:trojan-activity; sid:100002553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.238.83.238",nocase; classtype:trojan-activity; sid:100002554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.113.49",nocase; classtype:trojan-activity; sid:100002555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.5.96",nocase; classtype:trojan-activity; sid:100002556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.36.174.137",nocase; classtype:trojan-activity; sid:100002557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.51.174.149",nocase; classtype:trojan-activity; sid:100002558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.122.86.105",nocase; classtype:trojan-activity; sid:100002559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.143.227.22",nocase; classtype:trojan-activity; sid:100002560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.156.215.178",nocase; classtype:trojan-activity; sid:100002561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.46.197.114",nocase; classtype:trojan-activity; sid:100002562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.56.197.230",nocase; classtype:trojan-activity; sid:100002563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.119.74.202",nocase; classtype:trojan-activity; sid:100002564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.123.206.197",nocase; classtype:trojan-activity; sid:100002565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.135.178.253",nocase; classtype:trojan-activity; sid:100002566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.14.173.117",nocase; classtype:trojan-activity; sid:100002567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.182.113",nocase; classtype:trojan-activity; sid:100002568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.190.193",nocase; classtype:trojan-activity; sid:100002569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.12",nocase; classtype:trojan-activity; sid:100002570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.138",nocase; classtype:trojan-activity; sid:100002571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.160",nocase; classtype:trojan-activity; sid:100002572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.99",nocase; classtype:trojan-activity; sid:100002573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.135",nocase; classtype:trojan-activity; sid:100002574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.225",nocase; classtype:trojan-activity; sid:100002575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.23",nocase; classtype:trojan-activity; sid:100002576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.237",nocase; classtype:trojan-activity; sid:100002577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.51",nocase; classtype:trojan-activity; sid:100002578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.155",nocase; classtype:trojan-activity; sid:100002579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.191",nocase; classtype:trojan-activity; sid:100002580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.80",nocase; classtype:trojan-activity; sid:100002581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.1",nocase; classtype:trojan-activity; sid:100002582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.11",nocase; classtype:trojan-activity; sid:100002583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.26",nocase; classtype:trojan-activity; sid:100002584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.33",nocase; classtype:trojan-activity; sid:100002585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.71",nocase; classtype:trojan-activity; sid:100002586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.132",nocase; classtype:trojan-activity; sid:100002587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.192",nocase; classtype:trojan-activity; sid:100002588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.203",nocase; classtype:trojan-activity; sid:100002589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.33",nocase; classtype:trojan-activity; sid:100002590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.85",nocase; classtype:trojan-activity; sid:100002591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.117.122",nocase; classtype:trojan-activity; sid:100002592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.117.151",nocase; classtype:trojan-activity; sid:100002593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.117.97",nocase; classtype:trojan-activity; sid:100002594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.129",nocase; classtype:trojan-activity; sid:100002595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.144",nocase; classtype:trojan-activity; sid:100002596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.238",nocase; classtype:trojan-activity; sid:100002597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.65",nocase; classtype:trojan-activity; sid:100002598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.119.24",nocase; classtype:trojan-activity; sid:100002599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.119.240",nocase; classtype:trojan-activity; sid:100002600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.104",nocase; classtype:trojan-activity; sid:100002601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.20",nocase; classtype:trojan-activity; sid:100002602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.243",nocase; classtype:trojan-activity; sid:100002603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.60",nocase; classtype:trojan-activity; sid:100002604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.7",nocase; classtype:trojan-activity; sid:100002605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.84",nocase; classtype:trojan-activity; sid:100002606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.204",nocase; classtype:trojan-activity; sid:100002607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.217",nocase; classtype:trojan-activity; sid:100002608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.46",nocase; classtype:trojan-activity; sid:100002609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.189.178.163",nocase; classtype:trojan-activity; sid:100002610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.226.140.23",nocase; classtype:trojan-activity; sid:100002611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.240.218.15",nocase; classtype:trojan-activity; sid:100002612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.249.156.189",nocase; classtype:trojan-activity; sid:100002613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.27.8.6",nocase; classtype:trojan-activity; sid:100002614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.80.44.17",nocase; classtype:trojan-activity; sid:100002615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.87.87.173",nocase; classtype:trojan-activity; sid:100002616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.254.52",nocase; classtype:trojan-activity; sid:100002617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.36",nocase; classtype:trojan-activity; sid:100002618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.84",nocase; classtype:trojan-activity; sid:100002619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.127.185.150",nocase; classtype:trojan-activity; sid:100002620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.170.240.98",nocase; classtype:trojan-activity; sid:100002621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.183.54.169",nocase; classtype:trojan-activity; sid:100002622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.36.12.98",nocase; classtype:trojan-activity; sid:100002623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.11.75.162",nocase; classtype:trojan-activity; sid:100002624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.127.133.214",nocase; classtype:trojan-activity; sid:100002625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.8.228.92",nocase; classtype:trojan-activity; sid:100002626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.12.162.39",nocase; classtype:trojan-activity; sid:100002627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.12.181.110",nocase; classtype:trojan-activity; sid:100002628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.2.40.34",nocase; classtype:trojan-activity; sid:100002629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.215.243.65",nocase; classtype:trojan-activity; sid:100002630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.238.246.3",nocase; classtype:trojan-activity; sid:100002631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.28.160.174",nocase; classtype:trojan-activity; sid:100002632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.207.119",nocase; classtype:trojan-activity; sid:100002633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.227.133",nocase; classtype:trojan-activity; sid:100002634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.68.35",nocase; classtype:trojan-activity; sid:100002635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.81.81",nocase; classtype:trojan-activity; sid:100002636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.48.135.50",nocase; classtype:trojan-activity; sid:100002637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.56.93.129",nocase; classtype:trojan-activity; sid:100002638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.57.53.55",nocase; classtype:trojan-activity; sid:100002639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.59.116.203",nocase; classtype:trojan-activity; sid:100002640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.72.198.15",nocase; classtype:trojan-activity; sid:100002641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.79.103.159",nocase; classtype:trojan-activity; sid:100002642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.63",nocase; classtype:trojan-activity; sid:100002643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.75",nocase; classtype:trojan-activity; sid:100002644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.103.40",nocase; classtype:trojan-activity; sid:100002645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.114.132",nocase; classtype:trojan-activity; sid:100002646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.114.45",nocase; classtype:trojan-activity; sid:100002647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.115.250",nocase; classtype:trojan-activity; sid:100002648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.126.205",nocase; classtype:trojan-activity; sid:100002649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.147.58",nocase; classtype:trojan-activity; sid:100002650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.148.116",nocase; classtype:trojan-activity; sid:100002651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.173.163",nocase; classtype:trojan-activity; sid:100002652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.102.14",nocase; classtype:trojan-activity; sid:100002653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.113.58",nocase; classtype:trojan-activity; sid:100002654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.14.17",nocase; classtype:trojan-activity; sid:100002655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.170.22",nocase; classtype:trojan-activity; sid:100002656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.24.246",nocase; classtype:trojan-activity; sid:100002657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.243.184",nocase; classtype:trojan-activity; sid:100002658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.26.204",nocase; classtype:trojan-activity; sid:100002659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.26.37",nocase; classtype:trojan-activity; sid:100002660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.29.165",nocase; classtype:trojan-activity; sid:100002661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.31.15",nocase; classtype:trojan-activity; sid:100002662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.31.67",nocase; classtype:trojan-activity; sid:100002663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.42.216",nocase; classtype:trojan-activity; sid:100002664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.98.64",nocase; classtype:trojan-activity; sid:100002665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.131.116",nocase; classtype:trojan-activity; sid:100002666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.167.103",nocase; classtype:trojan-activity; sid:100002667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.17.217",nocase; classtype:trojan-activity; sid:100002668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.23.29",nocase; classtype:trojan-activity; sid:100002669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.60.224",nocase; classtype:trojan-activity; sid:100002670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.88.219",nocase; classtype:trojan-activity; sid:100002671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.9.32",nocase; classtype:trojan-activity; sid:100002672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.11.39",nocase; classtype:trojan-activity; sid:100002673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.146.200",nocase; classtype:trojan-activity; sid:100002674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.147.87",nocase; classtype:trojan-activity; sid:100002675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.150.91",nocase; classtype:trojan-activity; sid:100002676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.178.201",nocase; classtype:trojan-activity; sid:100002677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.178.210",nocase; classtype:trojan-activity; sid:100002678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.183.29",nocase; classtype:trojan-activity; sid:100002679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.223.241",nocase; classtype:trojan-activity; sid:100002680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.223.245",nocase; classtype:trojan-activity; sid:100002681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.42.228",nocase; classtype:trojan-activity; sid:100002682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.67.171",nocase; classtype:trojan-activity; sid:100002683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.241.6.180",nocase; classtype:trojan-activity; sid:100002684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.148",nocase; classtype:trojan-activity; sid:100002685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.84",nocase; classtype:trojan-activity; sid:100002686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.163.7",nocase; classtype:trojan-activity; sid:100002687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.171.144",nocase; classtype:trojan-activity; sid:100002688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.251.32",nocase; classtype:trojan-activity; sid:100002689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.5.140",nocase; classtype:trojan-activity; sid:100002690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.69.71.186",nocase; classtype:trojan-activity; sid:100002691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.80.217.209",nocase; classtype:trojan-activity; sid:100002692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.85.145.194",nocase; classtype:trojan-activity; sid:100002693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"21robo.com",nocase; classtype:trojan-activity; sid:100002694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.118.168.155",nocase; classtype:trojan-activity; sid:100002695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.126.237.74",nocase; classtype:trojan-activity; sid:100002696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.133.30.200",nocase; classtype:trojan-activity; sid:100002697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.200.22.163",nocase; classtype:trojan-activity; sid:100002698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.71.239.115",nocase; classtype:trojan-activity; sid:100002699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.1.162.82",nocase; classtype:trojan-activity; sid:100002700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.124.78.15",nocase; classtype:trojan-activity; sid:100002701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.11.33",nocase; classtype:trojan-activity; sid:100002702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.122.127",nocase; classtype:trojan-activity; sid:100002703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.165.237",nocase; classtype:trojan-activity; sid:100002704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.47.162",nocase; classtype:trojan-activity; sid:100002705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.58.5",nocase; classtype:trojan-activity; sid:100002706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.108.55",nocase; classtype:trojan-activity; sid:100002707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.125.190",nocase; classtype:trojan-activity; sid:100002708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.127.124",nocase; classtype:trojan-activity; sid:100002709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.147.220",nocase; classtype:trojan-activity; sid:100002710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.21.133",nocase; classtype:trojan-activity; sid:100002711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.212.123",nocase; classtype:trojan-activity; sid:100002712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.234.159",nocase; classtype:trojan-activity; sid:100002713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.236.211",nocase; classtype:trojan-activity; sid:100002714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.237.107",nocase; classtype:trojan-activity; sid:100002715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.250.213",nocase; classtype:trojan-activity; sid:100002716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.253.236",nocase; classtype:trojan-activity; sid:100002717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.54.237",nocase; classtype:trojan-activity; sid:100002718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.55.56",nocase; classtype:trojan-activity; sid:100002719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.157.191.178",nocase; classtype:trojan-activity; sid:100002720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.136.213",nocase; classtype:trojan-activity; sid:100002721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.104",nocase; classtype:trojan-activity; sid:100002722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.107",nocase; classtype:trojan-activity; sid:100002723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.224",nocase; classtype:trojan-activity; sid:100002724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.196.12.96",nocase; classtype:trojan-activity; sid:100002725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.198.167.192",nocase; classtype:trojan-activity; sid:100002726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.2.190.22",nocase; classtype:trojan-activity; sid:100002727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.130.147",nocase; classtype:trojan-activity; sid:100002728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.224.184",nocase; classtype:trojan-activity; sid:100002729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.116.167",nocase; classtype:trojan-activity; sid:100002730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.172.207",nocase; classtype:trojan-activity; sid:100002731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.184.31",nocase; classtype:trojan-activity; sid:100002732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.237.220",nocase; classtype:trojan-activity; sid:100002733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.252.64",nocase; classtype:trojan-activity; sid:100002734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.8.64",nocase; classtype:trojan-activity; sid:100002735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.1.82",nocase; classtype:trojan-activity; sid:100002736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.179.70",nocase; classtype:trojan-activity; sid:100002737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.137.36",nocase; classtype:trojan-activity; sid:100002738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.142.206",nocase; classtype:trojan-activity; sid:100002739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.112.125",nocase; classtype:trojan-activity; sid:100002740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.32.88",nocase; classtype:trojan-activity; sid:100002741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.34.43",nocase; classtype:trojan-activity; sid:100002742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.43.223",nocase; classtype:trojan-activity; sid:100002743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.68.16",nocase; classtype:trojan-activity; sid:100002744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.108.17.64",nocase; classtype:trojan-activity; sid:100002745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.119.65.145",nocase; classtype:trojan-activity; sid:100002746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.132.125.138",nocase; classtype:trojan-activity; sid:100002747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.102.202",nocase; classtype:trojan-activity; sid:100002748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.103.120",nocase; classtype:trojan-activity; sid:100002749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.105.87",nocase; classtype:trojan-activity; sid:100002750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.219.29",nocase; classtype:trojan-activity; sid:100002751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.26.161",nocase; classtype:trojan-activity; sid:100002752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.67.115",nocase; classtype:trojan-activity; sid:100002753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.136.49.252",nocase; classtype:trojan-activity; sid:100002754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.136.53.227",nocase; classtype:trojan-activity; sid:100002755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.101.251",nocase; classtype:trojan-activity; sid:100002756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.101.33",nocase; classtype:trojan-activity; sid:100002757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.121.127",nocase; classtype:trojan-activity; sid:100002758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.137.5",nocase; classtype:trojan-activity; sid:100002759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.138.252",nocase; classtype:trojan-activity; sid:100002760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.148.192",nocase; classtype:trojan-activity; sid:100002761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.160.202",nocase; classtype:trojan-activity; sid:100002762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.172.250",nocase; classtype:trojan-activity; sid:100002763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.198.247",nocase; classtype:trojan-activity; sid:100002764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.239.124",nocase; classtype:trojan-activity; sid:100002765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.49.36",nocase; classtype:trojan-activity; sid:100002766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.5.150",nocase; classtype:trojan-activity; sid:100002767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.57.234",nocase; classtype:trojan-activity; sid:100002768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.72.146",nocase; classtype:trojan-activity; sid:100002769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.85.26",nocase; classtype:trojan-activity; sid:100002770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.96.9",nocase; classtype:trojan-activity; sid:100002771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.143.84",nocase; classtype:trojan-activity; sid:100002772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.151.100",nocase; classtype:trojan-activity; sid:100002773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.189.138",nocase; classtype:trojan-activity; sid:100002774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.201.241",nocase; classtype:trojan-activity; sid:100002775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.23.254",nocase; classtype:trojan-activity; sid:100002776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.96.79",nocase; classtype:trojan-activity; sid:100002777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.139.16.229",nocase; classtype:trojan-activity; sid:100002778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.129.239",nocase; classtype:trojan-activity; sid:100002779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.162.140",nocase; classtype:trojan-activity; sid:100002780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.163.112",nocase; classtype:trojan-activity; sid:100002781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.17.245",nocase; classtype:trojan-activity; sid:100002782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.209.222",nocase; classtype:trojan-activity; sid:100002783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.254.11",nocase; classtype:trojan-activity; sid:100002784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.39.66",nocase; classtype:trojan-activity; sid:100002785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.120.26",nocase; classtype:trojan-activity; sid:100002786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.13.77",nocase; classtype:trojan-activity; sid:100002787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.44.36",nocase; classtype:trojan-activity; sid:100002788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.73.249",nocase; classtype:trojan-activity; sid:100002789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.9.0",nocase; classtype:trojan-activity; sid:100002790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.162.164",nocase; classtype:trojan-activity; sid:100002791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.192.66",nocase; classtype:trojan-activity; sid:100002792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.209.231",nocase; classtype:trojan-activity; sid:100002793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.209.7",nocase; classtype:trojan-activity; sid:100002794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.245.207",nocase; classtype:trojan-activity; sid:100002795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.179.215.189",nocase; classtype:trojan-activity; sid:100002796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.185.116.233",nocase; classtype:trojan-activity; sid:100002797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.186.20.19",nocase; classtype:trojan-activity; sid:100002798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.187.184.136",nocase; classtype:trojan-activity; sid:100002799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.187.9.178",nocase; classtype:trojan-activity; sid:100002800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.211.72.66",nocase; classtype:trojan-activity; sid:100002801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.214.54.208",nocase; classtype:trojan-activity; sid:100002802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.218.220.219",nocase; classtype:trojan-activity; sid:100002803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.236.85.220",nocase; classtype:trojan-activity; sid:100002804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.238.230.7",nocase; classtype:trojan-activity; sid:100002805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.239.83.232",nocase; classtype:trojan-activity; sid:100002806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.248.64.253",nocase; classtype:trojan-activity; sid:100002807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.83.150.240",nocase; classtype:trojan-activity; sid:100002808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.92.9.126",nocase; classtype:trojan-activity; sid:100002809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.99.171.192",nocase; classtype:trojan-activity; sid:100002810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.166.117.210",nocase; classtype:trojan-activity; sid:100002811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.167.118.17",nocase; classtype:trojan-activity; sid:100002812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.225.68",nocase; classtype:trojan-activity; sid:100002813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.234.84",nocase; classtype:trojan-activity; sid:100002814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.5.29",nocase; classtype:trojan-activity; sid:100002815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.73.175",nocase; classtype:trojan-activity; sid:100002816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.125.186.135",nocase; classtype:trojan-activity; sid:100002817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.126.120.25",nocase; classtype:trojan-activity; sid:100002818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.228.143.58",nocase; classtype:trojan-activity; sid:100002819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.24.213.121",nocase; classtype:trojan-activity; sid:100002820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.149.13",nocase; classtype:trojan-activity; sid:100002821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.21.167",nocase; classtype:trojan-activity; sid:100002822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.95.89.21",nocase; classtype:trojan-activity; sid:100002823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.103.74.180",nocase; classtype:trojan-activity; sid:100002824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.11.141.134",nocase; classtype:trojan-activity; sid:100002825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.119.158.74",nocase; classtype:trojan-activity; sid:100002826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.137.147.95",nocase; classtype:trojan-activity; sid:100002827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.152.235.88",nocase; classtype:trojan-activity; sid:100002828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.158.25.98",nocase; classtype:trojan-activity; sid:100002829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.176.206.12",nocase; classtype:trojan-activity; sid:100002830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.184.1.41",nocase; classtype:trojan-activity; sid:100002831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.192.191.109",nocase; classtype:trojan-activity; sid:100002832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.225.114.161",nocase; classtype:trojan-activity; sid:100002833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.227.190.78",nocase; classtype:trojan-activity; sid:100002834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.35.245.52",nocase; classtype:trojan-activity; sid:100002835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.181.18",nocase; classtype:trojan-activity; sid:100002836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.34.242",nocase; classtype:trojan-activity; sid:100002837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.42.229.143",nocase; classtype:trojan-activity; sid:100002838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.45.4.1",nocase; classtype:trojan-activity; sid:100002839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.51.91.113",nocase; classtype:trojan-activity; sid:100002840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.10",nocase; classtype:trojan-activity; sid:100002841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.9",nocase; classtype:trojan-activity; sid:100002842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.16",nocase; classtype:trojan-activity; sid:100002844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.7",nocase; classtype:trojan-activity; sid:100002845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.106.201",nocase; classtype:trojan-activity; sid:100002846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.152.107",nocase; classtype:trojan-activity; sid:100002847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.116.84.57",nocase; classtype:trojan-activity; sid:100002848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.12.245.238",nocase; classtype:trojan-activity; sid:100002849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.141.218.17",nocase; classtype:trojan-activity; sid:100002850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.29.52",nocase; classtype:trojan-activity; sid:100002851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.40.128",nocase; classtype:trojan-activity; sid:100002852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.153.207.1",nocase; classtype:trojan-activity; sid:100002853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.184.244.14",nocase; classtype:trojan-activity; sid:100002854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.184.54.199",nocase; classtype:trojan-activity; sid:100002855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.187.248.22",nocase; classtype:trojan-activity; sid:100002856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.187.250.192",nocase; classtype:trojan-activity; sid:100002857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.196.190",nocase; classtype:trojan-activity; sid:100002858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.217.210",nocase; classtype:trojan-activity; sid:100002859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.149.142",nocase; classtype:trojan-activity; sid:100002860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.158.229",nocase; classtype:trojan-activity; sid:100002861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.192.66",nocase; classtype:trojan-activity; sid:100002862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.210.20",nocase; classtype:trojan-activity; sid:100002863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.17.88",nocase; classtype:trojan-activity; sid:100002864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.22.217",nocase; classtype:trojan-activity; sid:100002865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.23.215",nocase; classtype:trojan-activity; sid:100002866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.24.175",nocase; classtype:trojan-activity; sid:100002867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.28.84",nocase; classtype:trojan-activity; sid:100002868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.148.189",nocase; classtype:trojan-activity; sid:100002869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.232.65",nocase; classtype:trojan-activity; sid:100002870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.3.194",nocase; classtype:trojan-activity; sid:100002871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.34.48",nocase; classtype:trojan-activity; sid:100002872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.110.211",nocase; classtype:trojan-activity; sid:100002873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.140.229",nocase; classtype:trojan-activity; sid:100002874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.2.163",nocase; classtype:trojan-activity; sid:100002875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.23.62",nocase; classtype:trojan-activity; sid:100002876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.32.146",nocase; classtype:trojan-activity; sid:100002877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.201.183.149",nocase; classtype:trojan-activity; sid:100002878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.182.201",nocase; classtype:trojan-activity; sid:100002879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.66.46",nocase; classtype:trojan-activity; sid:100002880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.102.12",nocase; classtype:trojan-activity; sid:100002881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.126.194",nocase; classtype:trojan-activity; sid:100002882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.154.105",nocase; classtype:trojan-activity; sid:100002883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.165.138",nocase; classtype:trojan-activity; sid:100002884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.175.203",nocase; classtype:trojan-activity; sid:100002885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.185.42",nocase; classtype:trojan-activity; sid:100002886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.185.48",nocase; classtype:trojan-activity; sid:100002887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.213.79",nocase; classtype:trojan-activity; sid:100002888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.246.96",nocase; classtype:trojan-activity; sid:100002889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.255.42",nocase; classtype:trojan-activity; sid:100002890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.28.115",nocase; classtype:trojan-activity; sid:100002891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.4.188",nocase; classtype:trojan-activity; sid:100002892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.54.217",nocase; classtype:trojan-activity; sid:100002893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.68.144",nocase; classtype:trojan-activity; sid:100002894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.87.75",nocase; classtype:trojan-activity; sid:100002895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.94.134",nocase; classtype:trojan-activity; sid:100002896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.204.253.74",nocase; classtype:trojan-activity; sid:100002897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.205.178.110",nocase; classtype:trojan-activity; sid:100002898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.136.101",nocase; classtype:trojan-activity; sid:100002899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.148.106",nocase; classtype:trojan-activity; sid:100002900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.154.122",nocase; classtype:trojan-activity; sid:100002901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.26.218",nocase; classtype:trojan-activity; sid:100002902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.80.209",nocase; classtype:trojan-activity; sid:100002903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.81.66",nocase; classtype:trojan-activity; sid:100002904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.83.48",nocase; classtype:trojan-activity; sid:100002905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.97.81",nocase; classtype:trojan-activity; sid:100002906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.151.126",nocase; classtype:trojan-activity; sid:100002907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.155.31",nocase; classtype:trojan-activity; sid:100002908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.170.203",nocase; classtype:trojan-activity; sid:100002909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.54.91",nocase; classtype:trojan-activity; sid:100002910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.144.57",nocase; classtype:trojan-activity; sid:100002911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.152.10",nocase; classtype:trojan-activity; sid:100002912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.160.177",nocase; classtype:trojan-activity; sid:100002913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.164.18",nocase; classtype:trojan-activity; sid:100002914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.166.13",nocase; classtype:trojan-activity; sid:100002915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.201.212",nocase; classtype:trojan-activity; sid:100002916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.214.139",nocase; classtype:trojan-activity; sid:100002917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.247.130",nocase; classtype:trojan-activity; sid:100002918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.25.59",nocase; classtype:trojan-activity; sid:100002919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.34.2",nocase; classtype:trojan-activity; sid:100002920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.46.167",nocase; classtype:trojan-activity; sid:100002921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.92.64",nocase; classtype:trojan-activity; sid:100002922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.160.222",nocase; classtype:trojan-activity; sid:100002923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.231.15",nocase; classtype:trojan-activity; sid:100002924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.60.21",nocase; classtype:trojan-activity; sid:100002925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.107.125",nocase; classtype:trojan-activity; sid:100002926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.127.11",nocase; classtype:trojan-activity; sid:100002927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.172.245",nocase; classtype:trojan-activity; sid:100002928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.234.28",nocase; classtype:trojan-activity; sid:100002929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.236.134",nocase; classtype:trojan-activity; sid:100002930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.63.243",nocase; classtype:trojan-activity; sid:100002931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.211.251.162",nocase; classtype:trojan-activity; sid:100002932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.104.201",nocase; classtype:trojan-activity; sid:100002933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.109.105",nocase; classtype:trojan-activity; sid:100002934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.109.58",nocase; classtype:trojan-activity; sid:100002935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.145.221",nocase; classtype:trojan-activity; sid:100002936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.167.175",nocase; classtype:trojan-activity; sid:100002937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.175.208",nocase; classtype:trojan-activity; sid:100002938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.220.5",nocase; classtype:trojan-activity; sid:100002939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.255.202",nocase; classtype:trojan-activity; sid:100002940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.255.6",nocase; classtype:trojan-activity; sid:100002941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.84.74",nocase; classtype:trojan-activity; sid:100002942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.214.37.129",nocase; classtype:trojan-activity; sid:100002943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.139.242",nocase; classtype:trojan-activity; sid:100002944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.190.172",nocase; classtype:trojan-activity; sid:100002945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.212.209",nocase; classtype:trojan-activity; sid:100002946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.212.80",nocase; classtype:trojan-activity; sid:100002947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.253.149",nocase; classtype:trojan-activity; sid:100002948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.34.242",nocase; classtype:trojan-activity; sid:100002949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.38.119",nocase; classtype:trojan-activity; sid:100002950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.38.166",nocase; classtype:trojan-activity; sid:100002951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.71.243",nocase; classtype:trojan-activity; sid:100002952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.98.242",nocase; classtype:trojan-activity; sid:100002953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.131.66",nocase; classtype:trojan-activity; sid:100002954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.144.66",nocase; classtype:trojan-activity; sid:100002955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.193.217",nocase; classtype:trojan-activity; sid:100002956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.197.193",nocase; classtype:trojan-activity; sid:100002957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.223.246",nocase; classtype:trojan-activity; sid:100002958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.225.28",nocase; classtype:trojan-activity; sid:100002959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.227.95",nocase; classtype:trojan-activity; sid:100002960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.234.98",nocase; classtype:trojan-activity; sid:100002961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.46.85",nocase; classtype:trojan-activity; sid:100002962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.58.120",nocase; classtype:trojan-activity; sid:100002963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.95.56",nocase; classtype:trojan-activity; sid:100002964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.120.226",nocase; classtype:trojan-activity; sid:100002965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.133.53",nocase; classtype:trojan-activity; sid:100002966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.191.58",nocase; classtype:trojan-activity; sid:100002967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.76.48",nocase; classtype:trojan-activity; sid:100002968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.180.172",nocase; classtype:trojan-activity; sid:100002969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.219.228",nocase; classtype:trojan-activity; sid:100002970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.240.158",nocase; classtype:trojan-activity; sid:100002971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.248.121",nocase; classtype:trojan-activity; sid:100002972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.119.149",nocase; classtype:trojan-activity; sid:100002973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.132.71",nocase; classtype:trojan-activity; sid:100002974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.151.83",nocase; classtype:trojan-activity; sid:100002975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.160.112",nocase; classtype:trojan-activity; sid:100002976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.172.175",nocase; classtype:trojan-activity; sid:100002977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.173.180",nocase; classtype:trojan-activity; sid:100002978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.176.72",nocase; classtype:trojan-activity; sid:100002979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.184.94",nocase; classtype:trojan-activity; sid:100002980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.192.223",nocase; classtype:trojan-activity; sid:100002981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.83.244",nocase; classtype:trojan-activity; sid:100002982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.40.189",nocase; classtype:trojan-activity; sid:100002983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.80.93",nocase; classtype:trojan-activity; sid:100002984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.85.168",nocase; classtype:trojan-activity; sid:100002985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.221.239.223",nocase; classtype:trojan-activity; sid:100002986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.241.223",nocase; classtype:trojan-activity; sid:100002987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.249.210",nocase; classtype:trojan-activity; sid:100002988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.42.189",nocase; classtype:trojan-activity; sid:100002989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.50.170",nocase; classtype:trojan-activity; sid:100002990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.223.242.164",nocase; classtype:trojan-activity; sid:100002991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.24.28.134",nocase; classtype:trojan-activity; sid:100002992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.107.66",nocase; classtype:trojan-activity; sid:100002993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.129.198",nocase; classtype:trojan-activity; sid:100002994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.154.13",nocase; classtype:trojan-activity; sid:100002995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.212.124",nocase; classtype:trojan-activity; sid:100002996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.58.5",nocase; classtype:trojan-activity; sid:100002997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.143.46",nocase; classtype:trojan-activity; sid:100002998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.9.44",nocase; classtype:trojan-activity; sid:100002999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.44.130",nocase; classtype:trojan-activity; sid:100003000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.44.161",nocase; classtype:trojan-activity; sid:100003001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.46.100",nocase; classtype:trojan-activity; sid:100003002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.46.252",nocase; classtype:trojan-activity; sid:100003003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.23.215",nocase; classtype:trojan-activity; sid:100003004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.34.254",nocase; classtype:trojan-activity; sid:100003005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.46.18",nocase; classtype:trojan-activity; sid:100003006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.6.195.65",nocase; classtype:trojan-activity; sid:100003007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.6.240.125",nocase; classtype:trojan-activity; sid:100003008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.6.242.65",nocase; classtype:trojan-activity; sid:100003009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.0.98.131",nocase; classtype:trojan-activity; sid:100003010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.11.51.57",nocase; classtype:trojan-activity; sid:100003011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.13.23.180",nocase; classtype:trojan-activity; sid:100003012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.154.234.3",nocase; classtype:trojan-activity; sid:100003013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.163.191.11",nocase; classtype:trojan-activity; sid:100003014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.179.83",nocase; classtype:trojan-activity; sid:100003015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.184.59",nocase; classtype:trojan-activity; sid:100003016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.191.243",nocase; classtype:trojan-activity; sid:100003017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.194.67",nocase; classtype:trojan-activity; sid:100003018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.216.132",nocase; classtype:trojan-activity; sid:100003019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.219.28",nocase; classtype:trojan-activity; sid:100003020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.24.115",nocase; classtype:trojan-activity; sid:100003021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.30.65",nocase; classtype:trojan-activity; sid:100003022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.60.234",nocase; classtype:trojan-activity; sid:100003023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.63.203",nocase; classtype:trojan-activity; sid:100003024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.65.233",nocase; classtype:trojan-activity; sid:100003025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.94.16",nocase; classtype:trojan-activity; sid:100003026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.179.201.26",nocase; classtype:trojan-activity; sid:100003027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.195.84.250",nocase; classtype:trojan-activity; sid:100003028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.177",nocase; classtype:trojan-activity; sid:100003029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.69",nocase; classtype:trojan-activity; sid:100003030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.28.7.159",nocase; classtype:trojan-activity; sid:100003031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.30.119.23",nocase; classtype:trojan-activity; sid:100003032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32.208.157.193",nocase; classtype:trojan-activity; sid:100003033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32.218.180.9",nocase; classtype:trojan-activity; sid:100003034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"35.184.169.169",nocase; classtype:trojan-activity; sid:100003035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.108.231.218",nocase; classtype:trojan-activity; sid:100003036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.250.203.246",nocase; classtype:trojan-activity; sid:100003037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.157.225",nocase; classtype:trojan-activity; sid:100003038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.18.18",nocase; classtype:trojan-activity; sid:100003039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.19.88",nocase; classtype:trojan-activity; sid:100003040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.51.244",nocase; classtype:trojan-activity; sid:100003041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.255.90.219",nocase; classtype:trojan-activity; sid:100003042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.128.60",nocase; classtype:trojan-activity; sid:100003043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.160.167",nocase; classtype:trojan-activity; sid:100003044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.34.150.236",nocase; classtype:trojan-activity; sid:100003045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.36.243.67",nocase; classtype:trojan-activity; sid:100003046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.105.159",nocase; classtype:trojan-activity; sid:100003047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.111.203",nocase; classtype:trojan-activity; sid:100003048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.133.125",nocase; classtype:trojan-activity; sid:100003049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.139.36",nocase; classtype:trojan-activity; sid:100003050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.89.18.133",nocase; classtype:trojan-activity; sid:100003051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.96.187.93",nocase; classtype:trojan-activity; sid:100003052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360.lcy2zzx.pw",nocase; classtype:trojan-activity; sid:100003053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360down7.miiyun.cn",nocase; classtype:trojan-activity; sid:100003054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.222.98.51",nocase; classtype:trojan-activity; sid:100003055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.233.60.68",nocase; classtype:trojan-activity; sid:100003056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.179.221",nocase; classtype:trojan-activity; sid:100003057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.180.172",nocase; classtype:trojan-activity; sid:100003058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.44.238.35",nocase; classtype:trojan-activity; sid:100003059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.49.229.154",nocase; classtype:trojan-activity; sid:100003060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.49.230.152",nocase; classtype:trojan-activity; sid:100003061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.52.117.132",nocase; classtype:trojan-activity; sid:100003062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.14.36",nocase; classtype:trojan-activity; sid:100003063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"38.77.14.237",nocase; classtype:trojan-activity; sid:100003064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.245.254",nocase; classtype:trojan-activity; sid:100003065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.98.136",nocase; classtype:trojan-activity; sid:100003066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.114.137.102",nocase; classtype:trojan-activity; sid:100003067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.117.31.162",nocase; classtype:trojan-activity; sid:100003068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.162.104.119",nocase; classtype:trojan-activity; sid:100003069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.64.28.214",nocase; classtype:trojan-activity; sid:100003070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.196.34",nocase; classtype:trojan-activity; sid:100003071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.59.160",nocase; classtype:trojan-activity; sid:100003072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.115.94",nocase; classtype:trojan-activity; sid:100003073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.129.163",nocase; classtype:trojan-activity; sid:100003074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.44.109",nocase; classtype:trojan-activity; sid:100003075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.104.83",nocase; classtype:trojan-activity; sid:100003076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.125.186",nocase; classtype:trojan-activity; sid:100003077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.146.60",nocase; classtype:trojan-activity; sid:100003078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.148.163",nocase; classtype:trojan-activity; sid:100003079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.124.76",nocase; classtype:trojan-activity; sid:100003080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.171.125",nocase; classtype:trojan-activity; sid:100003081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.249.255",nocase; classtype:trojan-activity; sid:100003082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.60.61",nocase; classtype:trojan-activity; sid:100003083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.167.202",nocase; classtype:trojan-activity; sid:100003084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.5.175",nocase; classtype:trojan-activity; sid:100003085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.67.64",nocase; classtype:trojan-activity; sid:100003086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.10.198",nocase; classtype:trojan-activity; sid:100003087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.163.231",nocase; classtype:trojan-activity; sid:100003088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.203.225",nocase; classtype:trojan-activity; sid:100003089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.104.228",nocase; classtype:trojan-activity; sid:100003090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.184.222",nocase; classtype:trojan-activity; sid:100003091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.31.192",nocase; classtype:trojan-activity; sid:100003092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.68.182",nocase; classtype:trojan-activity; sid:100003093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.194.65",nocase; classtype:trojan-activity; sid:100003094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.33.191",nocase; classtype:trojan-activity; sid:100003095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.79.43",nocase; classtype:trojan-activity; sid:100003096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.97.16",nocase; classtype:trojan-activity; sid:100003097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.113.201",nocase; classtype:trojan-activity; sid:100003098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.114.45",nocase; classtype:trojan-activity; sid:100003099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.136.47",nocase; classtype:trojan-activity; sid:100003100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.14.27",nocase; classtype:trojan-activity; sid:100003101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.150.203",nocase; classtype:trojan-activity; sid:100003102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.197.81",nocase; classtype:trojan-activity; sid:100003103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.209.209",nocase; classtype:trojan-activity; sid:100003104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.94.189",nocase; classtype:trojan-activity; sid:100003105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.95.50",nocase; classtype:trojan-activity; sid:100003106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.146.67",nocase; classtype:trojan-activity; sid:100003107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.166.31",nocase; classtype:trojan-activity; sid:100003108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.218.46",nocase; classtype:trojan-activity; sid:100003109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.62.43",nocase; classtype:trojan-activity; sid:100003110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.91.244",nocase; classtype:trojan-activity; sid:100003111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.93.171",nocase; classtype:trojan-activity; sid:100003112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.127.214",nocase; classtype:trojan-activity; sid:100003113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.18.140",nocase; classtype:trojan-activity; sid:100003114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.191.137",nocase; classtype:trojan-activity; sid:100003115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.205.255",nocase; classtype:trojan-activity; sid:100003116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.24.54",nocase; classtype:trojan-activity; sid:100003117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.36.151",nocase; classtype:trojan-activity; sid:100003118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.251.0",nocase; classtype:trojan-activity; sid:100003119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.27.15",nocase; classtype:trojan-activity; sid:100003120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.29.231",nocase; classtype:trojan-activity; sid:100003121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.82.86.105",nocase; classtype:trojan-activity; sid:100003122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.83.94.11",nocase; classtype:trojan-activity; sid:100003123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.115.152",nocase; classtype:trojan-activity; sid:100003124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.157.52",nocase; classtype:trojan-activity; sid:100003125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.34.217",nocase; classtype:trojan-activity; sid:100003126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.95.200",nocase; classtype:trojan-activity; sid:100003127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.191",nocase; classtype:trojan-activity; sid:100003128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.4",nocase; classtype:trojan-activity; sid:100003129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.129.233",nocase; classtype:trojan-activity; sid:100003130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.13.0",nocase; classtype:trojan-activity; sid:100003131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.170.209",nocase; classtype:trojan-activity; sid:100003132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.184.164",nocase; classtype:trojan-activity; sid:100003133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.211.20",nocase; classtype:trojan-activity; sid:100003134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.216.144",nocase; classtype:trojan-activity; sid:100003135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.234.187",nocase; classtype:trojan-activity; sid:100003136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.248.91",nocase; classtype:trojan-activity; sid:100003137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.60.98",nocase; classtype:trojan-activity; sid:100003138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.66.24",nocase; classtype:trojan-activity; sid:100003139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.73.100",nocase; classtype:trojan-activity; sid:100003140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.78.228",nocase; classtype:trojan-activity; sid:100003141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.63.58",nocase; classtype:trojan-activity; sid:100003142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.90.210",nocase; classtype:trojan-activity; sid:100003143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.93.109",nocase; classtype:trojan-activity; sid:100003144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.141.172",nocase; classtype:trojan-activity; sid:100003145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.155.96",nocase; classtype:trojan-activity; sid:100003146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.233.131",nocase; classtype:trojan-activity; sid:100003147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.41.73",nocase; classtype:trojan-activity; sid:100003148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.67.238",nocase; classtype:trojan-activity; sid:100003149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.72.9",nocase; classtype:trojan-activity; sid:100003150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.198",nocase; classtype:trojan-activity; sid:100003151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.36",nocase; classtype:trojan-activity; sid:100003152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.157.140",nocase; classtype:trojan-activity; sid:100003153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.63.23",nocase; classtype:trojan-activity; sid:100003154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.90.86.212",nocase; classtype:trojan-activity; sid:100003155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"40.88.2.151",nocase; classtype:trojan-activity; sid:100003156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.139.209.46",nocase; classtype:trojan-activity; sid:100003157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.165.130.43",nocase; classtype:trojan-activity; sid:100003158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.193.192.100",nocase; classtype:trojan-activity; sid:100003159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.219.185.171",nocase; classtype:trojan-activity; sid:100003160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.230.31.58",nocase; classtype:trojan-activity; sid:100003161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.72.203.82",nocase; classtype:trojan-activity; sid:100003162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.148",nocase; classtype:trojan-activity; sid:100003163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.200",nocase; classtype:trojan-activity; sid:100003164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.71",nocase; classtype:trojan-activity; sid:100003165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.23",nocase; classtype:trojan-activity; sid:100003166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.233",nocase; classtype:trojan-activity; sid:100003167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.236",nocase; classtype:trojan-activity; sid:100003168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.176.112.72",nocase; classtype:trojan-activity; sid:100003169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.177.164.171",nocase; classtype:trojan-activity; sid:100003170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.179.162.208",nocase; classtype:trojan-activity; sid:100003171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.179.163.177",nocase; classtype:trojan-activity; sid:100003172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.202.101.147",nocase; classtype:trojan-activity; sid:100003173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.172.72",nocase; classtype:trojan-activity; sid:100000574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.53.200.130",nocase; classtype:trojan-activity; sid:100000575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.53.224.134",nocase; classtype:trojan-activity; sid:100000576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.53.234.210",nocase; classtype:trojan-activity; sid:100000577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.53.58.228",nocase; classtype:trojan-activity; sid:100000578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.113.49",nocase; classtype:trojan-activity; sid:100000579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.123.147",nocase; classtype:trojan-activity; sid:100000580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.158.251",nocase; classtype:trojan-activity; sid:100000581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.127.0",nocase; classtype:trojan-activity; sid:100000582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.144.42",nocase; classtype:trojan-activity; sid:100000583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.145.147",nocase; classtype:trojan-activity; sid:100000584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.157.96",nocase; classtype:trojan-activity; sid:100000585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.158.230",nocase; classtype:trojan-activity; sid:100000586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.158.250",nocase; classtype:trojan-activity; sid:100000587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.161.38",nocase; classtype:trojan-activity; sid:100000588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.179.168",nocase; classtype:trojan-activity; sid:100000589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.198.105",nocase; classtype:trojan-activity; sid:100000590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.206.35",nocase; classtype:trojan-activity; sid:100000591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.206.78",nocase; classtype:trojan-activity; sid:100000592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.26.94",nocase; classtype:trojan-activity; sid:100000593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.42.200",nocase; classtype:trojan-activity; sid:100000594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.52.17",nocase; classtype:trojan-activity; sid:100000595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.111.63",nocase; classtype:trojan-activity; sid:100000596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.114.17",nocase; classtype:trojan-activity; sid:100000597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.131.150",nocase; classtype:trojan-activity; sid:100000598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.133.96",nocase; classtype:trojan-activity; sid:100000599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.134.79",nocase; classtype:trojan-activity; sid:100000600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.135.255",nocase; classtype:trojan-activity; sid:100000601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.137.48",nocase; classtype:trojan-activity; sid:100000602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.139.122",nocase; classtype:trojan-activity; sid:100000603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.142.45",nocase; classtype:trojan-activity; sid:100000604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.145.102",nocase; classtype:trojan-activity; sid:100000605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.148.22",nocase; classtype:trojan-activity; sid:100000606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.150.149",nocase; classtype:trojan-activity; sid:100000607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.151.65",nocase; classtype:trojan-activity; sid:100000608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.151.68",nocase; classtype:trojan-activity; sid:100000609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.154.147",nocase; classtype:trojan-activity; sid:100000610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.155.50",nocase; classtype:trojan-activity; sid:100000611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.189.162",nocase; classtype:trojan-activity; sid:100000612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.31.11",nocase; classtype:trojan-activity; sid:100000613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.31.54",nocase; classtype:trojan-activity; sid:100000614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.98.205",nocase; classtype:trojan-activity; sid:100000615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.99.235",nocase; classtype:trojan-activity; sid:100000616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.132.199",nocase; classtype:trojan-activity; sid:100000617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.134.143",nocase; classtype:trojan-activity; sid:100000618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.86.217",nocase; classtype:trojan-activity; sid:100000619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.90.143",nocase; classtype:trojan-activity; sid:100000620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.91.65",nocase; classtype:trojan-activity; sid:100000621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.198.69",nocase; classtype:trojan-activity; sid:100000622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.212.193",nocase; classtype:trojan-activity; sid:100000623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.214.107",nocase; classtype:trojan-activity; sid:100000624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.228.237",nocase; classtype:trojan-activity; sid:100000625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.253.202",nocase; classtype:trojan-activity; sid:100000626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.57.171",nocase; classtype:trojan-activity; sid:100000627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.82.123",nocase; classtype:trojan-activity; sid:100000628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.103.197",nocase; classtype:trojan-activity; sid:100000629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.112.159",nocase; classtype:trojan-activity; sid:100000630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.118.201",nocase; classtype:trojan-activity; sid:100000631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.118.90",nocase; classtype:trojan-activity; sid:100000632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.158.98",nocase; classtype:trojan-activity; sid:100000633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.155.83",nocase; classtype:trojan-activity; sid:100000634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.171.143",nocase; classtype:trojan-activity; sid:100000635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.26.39",nocase; classtype:trojan-activity; sid:100000636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.131.173",nocase; classtype:trojan-activity; sid:100000637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.139.175",nocase; classtype:trojan-activity; sid:100000638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.141.147",nocase; classtype:trojan-activity; sid:100000639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.180.149",nocase; classtype:trojan-activity; sid:100000640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.189.77",nocase; classtype:trojan-activity; sid:100000641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.21.130",nocase; classtype:trojan-activity; sid:100000642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.53.188",nocase; classtype:trojan-activity; sid:100000643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.73.3.11",nocase; classtype:trojan-activity; sid:100000644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.75.217.79",nocase; classtype:trojan-activity; sid:100000645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.78.133.146",nocase; classtype:trojan-activity; sid:100000646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.92.174.231",nocase; classtype:trojan-activity; sid:100000647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.97.139.32",nocase; classtype:trojan-activity; sid:100000648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.124.219.2",nocase; classtype:trojan-activity; sid:100000649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.149.243.14",nocase; classtype:trojan-activity; sid:100000650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.206.164.46",nocase; classtype:trojan-activity; sid:100000651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.207.71.237",nocase; classtype:trojan-activity; sid:100000652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.211.100.26",nocase; classtype:trojan-activity; sid:100000653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.212.132.119",nocase; classtype:trojan-activity; sid:100000654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.212.142.215",nocase; classtype:trojan-activity; sid:100000655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.30.4.2",nocase; classtype:trojan-activity; sid:100000656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.30.95.156",nocase; classtype:trojan-activity; sid:100000657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.72.28.239",nocase; classtype:trojan-activity; sid:100000658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.73.52.125",nocase; classtype:trojan-activity; sid:100000659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.74.101.150",nocase; classtype:trojan-activity; sid:100000660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.74.17.122",nocase; classtype:trojan-activity; sid:100000661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.75.193.33",nocase; classtype:trojan-activity; sid:100000662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.75.198.85",nocase; classtype:trojan-activity; sid:100000663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.75.212.81",nocase; classtype:trojan-activity; sid:100000664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.76.114.71",nocase; classtype:trojan-activity; sid:100000665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.9.43.220",nocase; classtype:trojan-activity; sid:100000666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.11.234.35",nocase; classtype:trojan-activity; sid:100000667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.12.48.157",nocase; classtype:trojan-activity; sid:100000668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.156.69.22",nocase; classtype:trojan-activity; sid:100000669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.148.198",nocase; classtype:trojan-activity; sid:100000670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.160.203",nocase; classtype:trojan-activity; sid:100000671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.164.123",nocase; classtype:trojan-activity; sid:100000672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.167.131",nocase; classtype:trojan-activity; sid:100000673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.196.48.148",nocase; classtype:trojan-activity; sid:100000674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.196.48.181",nocase; classtype:trojan-activity; sid:100000675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.196.50.154",nocase; classtype:trojan-activity; sid:100000676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.196.50.239",nocase; classtype:trojan-activity; sid:100000677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.196.50.76",nocase; classtype:trojan-activity; sid:100000678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.138",nocase; classtype:trojan-activity; sid:100000679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.5",nocase; classtype:trojan-activity; sid:100000680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.210.52",nocase; classtype:trojan-activity; sid:100000681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.236.14",nocase; classtype:trojan-activity; sid:100000682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.243.40",nocase; classtype:trojan-activity; sid:100000683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.200.76.54",nocase; classtype:trojan-activity; sid:100000684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.200.76.60",nocase; classtype:trojan-activity; sid:100000685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.67.92",nocase; classtype:trojan-activity; sid:100000686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.208.132.10",nocase; classtype:trojan-activity; sid:100000687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.208.132.45",nocase; classtype:trojan-activity; sid:100000688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.44.102",nocase; classtype:trojan-activity; sid:100000689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.161.42",nocase; classtype:trojan-activity; sid:100000690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.164.100",nocase; classtype:trojan-activity; sid:100000691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.164.189",nocase; classtype:trojan-activity; sid:100000692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.173.218",nocase; classtype:trojan-activity; sid:100000693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.175.120",nocase; classtype:trojan-activity; sid:100000694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.241.64.105",nocase; classtype:trojan-activity; sid:100000695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.248.62.29",nocase; classtype:trojan-activity; sid:100000696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.26.235.164",nocase; classtype:trojan-activity; sid:100000697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.27.10.73",nocase; classtype:trojan-activity; sid:100000698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.60.204.190",nocase; classtype:trojan-activity; sid:100000699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.113.146",nocase; classtype:trojan-activity; sid:100000700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.195.140",nocase; classtype:trojan-activity; sid:100000701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.252.82",nocase; classtype:trojan-activity; sid:100000702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.53.15",nocase; classtype:trojan-activity; sid:100000703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.86.105.110",nocase; classtype:trojan-activity; sid:100000704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.91.240.50",nocase; classtype:trojan-activity; sid:100000705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.93.115.242",nocase; classtype:trojan-activity; sid:100000706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.93.79.40",nocase; classtype:trojan-activity; sid:100000707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.114.84.237",nocase; classtype:trojan-activity; sid:100000708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.172.176.41",nocase; classtype:trojan-activity; sid:100000709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.104.35",nocase; classtype:trojan-activity; sid:100000710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.157.64",nocase; classtype:trojan-activity; sid:100000711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.7.132",nocase; classtype:trojan-activity; sid:100000712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.211.38.112",nocase; classtype:trojan-activity; sid:100000713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.32.74",nocase; classtype:trojan-activity; sid:100000714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.5.149",nocase; classtype:trojan-activity; sid:100000715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.72.141",nocase; classtype:trojan-activity; sid:100000716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.12.130",nocase; classtype:trojan-activity; sid:100000717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.128.147",nocase; classtype:trojan-activity; sid:100000718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.208.215",nocase; classtype:trojan-activity; sid:100000719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.209.108",nocase; classtype:trojan-activity; sid:100000720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.214.72",nocase; classtype:trojan-activity; sid:100000721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.88.146",nocase; classtype:trojan-activity; sid:100000722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.150",nocase; classtype:trojan-activity; sid:100000723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.6",nocase; classtype:trojan-activity; sid:100000724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.221.162",nocase; classtype:trojan-activity; sid:100000725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.63.194",nocase; classtype:trojan-activity; sid:100000726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.65.93",nocase; classtype:trojan-activity; sid:100000727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.250.51.192",nocase; classtype:trojan-activity; sid:100000728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.42.125.246",nocase; classtype:trojan-activity; sid:100000729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.43.180.33",nocase; classtype:trojan-activity; sid:100000730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.70.83.140",nocase; classtype:trojan-activity; sid:100000731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.120.136",nocase; classtype:trojan-activity; sid:100000732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.240.136",nocase; classtype:trojan-activity; sid:100000733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.240.239",nocase; classtype:trojan-activity; sid:100000734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.50.253",nocase; classtype:trojan-activity; sid:100000735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.70.70",nocase; classtype:trojan-activity; sid:100000736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.125.92",nocase; classtype:trojan-activity; sid:100000737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.161.110",nocase; classtype:trojan-activity; sid:100000738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.164.102",nocase; classtype:trojan-activity; sid:100000739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.218.157",nocase; classtype:trojan-activity; sid:100000740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.50.203",nocase; classtype:trojan-activity; sid:100000741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.58.82",nocase; classtype:trojan-activity; sid:100000742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.96.11",nocase; classtype:trojan-activity; sid:100000743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.83.79.43",nocase; classtype:trojan-activity; sid:100000744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.91.41.135",nocase; classtype:trojan-activity; sid:100000745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.179.164",nocase; classtype:trojan-activity; sid:100000746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.183.235",nocase; classtype:trojan-activity; sid:100000747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.239.217",nocase; classtype:trojan-activity; sid:100000748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.100.40.250",nocase; classtype:trojan-activity; sid:100000749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.108.251.176",nocase; classtype:trojan-activity; sid:100000750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.112.22.58",nocase; classtype:trojan-activity; sid:100000751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.115.247.23",nocase; classtype:trojan-activity; sid:100000752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.118.150.84",nocase; classtype:trojan-activity; sid:100000753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.119.176.198",nocase; classtype:trojan-activity; sid:100000754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.119.52.202",nocase; classtype:trojan-activity; sid:100000755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.123.173.95",nocase; classtype:trojan-activity; sid:100000756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.123.175.210",nocase; classtype:trojan-activity; sid:100000757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.14.143.145",nocase; classtype:trojan-activity; sid:100000758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.147.213.57",nocase; classtype:trojan-activity; sid:100000759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.162.109.111",nocase; classtype:trojan-activity; sid:100000760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.144.208",nocase; classtype:trojan-activity; sid:100000761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.207.197",nocase; classtype:trojan-activity; sid:100000762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.93.191",nocase; classtype:trojan-activity; sid:100000763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.18.235",nocase; classtype:trojan-activity; sid:100000764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.31.76",nocase; classtype:trojan-activity; sid:100000765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.107.93",nocase; classtype:trojan-activity; sid:100000766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.163.220",nocase; classtype:trojan-activity; sid:100000767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.174.63",nocase; classtype:trojan-activity; sid:100000768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.241.222",nocase; classtype:trojan-activity; sid:100000769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.27.77",nocase; classtype:trojan-activity; sid:100000770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.68.145",nocase; classtype:trojan-activity; sid:100000771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.170.241",nocase; classtype:trojan-activity; sid:100000772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.19.254",nocase; classtype:trojan-activity; sid:100000773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.97.6",nocase; classtype:trojan-activity; sid:100000774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.1.13",nocase; classtype:trojan-activity; sid:100000775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.2.214",nocase; classtype:trojan-activity; sid:100000776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.26.33",nocase; classtype:trojan-activity; sid:100000777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.63.195",nocase; classtype:trojan-activity; sid:100000778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.201.188",nocase; classtype:trojan-activity; sid:100000779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.248.123",nocase; classtype:trojan-activity; sid:100000780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.249.140",nocase; classtype:trojan-activity; sid:100000781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.120.180",nocase; classtype:trojan-activity; sid:100000782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.157.219",nocase; classtype:trojan-activity; sid:100000783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.16.149",nocase; classtype:trojan-activity; sid:100000784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.170.212",nocase; classtype:trojan-activity; sid:100000785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.190.180",nocase; classtype:trojan-activity; sid:100000786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.43.1",nocase; classtype:trojan-activity; sid:100000787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.75.8",nocase; classtype:trojan-activity; sid:100000788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.18.38.144",nocase; classtype:trojan-activity; sid:100000789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.101.151",nocase; classtype:trojan-activity; sid:100000790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.106.217",nocase; classtype:trojan-activity; sid:100000791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.227",nocase; classtype:trojan-activity; sid:100000792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.79",nocase; classtype:trojan-activity; sid:100000793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.11.29",nocase; classtype:trojan-activity; sid:100000794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.231.79",nocase; classtype:trojan-activity; sid:100000795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.33.161",nocase; classtype:trojan-activity; sid:100000796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.9.35",nocase; classtype:trojan-activity; sid:100000797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.94.80",nocase; classtype:trojan-activity; sid:100000798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.119.21",nocase; classtype:trojan-activity; sid:100000799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.124.203",nocase; classtype:trojan-activity; sid:100000800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.115.103",nocase; classtype:trojan-activity; sid:100000801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.9.82",nocase; classtype:trojan-activity; sid:100000802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.14.112",nocase; classtype:trojan-activity; sid:100000803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.172.199",nocase; classtype:trojan-activity; sid:100000804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.237.89",nocase; classtype:trojan-activity; sid:100000805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.43.193",nocase; classtype:trojan-activity; sid:100000806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.186.140.160",nocase; classtype:trojan-activity; sid:100000807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.186.22.245",nocase; classtype:trojan-activity; sid:100000808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.195.161",nocase; classtype:trojan-activity; sid:100000809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.220.115",nocase; classtype:trojan-activity; sid:100000810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.137.195",nocase; classtype:trojan-activity; sid:100000811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.227.244",nocase; classtype:trojan-activity; sid:100000812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.190.211.99",nocase; classtype:trojan-activity; sid:100000813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.190.234.181",nocase; classtype:trojan-activity; sid:100000814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.150.85",nocase; classtype:trojan-activity; sid:100000815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.187.206",nocase; classtype:trojan-activity; sid:100000816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.215.221",nocase; classtype:trojan-activity; sid:100000817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.240.20",nocase; classtype:trojan-activity; sid:100000818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.253.206",nocase; classtype:trojan-activity; sid:100000819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.204.30.144",nocase; classtype:trojan-activity; sid:100000820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.250.129.231",nocase; classtype:trojan-activity; sid:100000821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.105.221",nocase; classtype:trojan-activity; sid:100000822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.12.85",nocase; classtype:trojan-activity; sid:100000823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.14.251",nocase; classtype:trojan-activity; sid:100000824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.131.155",nocase; classtype:trojan-activity; sid:100000825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.140.73",nocase; classtype:trojan-activity; sid:100000826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.46",nocase; classtype:trojan-activity; sid:100000827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.71",nocase; classtype:trojan-activity; sid:100000828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.148.115",nocase; classtype:trojan-activity; sid:100000829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.155.57",nocase; classtype:trojan-activity; sid:100000830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.172.28",nocase; classtype:trojan-activity; sid:100000831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.96.37.55",nocase; classtype:trojan-activity; sid:100000832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.96.70.116",nocase; classtype:trojan-activity; sid:100000833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.188.187",nocase; classtype:trojan-activity; sid:100000834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.190.152",nocase; classtype:trojan-activity; sid:100000835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.232.62",nocase; classtype:trojan-activity; sid:100000836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.132.113.2",nocase; classtype:trojan-activity; sid:100000837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.15.69.83",nocase; classtype:trojan-activity; sid:100000838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.6",nocase; classtype:trojan-activity; sid:100000839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.7",nocase; classtype:trojan-activity; sid:100000840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.8",nocase; classtype:trojan-activity; sid:100000841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.9",nocase; classtype:trojan-activity; sid:100000842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.207.39.227",nocase; classtype:trojan-activity; sid:100000843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.153.54",nocase; classtype:trojan-activity; sid:100000844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.212.5",nocase; classtype:trojan-activity; sid:100000845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.231.61",nocase; classtype:trojan-activity; sid:100000846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.142.222.22",nocase; classtype:trojan-activity; sid:100000847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.150.213.110",nocase; classtype:trojan-activity; sid:100000848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.151.248.134",nocase; classtype:trojan-activity; sid:100000849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.177",nocase; classtype:trojan-activity; sid:100000850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.178",nocase; classtype:trojan-activity; sid:100000851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.180",nocase; classtype:trojan-activity; sid:100000852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.181",nocase; classtype:trojan-activity; sid:100000853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.183",nocase; classtype:trojan-activity; sid:100000854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.184",nocase; classtype:trojan-activity; sid:100000855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.185",nocase; classtype:trojan-activity; sid:100000856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.186",nocase; classtype:trojan-activity; sid:100000857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.188",nocase; classtype:trojan-activity; sid:100000858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.191",nocase; classtype:trojan-activity; sid:100000859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.193",nocase; classtype:trojan-activity; sid:100000860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.196",nocase; classtype:trojan-activity; sid:100000861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.197",nocase; classtype:trojan-activity; sid:100000862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.198",nocase; classtype:trojan-activity; sid:100000863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.199",nocase; classtype:trojan-activity; sid:100000864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.200",nocase; classtype:trojan-activity; sid:100000865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.201",nocase; classtype:trojan-activity; sid:100000866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.202",nocase; classtype:trojan-activity; sid:100000867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.204",nocase; classtype:trojan-activity; sid:100000868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.205",nocase; classtype:trojan-activity; sid:100000869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.207",nocase; classtype:trojan-activity; sid:100000870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.208",nocase; classtype:trojan-activity; sid:100000871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.212",nocase; classtype:trojan-activity; sid:100000872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.213",nocase; classtype:trojan-activity; sid:100000873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.215",nocase; classtype:trojan-activity; sid:100000874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.233",nocase; classtype:trojan-activity; sid:100000875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.93.227",nocase; classtype:trojan-activity; sid:100000876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.121.243",nocase; classtype:trojan-activity; sid:100000877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.206",nocase; classtype:trojan-activity; sid:100000878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.225",nocase; classtype:trojan-activity; sid:100000879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.235",nocase; classtype:trojan-activity; sid:100000880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.240",nocase; classtype:trojan-activity; sid:100000881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.243",nocase; classtype:trojan-activity; sid:100000882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.60",nocase; classtype:trojan-activity; sid:100000883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.127.187",nocase; classtype:trojan-activity; sid:100000884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.99.127",nocase; classtype:trojan-activity; sid:100000885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.210.89.79",nocase; classtype:trojan-activity; sid:100000886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.43.34.242",nocase; classtype:trojan-activity; sid:100000887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.5.15.95",nocase; classtype:trojan-activity; sid:100000888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.66.60",nocase; classtype:trojan-activity; sid:100000889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.93.115",nocase; classtype:trojan-activity; sid:100000890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.57.214.228",nocase; classtype:trojan-activity; sid:100000891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.57.98.208",nocase; classtype:trojan-activity; sid:100000892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.141.142",nocase; classtype:trojan-activity; sid:100000893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.241.130",nocase; classtype:trojan-activity; sid:100000894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.8.11",nocase; classtype:trojan-activity; sid:100000895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.69.131.51",nocase; classtype:trojan-activity; sid:100000896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.7.75.99",nocase; classtype:trojan-activity; sid:100000897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.7.90.104",nocase; classtype:trojan-activity; sid:100000898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.83.189.232",nocase; classtype:trojan-activity; sid:100000899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.165.112",nocase; classtype:trojan-activity; sid:100000900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.185.141",nocase; classtype:trojan-activity; sid:100000901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.196.211",nocase; classtype:trojan-activity; sid:100000902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.208.107",nocase; classtype:trojan-activity; sid:100000903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.238.10",nocase; classtype:trojan-activity; sid:100000904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.9.32.51",nocase; classtype:trojan-activity; sid:100000905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.114.164",nocase; classtype:trojan-activity; sid:100000906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.96.8",nocase; classtype:trojan-activity; sid:100000907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.121.44.222",nocase; classtype:trojan-activity; sid:100000908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.123.53.25",nocase; classtype:trojan-activity; sid:100000909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.127.155.220",nocase; classtype:trojan-activity; sid:100000910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.141.11.56",nocase; classtype:trojan-activity; sid:100000911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.15.142.137",nocase; classtype:trojan-activity; sid:100000912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.159.22.144",nocase; classtype:trojan-activity; sid:100000913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.17.103.176",nocase; classtype:trojan-activity; sid:100000914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.170.234.142",nocase; classtype:trojan-activity; sid:100000915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.185.31.2",nocase; classtype:trojan-activity; sid:100000916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.190.36.8",nocase; classtype:trojan-activity; sid:100000917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.225.11.163",nocase; classtype:trojan-activity; sid:100000918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.226.82.202",nocase; classtype:trojan-activity; sid:100000919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.23.57.130",nocase; classtype:trojan-activity; sid:100000920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.230.171.198",nocase; classtype:trojan-activity; sid:100000921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.231.103.95",nocase; classtype:trojan-activity; sid:100000922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.233.18.172",nocase; classtype:trojan-activity; sid:100000923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.238.175.87",nocase; classtype:trojan-activity; sid:100000924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.239.15.74",nocase; classtype:trojan-activity; sid:100000925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.24.116.173",nocase; classtype:trojan-activity; sid:100000926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.25.101.86",nocase; classtype:trojan-activity; sid:100000927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.254.43.215",nocase; classtype:trojan-activity; sid:100000928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.254.76.17",nocase; classtype:trojan-activity; sid:100000929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.102.1",nocase; classtype:trojan-activity; sid:100000930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.107.189",nocase; classtype:trojan-activity; sid:100000931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.97.195",nocase; classtype:trojan-activity; sid:100000932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.98.151",nocase; classtype:trojan-activity; sid:100000933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.88.99.236",nocase; classtype:trojan-activity; sid:100000934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.100.150.204",nocase; classtype:trojan-activity; sid:100000935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.160.147.53",nocase; classtype:trojan-activity; sid:100000936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.176.44.34",nocase; classtype:trojan-activity; sid:100000937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.188.86.225",nocase; classtype:trojan-activity; sid:100000938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.66.28",nocase; classtype:trojan-activity; sid:100000939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.72.23",nocase; classtype:trojan-activity; sid:100000940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.79.27",nocase; classtype:trojan-activity; sid:100000941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.37.85",nocase; classtype:trojan-activity; sid:100000942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.41.23",nocase; classtype:trojan-activity; sid:100000943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.252.199.3",nocase; classtype:trojan-activity; sid:100000944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.183.207",nocase; classtype:trojan-activity; sid:100000945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.29.37",nocase; classtype:trojan-activity; sid:100000946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.33.214",nocase; classtype:trojan-activity; sid:100000947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.0.240.58",nocase; classtype:trojan-activity; sid:100000948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.83.136",nocase; classtype:trojan-activity; sid:100000949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.11.207",nocase; classtype:trojan-activity; sid:100000950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.4.168",nocase; classtype:trojan-activity; sid:100000951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.7.1",nocase; classtype:trojan-activity; sid:100000952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.71.166",nocase; classtype:trojan-activity; sid:100000953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.238",nocase; classtype:trojan-activity; sid:100000954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.244",nocase; classtype:trojan-activity; sid:100000955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.170.237",nocase; classtype:trojan-activity; sid:100000956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.182.187",nocase; classtype:trojan-activity; sid:100000957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.19.248",nocase; classtype:trojan-activity; sid:100000958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.200.98",nocase; classtype:trojan-activity; sid:100000959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.238.188",nocase; classtype:trojan-activity; sid:100000960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.12.189.247",nocase; classtype:trojan-activity; sid:100000961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.12.225.70",nocase; classtype:trojan-activity; sid:100000962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.12.235.159",nocase; classtype:trojan-activity; sid:100000963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.12.243.85",nocase; classtype:trojan-activity; sid:100000964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.128.205",nocase; classtype:trojan-activity; sid:100000965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.133.91",nocase; classtype:trojan-activity; sid:100000966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.177.161",nocase; classtype:trojan-activity; sid:100000967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.84.36",nocase; classtype:trojan-activity; sid:100000968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.88.123",nocase; classtype:trojan-activity; sid:100000969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.202.8",nocase; classtype:trojan-activity; sid:100000970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.208.52",nocase; classtype:trojan-activity; sid:100000971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.23.110",nocase; classtype:trojan-activity; sid:100000972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.27.19",nocase; classtype:trojan-activity; sid:100000973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.37.182",nocase; classtype:trojan-activity; sid:100000974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.61.210",nocase; classtype:trojan-activity; sid:100000975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.77.225",nocase; classtype:trojan-activity; sid:100000976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.131.186.250",nocase; classtype:trojan-activity; sid:100000977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.132.219.147",nocase; classtype:trojan-activity; sid:100000978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.125.77",nocase; classtype:trojan-activity; sid:100000979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.144.138",nocase; classtype:trojan-activity; sid:100000980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.184.77",nocase; classtype:trojan-activity; sid:100000981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.98.135",nocase; classtype:trojan-activity; sid:100000982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.14.130",nocase; classtype:trojan-activity; sid:100000983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.50.186",nocase; classtype:trojan-activity; sid:100000984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.39.36",nocase; classtype:trojan-activity; sid:100000985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.71.150",nocase; classtype:trojan-activity; sid:100000986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.127.238",nocase; classtype:trojan-activity; sid:100000987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.173.199",nocase; classtype:trojan-activity; sid:100000988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.249.33",nocase; classtype:trojan-activity; sid:100000989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.34.240",nocase; classtype:trojan-activity; sid:100000990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.37.32",nocase; classtype:trojan-activity; sid:100000991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.50.214",nocase; classtype:trojan-activity; sid:100000992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.93.154",nocase; classtype:trojan-activity; sid:100000993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.144.211.86",nocase; classtype:trojan-activity; sid:100000994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.152.42.4",nocase; classtype:trojan-activity; sid:100000995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.153.80.178",nocase; classtype:trojan-activity; sid:100000996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.116.116",nocase; classtype:trojan-activity; sid:100000997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.236.114",nocase; classtype:trojan-activity; sid:100000998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.94.1",nocase; classtype:trojan-activity; sid:100000999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.155.118.36",nocase; classtype:trojan-activity; sid:100001000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.156.136.21",nocase; classtype:trojan-activity; sid:100001001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.137.101",nocase; classtype:trojan-activity; sid:100001002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.31.110",nocase; classtype:trojan-activity; sid:100001003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.8.100",nocase; classtype:trojan-activity; sid:100001004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.101.163",nocase; classtype:trojan-activity; sid:100001005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.194.233",nocase; classtype:trojan-activity; sid:100001006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.149.235",nocase; classtype:trojan-activity; sid:100001007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.53.237",nocase; classtype:trojan-activity; sid:100001008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.235.37",nocase; classtype:trojan-activity; sid:100001009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.35.146",nocase; classtype:trojan-activity; sid:100001010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.52.79",nocase; classtype:trojan-activity; sid:100001011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.60.238",nocase; classtype:trojan-activity; sid:100001012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.112.240",nocase; classtype:trojan-activity; sid:100001013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.184.191",nocase; classtype:trojan-activity; sid:100001014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.98.141",nocase; classtype:trojan-activity; sid:100001015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.212.29.154",nocase; classtype:trojan-activity; sid:100001016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.213.225.130",nocase; classtype:trojan-activity; sid:100001017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.130.162",nocase; classtype:trojan-activity; sid:100001018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.152.249",nocase; classtype:trojan-activity; sid:100001019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.100.219",nocase; classtype:trojan-activity; sid:100001020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.116.110",nocase; classtype:trojan-activity; sid:100001021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.184.57",nocase; classtype:trojan-activity; sid:100001022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.246.103",nocase; classtype:trojan-activity; sid:100001023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.235.226.3",nocase; classtype:trojan-activity; sid:100001024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.103.89",nocase; classtype:trojan-activity; sid:100001025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.181.57",nocase; classtype:trojan-activity; sid:100001026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.79.61",nocase; classtype:trojan-activity; sid:100001027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.148.58",nocase; classtype:trojan-activity; sid:100001028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.184.124",nocase; classtype:trojan-activity; sid:100001029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.27.44.219",nocase; classtype:trojan-activity; sid:100001030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.28.217.23",nocase; classtype:trojan-activity; sid:100001031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.11.40",nocase; classtype:trojan-activity; sid:100001032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.166.2",nocase; classtype:trojan-activity; sid:100001033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.177.93",nocase; classtype:trojan-activity; sid:100001034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.194.152",nocase; classtype:trojan-activity; sid:100001035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.209.154",nocase; classtype:trojan-activity; sid:100001036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.241.118",nocase; classtype:trojan-activity; sid:100001037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.45.31",nocase; classtype:trojan-activity; sid:100001038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.76.117",nocase; classtype:trojan-activity; sid:100001039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.83.66",nocase; classtype:trojan-activity; sid:100001040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.85.149",nocase; classtype:trojan-activity; sid:100001041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.143.203",nocase; classtype:trojan-activity; sid:100001042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.146.238",nocase; classtype:trojan-activity; sid:100001043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.190.167",nocase; classtype:trojan-activity; sid:100001044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.5.242",nocase; classtype:trojan-activity; sid:100001045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.8.211",nocase; classtype:trojan-activity; sid:100001046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.56.94",nocase; classtype:trojan-activity; sid:100001047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.71.27",nocase; classtype:trojan-activity; sid:100001048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.194.169",nocase; classtype:trojan-activity; sid:100001049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.240.115",nocase; classtype:trojan-activity; sid:100001050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.245.207",nocase; classtype:trojan-activity; sid:100001051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.105.105.222",nocase; classtype:trojan-activity; sid:100001052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.162.169",nocase; classtype:trojan-activity; sid:100001053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.221.150",nocase; classtype:trojan-activity; sid:100001054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.76.230",nocase; classtype:trojan-activity; sid:100001055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.167.20",nocase; classtype:trojan-activity; sid:100001056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.40.31",nocase; classtype:trojan-activity; sid:100001057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.104.82",nocase; classtype:trojan-activity; sid:100001058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.130.95",nocase; classtype:trojan-activity; sid:100001059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.131.71",nocase; classtype:trojan-activity; sid:100001060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.136.75",nocase; classtype:trojan-activity; sid:100001061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.137.147",nocase; classtype:trojan-activity; sid:100001062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.151.135",nocase; classtype:trojan-activity; sid:100001063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.24.185",nocase; classtype:trojan-activity; sid:100001064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.26.243",nocase; classtype:trojan-activity; sid:100001065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.26.78",nocase; classtype:trojan-activity; sid:100001066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.41.48",nocase; classtype:trojan-activity; sid:100001067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.54.33",nocase; classtype:trojan-activity; sid:100001068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.72.208",nocase; classtype:trojan-activity; sid:100001069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.132.110.150",nocase; classtype:trojan-activity; sid:100001070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.135.34.157",nocase; classtype:trojan-activity; sid:100001071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.135.34.49",nocase; classtype:trojan-activity; sid:100001072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.136.175",nocase; classtype:trojan-activity; sid:100001073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.236.6",nocase; classtype:trojan-activity; sid:100001074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.160.126.238",nocase; classtype:trojan-activity; sid:100001075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.154.237",nocase; classtype:trojan-activity; sid:100001076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.65.64",nocase; classtype:trojan-activity; sid:100001077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.65.98",nocase; classtype:trojan-activity; sid:100001078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.72.102",nocase; classtype:trojan-activity; sid:100001079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.77.191",nocase; classtype:trojan-activity; sid:100001080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.89.212",nocase; classtype:trojan-activity; sid:100001081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.90.243",nocase; classtype:trojan-activity; sid:100001082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.165.123.7",nocase; classtype:trojan-activity; sid:100001083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.187.111.160",nocase; classtype:trojan-activity; sid:100001084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.199.56.198",nocase; classtype:trojan-activity; sid:100001085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.226.24.117",nocase; classtype:trojan-activity; sid:100001086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.230.174.233",nocase; classtype:trojan-activity; sid:100001087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.254.254.61",nocase; classtype:trojan-activity; sid:100001088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.5.92.20",nocase; classtype:trojan-activity; sid:100001089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.6.0.4",nocase; classtype:trojan-activity; sid:100001090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.67.89.28",nocase; classtype:trojan-activity; sid:100001091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.7.254.85",nocase; classtype:trojan-activity; sid:100001092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.80.46.73",nocase; classtype:trojan-activity; sid:100001093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.91.237.147",nocase; classtype:trojan-activity; sid:100001094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.92.135.37",nocase; classtype:trojan-activity; sid:100001095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.93.94.207",nocase; classtype:trojan-activity; sid:100001096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.105.219.169",nocase; classtype:trojan-activity; sid:100001097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.126.69.95",nocase; classtype:trojan-activity; sid:100001098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.128.28.161",nocase; classtype:trojan-activity; sid:100001099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.142.93.34",nocase; classtype:trojan-activity; sid:100001100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.168.10.234",nocase; classtype:trojan-activity; sid:100001101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.191.113.212",nocase; classtype:trojan-activity; sid:100001102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.209.71.6",nocase; classtype:trojan-activity; sid:100001103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.36.148.42",nocase; classtype:trojan-activity; sid:100001104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.1.127",nocase; classtype:trojan-activity; sid:100001105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.113.66",nocase; classtype:trojan-activity; sid:100001106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.25.140",nocase; classtype:trojan-activity; sid:100001107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.65.120",nocase; classtype:trojan-activity; sid:100001108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.73.6",nocase; classtype:trojan-activity; sid:100001109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.74.153",nocase; classtype:trojan-activity; sid:100001110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.75.22",nocase; classtype:trojan-activity; sid:100001111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.141.41",nocase; classtype:trojan-activity; sid:100001112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.164.60",nocase; classtype:trojan-activity; sid:100001113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.185.186",nocase; classtype:trojan-activity; sid:100001114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.196.114",nocase; classtype:trojan-activity; sid:100001115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.208.139",nocase; classtype:trojan-activity; sid:100001116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.6.192",nocase; classtype:trojan-activity; sid:100001117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.7.204",nocase; classtype:trojan-activity; sid:100001118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.74.22",nocase; classtype:trojan-activity; sid:100001119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.96.238",nocase; classtype:trojan-activity; sid:100001120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.96.33",nocase; classtype:trojan-activity; sid:100001121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.97.231",nocase; classtype:trojan-activity; sid:100001122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.97.81",nocase; classtype:trojan-activity; sid:100001123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.107.136",nocase; classtype:trojan-activity; sid:100001124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.124.114",nocase; classtype:trojan-activity; sid:100001125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.112.123",nocase; classtype:trojan-activity; sid:100001126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.112.182",nocase; classtype:trojan-activity; sid:100001127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.133.130",nocase; classtype:trojan-activity; sid:100001128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.167.192",nocase; classtype:trojan-activity; sid:100001129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.215.244",nocase; classtype:trojan-activity; sid:100001130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.33.20",nocase; classtype:trojan-activity; sid:100001131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.53.50",nocase; classtype:trojan-activity; sid:100001132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.53.9",nocase; classtype:trojan-activity; sid:100001133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.6.186",nocase; classtype:trojan-activity; sid:100001134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.60.218",nocase; classtype:trojan-activity; sid:100001135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.63.47",nocase; classtype:trojan-activity; sid:100001136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.10.125",nocase; classtype:trojan-activity; sid:100001137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.107.182",nocase; classtype:trojan-activity; sid:100001138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.175.118",nocase; classtype:trojan-activity; sid:100001139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.198.62",nocase; classtype:trojan-activity; sid:100001140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.208.152",nocase; classtype:trojan-activity; sid:100001141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.212.131",nocase; classtype:trojan-activity; sid:100001142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.227.51",nocase; classtype:trojan-activity; sid:100001143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.70.64",nocase; classtype:trojan-activity; sid:100001144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.8.227",nocase; classtype:trojan-activity; sid:100001145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.153.91",nocase; classtype:trojan-activity; sid:100001146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.43.63",nocase; classtype:trojan-activity; sid:100001147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.55.146",nocase; classtype:trojan-activity; sid:100001148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.166.112",nocase; classtype:trojan-activity; sid:100001149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.166.125",nocase; classtype:trojan-activity; sid:100001150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.205.88",nocase; classtype:trojan-activity; sid:100001151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.206.160",nocase; classtype:trojan-activity; sid:100001152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.217.52",nocase; classtype:trojan-activity; sid:100001153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.241.237",nocase; classtype:trojan-activity; sid:100001154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.125.16",nocase; classtype:trojan-activity; sid:100001155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.241.188",nocase; classtype:trojan-activity; sid:100001156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.245.200",nocase; classtype:trojan-activity; sid:100001157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.248.131",nocase; classtype:trojan-activity; sid:100001158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.250.98",nocase; classtype:trojan-activity; sid:100001159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.254.44",nocase; classtype:trojan-activity; sid:100001160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.28.18",nocase; classtype:trojan-activity; sid:100001161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.38.142",nocase; classtype:trojan-activity; sid:100001162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.45.218",nocase; classtype:trojan-activity; sid:100001163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.47.212",nocase; classtype:trojan-activity; sid:100001164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.57.80",nocase; classtype:trojan-activity; sid:100001165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.91.51",nocase; classtype:trojan-activity; sid:100001166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.79.192.197",nocase; classtype:trojan-activity; sid:100001167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"128.116.133.92",nocase; classtype:trojan-activity; sid:100001168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"130.255.159.133",nocase; classtype:trojan-activity; sid:100001169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"134.195.139.4",nocase; classtype:trojan-activity; sid:100001170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"134.255.93.203",nocase; classtype:trojan-activity; sid:100001171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"135.181.192.170",nocase; classtype:trojan-activity; sid:100001172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"138.99.204.224",nocase; classtype:trojan-activity; sid:100001173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.159.226.180",nocase; classtype:trojan-activity; sid:100001174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.173.198",nocase; classtype:trojan-activity; sid:100001175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.174.162",nocase; classtype:trojan-activity; sid:100001176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.213.97.191",nocase; classtype:trojan-activity; sid:100001177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.216.102.151",nocase; classtype:trojan-activity; sid:100001178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.227.46.137",nocase; classtype:trojan-activity; sid:100001179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.102.17.222",nocase; classtype:trojan-activity; sid:100001180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.102.97.204",nocase; classtype:trojan-activity; sid:100001181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.109.126.96",nocase; classtype:trojan-activity; sid:100001182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.136.80.242",nocase; classtype:trojan-activity; sid:100001183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.109.26",nocase; classtype:trojan-activity; sid:100001184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.215",nocase; classtype:trojan-activity; sid:100001185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.51",nocase; classtype:trojan-activity; sid:100001186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.155.220.240",nocase; classtype:trojan-activity; sid:100001187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.160.24.71",nocase; classtype:trojan-activity; sid:100001188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.169.164.77",nocase; classtype:trojan-activity; sid:100001189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.181.64.108",nocase; classtype:trojan-activity; sid:100001190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.189.247.118",nocase; classtype:trojan-activity; sid:100001191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.205.201.192",nocase; classtype:trojan-activity; sid:100001192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.248.187.0",nocase; classtype:trojan-activity; sid:100001193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.37.222.190",nocase; classtype:trojan-activity; sid:100001194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.45.127.110",nocase; classtype:trojan-activity; sid:100001195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.25.17",nocase; classtype:trojan-activity; sid:100001196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.98.241",nocase; classtype:trojan-activity; sid:100001197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.55.29.2",nocase; classtype:trojan-activity; sid:100001198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.98.184.178",nocase; classtype:trojan-activity; sid:100001199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"140.237.30.113",nocase; classtype:trojan-activity; sid:100001200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"140.237.30.172",nocase; classtype:trojan-activity; sid:100001201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"140.237.5.43",nocase; classtype:trojan-activity; sid:100001202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"140.240.151.177",nocase; classtype:trojan-activity; sid:100001203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.11.216.5",nocase; classtype:trojan-activity; sid:100001204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.177.56.127",nocase; classtype:trojan-activity; sid:100001205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"146.71.79.230",nocase; classtype:trojan-activity; sid:100001206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"148.69.108.177",nocase; classtype:trojan-activity; sid:100001207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.20.176.179",nocase; classtype:trojan-activity; sid:100001208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.134",nocase; classtype:trojan-activity; sid:100001209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.172",nocase; classtype:trojan-activity; sid:100001210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.180",nocase; classtype:trojan-activity; sid:100001211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.182",nocase; classtype:trojan-activity; sid:100001212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.184",nocase; classtype:trojan-activity; sid:100001213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.213",nocase; classtype:trojan-activity; sid:100001214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.43",nocase; classtype:trojan-activity; sid:100001215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.87",nocase; classtype:trojan-activity; sid:100001216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.99",nocase; classtype:trojan-activity; sid:100001217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.124.194",nocase; classtype:trojan-activity; sid:100001218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.73.210",nocase; classtype:trojan-activity; sid:100001219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"150.116.207.99",nocase; classtype:trojan-activity; sid:100001220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.177.163.87",nocase; classtype:trojan-activity; sid:100001221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.33.230.191",nocase; classtype:trojan-activity; sid:100001222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.73.124.231",nocase; classtype:trojan-activity; sid:100001223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.225.96",nocase; classtype:trojan-activity; sid:100001224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.234.167",nocase; classtype:trojan-activity; sid:100001225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.40.207",nocase; classtype:trojan-activity; sid:100001226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.43.136",nocase; classtype:trojan-activity; sid:100001227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.44.44",nocase; classtype:trojan-activity; sid:100001228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.135.92",nocase; classtype:trojan-activity; sid:100001229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.23.76",nocase; classtype:trojan-activity; sid:100001230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.29.28",nocase; classtype:trojan-activity; sid:100001231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.35.27.49",nocase; classtype:trojan-activity; sid:100001232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.36.126.35",nocase; classtype:trojan-activity; sid:100001233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.101.165.14",nocase; classtype:trojan-activity; sid:100001234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.174.213.128",nocase; classtype:trojan-activity; sid:100001235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.51.125.115",nocase; classtype:trojan-activity; sid:100001236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"159.224.74.112",nocase; classtype:trojan-activity; sid:100001237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.165.238",nocase; classtype:trojan-activity; sid:100001238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.205.175",nocase; classtype:trojan-activity; sid:100001239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.194.28.60",nocase; classtype:trojan-activity; sid:100001240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.209.98.174",nocase; classtype:trojan-activity; sid:100001241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.212.203.250",nocase; classtype:trojan-activity; sid:100001242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.18.93",nocase; classtype:trojan-activity; sid:100001243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.193.148",nocase; classtype:trojan-activity; sid:100001244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.200.118",nocase; classtype:trojan-activity; sid:100001245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.200.242",nocase; classtype:trojan-activity; sid:100001246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.202.193",nocase; classtype:trojan-activity; sid:100001247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.202.255",nocase; classtype:trojan-activity; sid:100001248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.202.87",nocase; classtype:trojan-activity; sid:100001249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.203.198",nocase; classtype:trojan-activity; sid:100001250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.203.236",nocase; classtype:trojan-activity; sid:100001251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.204.156",nocase; classtype:trojan-activity; sid:100001252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.204.34",nocase; classtype:trojan-activity; sid:100001253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.206.16",nocase; classtype:trojan-activity; sid:100001254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.255.165",nocase; classtype:trojan-activity; sid:100001255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.204.208.169",nocase; classtype:trojan-activity; sid:100001256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.204.211.136",nocase; classtype:trojan-activity; sid:100001257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.204.211.228",nocase; classtype:trojan-activity; sid:100001258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.204.211.58",nocase; classtype:trojan-activity; sid:100001259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.53.206.228",nocase; classtype:trojan-activity; sid:100001260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"165.90.16.5",nocase; classtype:trojan-activity; sid:100001261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"168.194.146.145",nocase; classtype:trojan-activity; sid:100001262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"168.205.223.254",nocase; classtype:trojan-activity; sid:100001263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"168.90.204.207",nocase; classtype:trojan-activity; sid:100001264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"170.81.238.178",nocase; classtype:trojan-activity; sid:100001265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.113.36.216",nocase; classtype:trojan-activity; sid:100001266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.118.18.184",nocase; classtype:trojan-activity; sid:100001267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.118.210.67",nocase; classtype:trojan-activity; sid:100001268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.217.149",nocase; classtype:trojan-activity; sid:100001269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.218.208",nocase; classtype:trojan-activity; sid:100001270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.219.150",nocase; classtype:trojan-activity; sid:100001271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.248.222",nocase; classtype:trojan-activity; sid:100001272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.255.96",nocase; classtype:trojan-activity; sid:100001273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.120.125.147",nocase; classtype:trojan-activity; sid:100001274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.121.6.162",nocase; classtype:trojan-activity; sid:100001275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.123.134.239",nocase; classtype:trojan-activity; sid:100001276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.122.91",nocase; classtype:trojan-activity; sid:100001277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.242.71",nocase; classtype:trojan-activity; sid:100001278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.30.233",nocase; classtype:trojan-activity; sid:100001279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.30.93",nocase; classtype:trojan-activity; sid:100001280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.64.223",nocase; classtype:trojan-activity; sid:100001281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.65.22",nocase; classtype:trojan-activity; sid:100001282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.65.89",nocase; classtype:trojan-activity; sid:100001283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.75.68",nocase; classtype:trojan-activity; sid:100001284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.126.70.133",nocase; classtype:trojan-activity; sid:100001285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.223.72.123",nocase; classtype:trojan-activity; sid:100001286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.112.42",nocase; classtype:trojan-activity; sid:100001287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.114.181",nocase; classtype:trojan-activity; sid:100001288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.179.178",nocase; classtype:trojan-activity; sid:100001289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.160.138",nocase; classtype:trojan-activity; sid:100001290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.161.234",nocase; classtype:trojan-activity; sid:100001291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.162.156",nocase; classtype:trojan-activity; sid:100001292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.174.198",nocase; classtype:trojan-activity; sid:100001293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.36.249.91",nocase; classtype:trojan-activity; sid:100001294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.145.146",nocase; classtype:trojan-activity; sid:100001295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.148.69",nocase; classtype:trojan-activity; sid:100001296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.219.189",nocase; classtype:trojan-activity; sid:100001297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.223.110",nocase; classtype:trojan-activity; sid:100001298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.223.213",nocase; classtype:trojan-activity; sid:100001299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.105.36.168",nocase; classtype:trojan-activity; sid:100001300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.114.244.127",nocase; classtype:trojan-activity; sid:100001301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.185",nocase; classtype:trojan-activity; sid:100001302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.190",nocase; classtype:trojan-activity; sid:100001303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.81.19",nocase; classtype:trojan-activity; sid:100001304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.167.85.89",nocase; classtype:trojan-activity; sid:100001305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.169.46.85",nocase; classtype:trojan-activity; sid:100001306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.19.58.108",nocase; classtype:trojan-activity; sid:100001307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.233.85.171",nocase; classtype:trojan-activity; sid:100001308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.235.209.70",nocase; classtype:trojan-activity; sid:100001309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.25.113.8",nocase; classtype:trojan-activity; sid:100001310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.95.134",nocase; classtype:trojan-activity; sid:100001311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.97.25",nocase; classtype:trojan-activity; sid:100001312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.119.108",nocase; classtype:trojan-activity; sid:100001313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.92.166",nocase; classtype:trojan-activity; sid:100001314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.106.33.85",nocase; classtype:trojan-activity; sid:100001315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.48.181.23",nocase; classtype:trojan-activity; sid:100001316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.61.3.149",nocase; classtype:trojan-activity; sid:100001317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.73.246.193",nocase; classtype:trojan-activity; sid:100001318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.81.78.7",nocase; classtype:trojan-activity; sid:100001319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.83.73.163",nocase; classtype:trojan-activity; sid:100001320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.10.147.167",nocase; classtype:trojan-activity; sid:100001321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.11.193.66",nocase; classtype:trojan-activity; sid:100001322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.115.241.87",nocase; classtype:trojan-activity; sid:100001323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.117.66.74",nocase; classtype:trojan-activity; sid:100001324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.145.200.216",nocase; classtype:trojan-activity; sid:100001325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.146.17.227",nocase; classtype:trojan-activity; sid:100001326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.150.168.92",nocase; classtype:trojan-activity; sid:100001327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.162.137.166",nocase; classtype:trojan-activity; sid:100001328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.162.195.27",nocase; classtype:trojan-activity; sid:100001329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.162.69.13",nocase; classtype:trojan-activity; sid:100001330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.164.61.215",nocase; classtype:trojan-activity; sid:100001331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.165.90.198",nocase; classtype:trojan-activity; sid:100001332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.168.139.182",nocase; classtype:trojan-activity; sid:100001333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.169.13.182",nocase; classtype:trojan-activity; sid:100001334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.17.90.14",nocase; classtype:trojan-activity; sid:100001335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.174.93.57",nocase; classtype:trojan-activity; sid:100001336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.199.33.139",nocase; classtype:trojan-activity; sid:100001337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.201.104.192",nocase; classtype:trojan-activity; sid:100001338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.208.230.8",nocase; classtype:trojan-activity; sid:100001339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.212.6.169",nocase; classtype:trojan-activity; sid:100001340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.42.46.118",nocase; classtype:trojan-activity; sid:100001341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.8.113.55",nocase; classtype:trojan-activity; sid:100001342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.9.24.110",nocase; classtype:trojan-activity; sid:100001343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.14",nocase; classtype:trojan-activity; sid:100001344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.35",nocase; classtype:trojan-activity; sid:100001345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.63",nocase; classtype:trojan-activity; sid:100001346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.66",nocase; classtype:trojan-activity; sid:100001347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.67",nocase; classtype:trojan-activity; sid:100001348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.104",nocase; classtype:trojan-activity; sid:100001349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.113",nocase; classtype:trojan-activity; sid:100001350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.128",nocase; classtype:trojan-activity; sid:100001351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.60",nocase; classtype:trojan-activity; sid:100001352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.65",nocase; classtype:trojan-activity; sid:100001353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.66",nocase; classtype:trojan-activity; sid:100001354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.76",nocase; classtype:trojan-activity; sid:100001355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.84",nocase; classtype:trojan-activity; sid:100001356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.88",nocase; classtype:trojan-activity; sid:100001357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.93",nocase; classtype:trojan-activity; sid:100001358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.174.139",nocase; classtype:trojan-activity; sid:100001359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.12.117.70",nocase; classtype:trojan-activity; sid:100001360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.4.115",nocase; classtype:trojan-activity; sid:100001361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.115",nocase; classtype:trojan-activity; sid:100001362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.127",nocase; classtype:trojan-activity; sid:100001363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.9.243",nocase; classtype:trojan-activity; sid:100001364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.124.7.225",nocase; classtype:trojan-activity; sid:100001365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.221.251.238",nocase; classtype:trojan-activity; sid:100001366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.40.142",nocase; classtype:trojan-activity; sid:100001367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.84.106",nocase; classtype:trojan-activity; sid:100001368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.11.92.78",nocase; classtype:trojan-activity; sid:100001369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.131.226.235",nocase; classtype:trojan-activity; sid:100001370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.229.64.218",nocase; classtype:trojan-activity; sid:100001371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.54.82.154",nocase; classtype:trojan-activity; sid:100001372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.124.182.187",nocase; classtype:trojan-activity; sid:100001373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.134.185.112",nocase; classtype:trojan-activity; sid:100001374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.25.82",nocase; classtype:trojan-activity; sid:100001375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.44.152",nocase; classtype:trojan-activity; sid:100001376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.45.2",nocase; classtype:trojan-activity; sid:100001377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.57.166",nocase; classtype:trojan-activity; sid:100001378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.150.174.65",nocase; classtype:trojan-activity; sid:100001379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.151.143.2",nocase; classtype:trojan-activity; sid:100001380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.165.122.141",nocase; classtype:trojan-activity; sid:100001381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.0.140",nocase; classtype:trojan-activity; sid:100001382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.139",nocase; classtype:trojan-activity; sid:100001383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.153",nocase; classtype:trojan-activity; sid:100001384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.176",nocase; classtype:trojan-activity; sid:100001385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.182",nocase; classtype:trojan-activity; sid:100001386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.244",nocase; classtype:trojan-activity; sid:100001387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.249",nocase; classtype:trojan-activity; sid:100001388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.250",nocase; classtype:trojan-activity; sid:100001389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.252",nocase; classtype:trojan-activity; sid:100001390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.44",nocase; classtype:trojan-activity; sid:100001391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.80",nocase; classtype:trojan-activity; sid:100001392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.104",nocase; classtype:trojan-activity; sid:100001393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.121",nocase; classtype:trojan-activity; sid:100001394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.178",nocase; classtype:trojan-activity; sid:100001395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.34",nocase; classtype:trojan-activity; sid:100001396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.42",nocase; classtype:trojan-activity; sid:100001397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.71",nocase; classtype:trojan-activity; sid:100001398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.78",nocase; classtype:trojan-activity; sid:100001399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.110",nocase; classtype:trojan-activity; sid:100001400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.129",nocase; classtype:trojan-activity; sid:100001401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.180",nocase; classtype:trojan-activity; sid:100001402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.191",nocase; classtype:trojan-activity; sid:100001403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.218",nocase; classtype:trojan-activity; sid:100001404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.34",nocase; classtype:trojan-activity; sid:100001405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.4",nocase; classtype:trojan-activity; sid:100001406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.52",nocase; classtype:trojan-activity; sid:100001407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.110",nocase; classtype:trojan-activity; sid:100001408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.173",nocase; classtype:trojan-activity; sid:100001409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.191",nocase; classtype:trojan-activity; sid:100001410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.134",nocase; classtype:trojan-activity; sid:100001411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.14",nocase; classtype:trojan-activity; sid:100001412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.221",nocase; classtype:trojan-activity; sid:100001413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.245",nocase; classtype:trojan-activity; sid:100001414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.35",nocase; classtype:trojan-activity; sid:100001415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.53",nocase; classtype:trojan-activity; sid:100001416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.172",nocase; classtype:trojan-activity; sid:100001417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.24",nocase; classtype:trojan-activity; sid:100001418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.246",nocase; classtype:trojan-activity; sid:100001419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.27",nocase; classtype:trojan-activity; sid:100001420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.106",nocase; classtype:trojan-activity; sid:100001421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.110",nocase; classtype:trojan-activity; sid:100001422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.120",nocase; classtype:trojan-activity; sid:100001423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.140",nocase; classtype:trojan-activity; sid:100001424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.151",nocase; classtype:trojan-activity; sid:100001425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.155",nocase; classtype:trojan-activity; sid:100001426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.16",nocase; classtype:trojan-activity; sid:100001427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.199",nocase; classtype:trojan-activity; sid:100001428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.206",nocase; classtype:trojan-activity; sid:100001429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.239",nocase; classtype:trojan-activity; sid:100001430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.49",nocase; classtype:trojan-activity; sid:100001431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.122",nocase; classtype:trojan-activity; sid:100001432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.125",nocase; classtype:trojan-activity; sid:100001433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.146",nocase; classtype:trojan-activity; sid:100001434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.197",nocase; classtype:trojan-activity; sid:100001435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.217",nocase; classtype:trojan-activity; sid:100001436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.240",nocase; classtype:trojan-activity; sid:100001437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.245",nocase; classtype:trojan-activity; sid:100001438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.248",nocase; classtype:trojan-activity; sid:100001439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.104",nocase; classtype:trojan-activity; sid:100001440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.106",nocase; classtype:trojan-activity; sid:100001441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.118",nocase; classtype:trojan-activity; sid:100001442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.149",nocase; classtype:trojan-activity; sid:100001443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.18",nocase; classtype:trojan-activity; sid:100001444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.193",nocase; classtype:trojan-activity; sid:100001445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.36",nocase; classtype:trojan-activity; sid:100001446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.37",nocase; classtype:trojan-activity; sid:100001447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.77",nocase; classtype:trojan-activity; sid:100001448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.83",nocase; classtype:trojan-activity; sid:100001449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.0",nocase; classtype:trojan-activity; sid:100001450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.133",nocase; classtype:trojan-activity; sid:100001451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.149",nocase; classtype:trojan-activity; sid:100001452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.240",nocase; classtype:trojan-activity; sid:100001453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.245",nocase; classtype:trojan-activity; sid:100001454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.83",nocase; classtype:trojan-activity; sid:100001455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.65",nocase; classtype:trojan-activity; sid:100001456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.87",nocase; classtype:trojan-activity; sid:100001457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.94",nocase; classtype:trojan-activity; sid:100001458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.132",nocase; classtype:trojan-activity; sid:100001459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.140",nocase; classtype:trojan-activity; sid:100001460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.227",nocase; classtype:trojan-activity; sid:100001461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.37",nocase; classtype:trojan-activity; sid:100001462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.77",nocase; classtype:trojan-activity; sid:100001463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.155",nocase; classtype:trojan-activity; sid:100001464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.165",nocase; classtype:trojan-activity; sid:100001465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.176",nocase; classtype:trojan-activity; sid:100001466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.204",nocase; classtype:trojan-activity; sid:100001467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.241",nocase; classtype:trojan-activity; sid:100001468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.57",nocase; classtype:trojan-activity; sid:100001469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.6",nocase; classtype:trojan-activity; sid:100001470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.155",nocase; classtype:trojan-activity; sid:100001471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.169",nocase; classtype:trojan-activity; sid:100001472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.194",nocase; classtype:trojan-activity; sid:100001473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.197",nocase; classtype:trojan-activity; sid:100001474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.198",nocase; classtype:trojan-activity; sid:100001475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.221",nocase; classtype:trojan-activity; sid:100001476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.105",nocase; classtype:trojan-activity; sid:100001477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.159",nocase; classtype:trojan-activity; sid:100001478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.187",nocase; classtype:trojan-activity; sid:100001479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.190",nocase; classtype:trojan-activity; sid:100001480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.195",nocase; classtype:trojan-activity; sid:100001481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.206",nocase; classtype:trojan-activity; sid:100001482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.98",nocase; classtype:trojan-activity; sid:100001483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.139",nocase; classtype:trojan-activity; sid:100001484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.147",nocase; classtype:trojan-activity; sid:100001485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.159",nocase; classtype:trojan-activity; sid:100001486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.4",nocase; classtype:trojan-activity; sid:100001487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.46",nocase; classtype:trojan-activity; sid:100001488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.85",nocase; classtype:trojan-activity; sid:100001489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.200",nocase; classtype:trojan-activity; sid:100001490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.254",nocase; classtype:trojan-activity; sid:100001491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.55",nocase; classtype:trojan-activity; sid:100001492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.63",nocase; classtype:trojan-activity; sid:100001493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.90",nocase; classtype:trojan-activity; sid:100001494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.99",nocase; classtype:trojan-activity; sid:100001495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.147",nocase; classtype:trojan-activity; sid:100001496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.175",nocase; classtype:trojan-activity; sid:100001497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.206",nocase; classtype:trojan-activity; sid:100001498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.208",nocase; classtype:trojan-activity; sid:100001499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.88",nocase; classtype:trojan-activity; sid:100001500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.101",nocase; classtype:trojan-activity; sid:100001501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.170",nocase; classtype:trojan-activity; sid:100001502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.188",nocase; classtype:trojan-activity; sid:100001503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.227",nocase; classtype:trojan-activity; sid:100001504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.48",nocase; classtype:trojan-activity; sid:100001505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.64",nocase; classtype:trojan-activity; sid:100001506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.12",nocase; classtype:trojan-activity; sid:100001507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.39",nocase; classtype:trojan-activity; sid:100001508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.112",nocase; classtype:trojan-activity; sid:100001509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.113",nocase; classtype:trojan-activity; sid:100001510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.192",nocase; classtype:trojan-activity; sid:100001511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.198",nocase; classtype:trojan-activity; sid:100001512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.47",nocase; classtype:trojan-activity; sid:100001513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.215",nocase; classtype:trojan-activity; sid:100001514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.237",nocase; classtype:trojan-activity; sid:100001515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.26",nocase; classtype:trojan-activity; sid:100001516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.56",nocase; classtype:trojan-activity; sid:100001517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.73",nocase; classtype:trojan-activity; sid:100001518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.86",nocase; classtype:trojan-activity; sid:100001519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.138",nocase; classtype:trojan-activity; sid:100001520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.151",nocase; classtype:trojan-activity; sid:100001521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.40",nocase; classtype:trojan-activity; sid:100001522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.53",nocase; classtype:trojan-activity; sid:100001523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.70",nocase; classtype:trojan-activity; sid:100001524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.93",nocase; classtype:trojan-activity; sid:100001525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.97",nocase; classtype:trojan-activity; sid:100001526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.184",nocase; classtype:trojan-activity; sid:100001527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.203",nocase; classtype:trojan-activity; sid:100001528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.231",nocase; classtype:trojan-activity; sid:100001529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.4",nocase; classtype:trojan-activity; sid:100001530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.5",nocase; classtype:trojan-activity; sid:100001531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.104",nocase; classtype:trojan-activity; sid:100001532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.116",nocase; classtype:trojan-activity; sid:100001533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.123",nocase; classtype:trojan-activity; sid:100001534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.155",nocase; classtype:trojan-activity; sid:100001535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.19",nocase; classtype:trojan-activity; sid:100001536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.192",nocase; classtype:trojan-activity; sid:100001537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.193",nocase; classtype:trojan-activity; sid:100001538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.229",nocase; classtype:trojan-activity; sid:100001539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.199",nocase; classtype:trojan-activity; sid:100001540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.201",nocase; classtype:trojan-activity; sid:100001541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.208",nocase; classtype:trojan-activity; sid:100001542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.217",nocase; classtype:trojan-activity; sid:100001543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.245",nocase; classtype:trojan-activity; sid:100001544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.26",nocase; classtype:trojan-activity; sid:100001545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.28",nocase; classtype:trojan-activity; sid:100001546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.191",nocase; classtype:trojan-activity; sid:100001547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.2",nocase; classtype:trojan-activity; sid:100001548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.26",nocase; classtype:trojan-activity; sid:100001549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.30",nocase; classtype:trojan-activity; sid:100001550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.56",nocase; classtype:trojan-activity; sid:100001551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.7",nocase; classtype:trojan-activity; sid:100001552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.90",nocase; classtype:trojan-activity; sid:100001553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.109",nocase; classtype:trojan-activity; sid:100001554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.122",nocase; classtype:trojan-activity; sid:100001555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.197",nocase; classtype:trojan-activity; sid:100001556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.4",nocase; classtype:trojan-activity; sid:100001557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.79",nocase; classtype:trojan-activity; sid:100001558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.89",nocase; classtype:trojan-activity; sid:100001559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.14",nocase; classtype:trojan-activity; sid:100001560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.153",nocase; classtype:trojan-activity; sid:100001561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.56",nocase; classtype:trojan-activity; sid:100001562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.167",nocase; classtype:trojan-activity; sid:100001563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.220",nocase; classtype:trojan-activity; sid:100001564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.222",nocase; classtype:trojan-activity; sid:100001565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.237",nocase; classtype:trojan-activity; sid:100001566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.61",nocase; classtype:trojan-activity; sid:100001567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.62",nocase; classtype:trojan-activity; sid:100001568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.83",nocase; classtype:trojan-activity; sid:100001569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.93",nocase; classtype:trojan-activity; sid:100001570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.10",nocase; classtype:trojan-activity; sid:100001571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.122",nocase; classtype:trojan-activity; sid:100001572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.15",nocase; classtype:trojan-activity; sid:100001573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.159",nocase; classtype:trojan-activity; sid:100001574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.166",nocase; classtype:trojan-activity; sid:100001575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.168",nocase; classtype:trojan-activity; sid:100001576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.176",nocase; classtype:trojan-activity; sid:100001577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.219",nocase; classtype:trojan-activity; sid:100001578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.230",nocase; classtype:trojan-activity; sid:100001579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.231",nocase; classtype:trojan-activity; sid:100001580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.236",nocase; classtype:trojan-activity; sid:100001581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.43",nocase; classtype:trojan-activity; sid:100001582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.63",nocase; classtype:trojan-activity; sid:100001583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.64",nocase; classtype:trojan-activity; sid:100001584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.75",nocase; classtype:trojan-activity; sid:100001585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.97",nocase; classtype:trojan-activity; sid:100001586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.19",nocase; classtype:trojan-activity; sid:100001587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.220",nocase; classtype:trojan-activity; sid:100001588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.237",nocase; classtype:trojan-activity; sid:100001589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.131",nocase; classtype:trojan-activity; sid:100001590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.178",nocase; classtype:trojan-activity; sid:100001591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.230",nocase; classtype:trojan-activity; sid:100001592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.60",nocase; classtype:trojan-activity; sid:100001593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.69",nocase; classtype:trojan-activity; sid:100001594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.166",nocase; classtype:trojan-activity; sid:100001595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.199",nocase; classtype:trojan-activity; sid:100001596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.215",nocase; classtype:trojan-activity; sid:100001597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.217",nocase; classtype:trojan-activity; sid:100001598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.35",nocase; classtype:trojan-activity; sid:100001599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.45",nocase; classtype:trojan-activity; sid:100001600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.5",nocase; classtype:trojan-activity; sid:100001601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.1",nocase; classtype:trojan-activity; sid:100001602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.108",nocase; classtype:trojan-activity; sid:100001603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.114",nocase; classtype:trojan-activity; sid:100001604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.123",nocase; classtype:trojan-activity; sid:100001605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.179",nocase; classtype:trojan-activity; sid:100001606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.221",nocase; classtype:trojan-activity; sid:100001607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.49",nocase; classtype:trojan-activity; sid:100001608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.73",nocase; classtype:trojan-activity; sid:100001609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.97",nocase; classtype:trojan-activity; sid:100001610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.118",nocase; classtype:trojan-activity; sid:100001611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.245",nocase; classtype:trojan-activity; sid:100001612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.66",nocase; classtype:trojan-activity; sid:100001613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.163",nocase; classtype:trojan-activity; sid:100001614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.174",nocase; classtype:trojan-activity; sid:100001615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.229",nocase; classtype:trojan-activity; sid:100001616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.44",nocase; classtype:trojan-activity; sid:100001617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.108",nocase; classtype:trojan-activity; sid:100001618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.110",nocase; classtype:trojan-activity; sid:100001619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.123",nocase; classtype:trojan-activity; sid:100001620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.186",nocase; classtype:trojan-activity; sid:100001621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.188",nocase; classtype:trojan-activity; sid:100001622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.237",nocase; classtype:trojan-activity; sid:100001623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.41",nocase; classtype:trojan-activity; sid:100001624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.47",nocase; classtype:trojan-activity; sid:100001625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.5",nocase; classtype:trojan-activity; sid:100001626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.54",nocase; classtype:trojan-activity; sid:100001627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.117",nocase; classtype:trojan-activity; sid:100001628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.170",nocase; classtype:trojan-activity; sid:100001629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.237",nocase; classtype:trojan-activity; sid:100001630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.24",nocase; classtype:trojan-activity; sid:100001631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.70",nocase; classtype:trojan-activity; sid:100001632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.97",nocase; classtype:trojan-activity; sid:100001633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.149",nocase; classtype:trojan-activity; sid:100001634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.184",nocase; classtype:trojan-activity; sid:100001635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.233",nocase; classtype:trojan-activity; sid:100001636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.238",nocase; classtype:trojan-activity; sid:100001637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.28",nocase; classtype:trojan-activity; sid:100001638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.76",nocase; classtype:trojan-activity; sid:100001639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.8",nocase; classtype:trojan-activity; sid:100001640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.110",nocase; classtype:trojan-activity; sid:100001641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.147",nocase; classtype:trojan-activity; sid:100001642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.237",nocase; classtype:trojan-activity; sid:100001643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.247",nocase; classtype:trojan-activity; sid:100001644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.156",nocase; classtype:trojan-activity; sid:100001645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.228",nocase; classtype:trojan-activity; sid:100001646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.250",nocase; classtype:trojan-activity; sid:100001647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.36",nocase; classtype:trojan-activity; sid:100001648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.138",nocase; classtype:trojan-activity; sid:100001649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.170",nocase; classtype:trojan-activity; sid:100001650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.171",nocase; classtype:trojan-activity; sid:100001651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.172",nocase; classtype:trojan-activity; sid:100001652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.177",nocase; classtype:trojan-activity; sid:100001653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.198",nocase; classtype:trojan-activity; sid:100001654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.218",nocase; classtype:trojan-activity; sid:100001655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.238",nocase; classtype:trojan-activity; sid:100001656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.243",nocase; classtype:trojan-activity; sid:100001657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.77",nocase; classtype:trojan-activity; sid:100001658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.113",nocase; classtype:trojan-activity; sid:100001659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.117",nocase; classtype:trojan-activity; sid:100001660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.148",nocase; classtype:trojan-activity; sid:100001661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.177",nocase; classtype:trojan-activity; sid:100001662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.28",nocase; classtype:trojan-activity; sid:100001663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.46",nocase; classtype:trojan-activity; sid:100001664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.56",nocase; classtype:trojan-activity; sid:100001665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.75",nocase; classtype:trojan-activity; sid:100001666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.77",nocase; classtype:trojan-activity; sid:100001667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.112",nocase; classtype:trojan-activity; sid:100001668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.116",nocase; classtype:trojan-activity; sid:100001669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.165",nocase; classtype:trojan-activity; sid:100001670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.209",nocase; classtype:trojan-activity; sid:100001671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.215",nocase; classtype:trojan-activity; sid:100001672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.219",nocase; classtype:trojan-activity; sid:100001673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.224",nocase; classtype:trojan-activity; sid:100001674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.246",nocase; classtype:trojan-activity; sid:100001675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.34",nocase; classtype:trojan-activity; sid:100001676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.106",nocase; classtype:trojan-activity; sid:100001677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.137",nocase; classtype:trojan-activity; sid:100001678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.138",nocase; classtype:trojan-activity; sid:100001679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.14",nocase; classtype:trojan-activity; sid:100001680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.167",nocase; classtype:trojan-activity; sid:100001681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.171",nocase; classtype:trojan-activity; sid:100001682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.177",nocase; classtype:trojan-activity; sid:100001683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.179",nocase; classtype:trojan-activity; sid:100001684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.199",nocase; classtype:trojan-activity; sid:100001685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.215",nocase; classtype:trojan-activity; sid:100001686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.225",nocase; classtype:trojan-activity; sid:100001687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.233",nocase; classtype:trojan-activity; sid:100001688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.239",nocase; classtype:trojan-activity; sid:100001689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.244",nocase; classtype:trojan-activity; sid:100001690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.32",nocase; classtype:trojan-activity; sid:100001691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.37",nocase; classtype:trojan-activity; sid:100001692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.46",nocase; classtype:trojan-activity; sid:100001693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.48",nocase; classtype:trojan-activity; sid:100001694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.69",nocase; classtype:trojan-activity; sid:100001695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.102",nocase; classtype:trojan-activity; sid:100001696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.199",nocase; classtype:trojan-activity; sid:100001697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.200",nocase; classtype:trojan-activity; sid:100001698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.51",nocase; classtype:trojan-activity; sid:100001699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.69",nocase; classtype:trojan-activity; sid:100001700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.16",nocase; classtype:trojan-activity; sid:100001701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.173",nocase; classtype:trojan-activity; sid:100001702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.174",nocase; classtype:trojan-activity; sid:100001703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.2",nocase; classtype:trojan-activity; sid:100001704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.201",nocase; classtype:trojan-activity; sid:100001705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.207",nocase; classtype:trojan-activity; sid:100001706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.208",nocase; classtype:trojan-activity; sid:100001707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.220",nocase; classtype:trojan-activity; sid:100001708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.7",nocase; classtype:trojan-activity; sid:100001709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.116",nocase; classtype:trojan-activity; sid:100001710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.166",nocase; classtype:trojan-activity; sid:100001711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.172",nocase; classtype:trojan-activity; sid:100001712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.190",nocase; classtype:trojan-activity; sid:100001713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.196",nocase; classtype:trojan-activity; sid:100001714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.214",nocase; classtype:trojan-activity; sid:100001715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.66",nocase; classtype:trojan-activity; sid:100001716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.87",nocase; classtype:trojan-activity; sid:100001717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.0",nocase; classtype:trojan-activity; sid:100001718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.135",nocase; classtype:trojan-activity; sid:100001719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.213",nocase; classtype:trojan-activity; sid:100001720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.70",nocase; classtype:trojan-activity; sid:100001721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.93",nocase; classtype:trojan-activity; sid:100001722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.96",nocase; classtype:trojan-activity; sid:100001723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.171",nocase; classtype:trojan-activity; sid:100001724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.251",nocase; classtype:trojan-activity; sid:100001725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.252",nocase; classtype:trojan-activity; sid:100001726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.6",nocase; classtype:trojan-activity; sid:100001727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.99",nocase; classtype:trojan-activity; sid:100001728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.14",nocase; classtype:trojan-activity; sid:100001729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.197",nocase; classtype:trojan-activity; sid:100001730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.198",nocase; classtype:trojan-activity; sid:100001731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.2",nocase; classtype:trojan-activity; sid:100001732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.20",nocase; classtype:trojan-activity; sid:100001733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.211",nocase; classtype:trojan-activity; sid:100001734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.229",nocase; classtype:trojan-activity; sid:100001735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.243",nocase; classtype:trojan-activity; sid:100001736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.244",nocase; classtype:trojan-activity; sid:100001737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.89",nocase; classtype:trojan-activity; sid:100001738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.112",nocase; classtype:trojan-activity; sid:100001739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.141",nocase; classtype:trojan-activity; sid:100001740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.162",nocase; classtype:trojan-activity; sid:100001741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.173",nocase; classtype:trojan-activity; sid:100001742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.181",nocase; classtype:trojan-activity; sid:100001743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.196",nocase; classtype:trojan-activity; sid:100001744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.208",nocase; classtype:trojan-activity; sid:100001745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.21",nocase; classtype:trojan-activity; sid:100001746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.215",nocase; classtype:trojan-activity; sid:100001747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.228",nocase; classtype:trojan-activity; sid:100001748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.234",nocase; classtype:trojan-activity; sid:100001749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.245",nocase; classtype:trojan-activity; sid:100001750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.26",nocase; classtype:trojan-activity; sid:100001751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.1",nocase; classtype:trojan-activity; sid:100001752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.2",nocase; classtype:trojan-activity; sid:100001753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.200",nocase; classtype:trojan-activity; sid:100001754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.53",nocase; classtype:trojan-activity; sid:100001755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.21",nocase; classtype:trojan-activity; sid:100001756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.38",nocase; classtype:trojan-activity; sid:100001757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.83",nocase; classtype:trojan-activity; sid:100001758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.91",nocase; classtype:trojan-activity; sid:100001759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.0",nocase; classtype:trojan-activity; sid:100001760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.127",nocase; classtype:trojan-activity; sid:100001761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.129",nocase; classtype:trojan-activity; sid:100001762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.184",nocase; classtype:trojan-activity; sid:100001763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.218",nocase; classtype:trojan-activity; sid:100001764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.231",nocase; classtype:trojan-activity; sid:100001765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.245",nocase; classtype:trojan-activity; sid:100001766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.33",nocase; classtype:trojan-activity; sid:100001767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.5",nocase; classtype:trojan-activity; sid:100001768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.107",nocase; classtype:trojan-activity; sid:100001769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.135",nocase; classtype:trojan-activity; sid:100001770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.153",nocase; classtype:trojan-activity; sid:100001771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.223",nocase; classtype:trojan-activity; sid:100001772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.26",nocase; classtype:trojan-activity; sid:100001773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.38",nocase; classtype:trojan-activity; sid:100001774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.56",nocase; classtype:trojan-activity; sid:100001775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.6",nocase; classtype:trojan-activity; sid:100001776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.71",nocase; classtype:trojan-activity; sid:100001777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.81",nocase; classtype:trojan-activity; sid:100001778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.83",nocase; classtype:trojan-activity; sid:100001779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.1",nocase; classtype:trojan-activity; sid:100001780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.132",nocase; classtype:trojan-activity; sid:100001781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.165",nocase; classtype:trojan-activity; sid:100001782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.98",nocase; classtype:trojan-activity; sid:100001783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.110",nocase; classtype:trojan-activity; sid:100001784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.129",nocase; classtype:trojan-activity; sid:100001785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.158",nocase; classtype:trojan-activity; sid:100001786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.245",nocase; classtype:trojan-activity; sid:100001787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.57",nocase; classtype:trojan-activity; sid:100001788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.63",nocase; classtype:trojan-activity; sid:100001789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.144",nocase; classtype:trojan-activity; sid:100001790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.192",nocase; classtype:trojan-activity; sid:100001791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.219",nocase; classtype:trojan-activity; sid:100001792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.231",nocase; classtype:trojan-activity; sid:100001793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.233",nocase; classtype:trojan-activity; sid:100001794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.95",nocase; classtype:trojan-activity; sid:100001795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.155",nocase; classtype:trojan-activity; sid:100001796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.226",nocase; classtype:trojan-activity; sid:100001797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.228",nocase; classtype:trojan-activity; sid:100001798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.41",nocase; classtype:trojan-activity; sid:100001799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.56",nocase; classtype:trojan-activity; sid:100001800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.67",nocase; classtype:trojan-activity; sid:100001801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.82",nocase; classtype:trojan-activity; sid:100001802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.203",nocase; classtype:trojan-activity; sid:100001803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.34",nocase; classtype:trojan-activity; sid:100001804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.171",nocase; classtype:trojan-activity; sid:100001805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.228",nocase; classtype:trojan-activity; sid:100001806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.240",nocase; classtype:trojan-activity; sid:100001807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.25",nocase; classtype:trojan-activity; sid:100001808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.1",nocase; classtype:trojan-activity; sid:100001809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.106",nocase; classtype:trojan-activity; sid:100001810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.121",nocase; classtype:trojan-activity; sid:100001811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.138",nocase; classtype:trojan-activity; sid:100001812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.147",nocase; classtype:trojan-activity; sid:100001813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.30",nocase; classtype:trojan-activity; sid:100001814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.33",nocase; classtype:trojan-activity; sid:100001815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.69",nocase; classtype:trojan-activity; sid:100001816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.0",nocase; classtype:trojan-activity; sid:100001817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.134",nocase; classtype:trojan-activity; sid:100001818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.143",nocase; classtype:trojan-activity; sid:100001819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.155",nocase; classtype:trojan-activity; sid:100001820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.197",nocase; classtype:trojan-activity; sid:100001821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.217",nocase; classtype:trojan-activity; sid:100001822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.22",nocase; classtype:trojan-activity; sid:100001823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.241",nocase; classtype:trojan-activity; sid:100001824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.70",nocase; classtype:trojan-activity; sid:100001825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.89",nocase; classtype:trojan-activity; sid:100001826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.90",nocase; classtype:trojan-activity; sid:100001827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.95",nocase; classtype:trojan-activity; sid:100001828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.205",nocase; classtype:trojan-activity; sid:100001829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.25",nocase; classtype:trojan-activity; sid:100001830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.6",nocase; classtype:trojan-activity; sid:100001831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.119",nocase; classtype:trojan-activity; sid:100001832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.187",nocase; classtype:trojan-activity; sid:100001833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.224",nocase; classtype:trojan-activity; sid:100001834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.42",nocase; classtype:trojan-activity; sid:100001835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.11",nocase; classtype:trojan-activity; sid:100001836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.141",nocase; classtype:trojan-activity; sid:100001837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.151",nocase; classtype:trojan-activity; sid:100001838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.16",nocase; classtype:trojan-activity; sid:100001839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.168",nocase; classtype:trojan-activity; sid:100001840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.245",nocase; classtype:trojan-activity; sid:100001841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.110",nocase; classtype:trojan-activity; sid:100001842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.168",nocase; classtype:trojan-activity; sid:100001843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.139",nocase; classtype:trojan-activity; sid:100001844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.214",nocase; classtype:trojan-activity; sid:100001845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.247",nocase; classtype:trojan-activity; sid:100001846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.252",nocase; classtype:trojan-activity; sid:100001847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.3",nocase; classtype:trojan-activity; sid:100001848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.17",nocase; classtype:trojan-activity; sid:100001849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.51",nocase; classtype:trojan-activity; sid:100001850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.79",nocase; classtype:trojan-activity; sid:100001851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.131",nocase; classtype:trojan-activity; sid:100001852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.168",nocase; classtype:trojan-activity; sid:100001853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.177",nocase; classtype:trojan-activity; sid:100001854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.22",nocase; classtype:trojan-activity; sid:100001855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.236",nocase; classtype:trojan-activity; sid:100001856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.237",nocase; classtype:trojan-activity; sid:100001857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.32",nocase; classtype:trojan-activity; sid:100001858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.137",nocase; classtype:trojan-activity; sid:100001859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.160",nocase; classtype:trojan-activity; sid:100001860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.202",nocase; classtype:trojan-activity; sid:100001861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.66",nocase; classtype:trojan-activity; sid:100001862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.146",nocase; classtype:trojan-activity; sid:100001863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.161",nocase; classtype:trojan-activity; sid:100001864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.21",nocase; classtype:trojan-activity; sid:100001865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.212",nocase; classtype:trojan-activity; sid:100001866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.94",nocase; classtype:trojan-activity; sid:100001867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.135",nocase; classtype:trojan-activity; sid:100001868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.151",nocase; classtype:trojan-activity; sid:100001869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.186",nocase; classtype:trojan-activity; sid:100001870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.217",nocase; classtype:trojan-activity; sid:100001871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.4",nocase; classtype:trojan-activity; sid:100001872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.5",nocase; classtype:trojan-activity; sid:100001873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.56",nocase; classtype:trojan-activity; sid:100001874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.58",nocase; classtype:trojan-activity; sid:100001875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.79",nocase; classtype:trojan-activity; sid:100001876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.15",nocase; classtype:trojan-activity; sid:100001877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.158",nocase; classtype:trojan-activity; sid:100001878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.163",nocase; classtype:trojan-activity; sid:100001879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.167",nocase; classtype:trojan-activity; sid:100001880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.205",nocase; classtype:trojan-activity; sid:100001881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.225",nocase; classtype:trojan-activity; sid:100001882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.64",nocase; classtype:trojan-activity; sid:100001883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.103",nocase; classtype:trojan-activity; sid:100001884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.14",nocase; classtype:trojan-activity; sid:100001885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.163",nocase; classtype:trojan-activity; sid:100001886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.25",nocase; classtype:trojan-activity; sid:100001887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.29",nocase; classtype:trojan-activity; sid:100001888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.38",nocase; classtype:trojan-activity; sid:100001889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.41",nocase; classtype:trojan-activity; sid:100001890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.47",nocase; classtype:trojan-activity; sid:100001891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.77",nocase; classtype:trojan-activity; sid:100001892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.103",nocase; classtype:trojan-activity; sid:100001893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.11",nocase; classtype:trojan-activity; sid:100001894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.120",nocase; classtype:trojan-activity; sid:100001895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.24",nocase; classtype:trojan-activity; sid:100001896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.252",nocase; classtype:trojan-activity; sid:100001897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.33",nocase; classtype:trojan-activity; sid:100001898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.37",nocase; classtype:trojan-activity; sid:100001899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.50",nocase; classtype:trojan-activity; sid:100001900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.52",nocase; classtype:trojan-activity; sid:100001901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.54",nocase; classtype:trojan-activity; sid:100001902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.72",nocase; classtype:trojan-activity; sid:100001903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.75",nocase; classtype:trojan-activity; sid:100001904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.10",nocase; classtype:trojan-activity; sid:100001905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.141",nocase; classtype:trojan-activity; sid:100001906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.179",nocase; classtype:trojan-activity; sid:100001907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.99",nocase; classtype:trojan-activity; sid:100001908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.28",nocase; classtype:trojan-activity; sid:100001909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.74",nocase; classtype:trojan-activity; sid:100001910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.79",nocase; classtype:trojan-activity; sid:100001911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.161",nocase; classtype:trojan-activity; sid:100001912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.241",nocase; classtype:trojan-activity; sid:100001913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.33",nocase; classtype:trojan-activity; sid:100001914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.54",nocase; classtype:trojan-activity; sid:100001915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.134",nocase; classtype:trojan-activity; sid:100001916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.157",nocase; classtype:trojan-activity; sid:100001917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.189",nocase; classtype:trojan-activity; sid:100001918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.89",nocase; classtype:trojan-activity; sid:100001919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.209",nocase; classtype:trojan-activity; sid:100001920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.212",nocase; classtype:trojan-activity; sid:100001921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.76",nocase; classtype:trojan-activity; sid:100001922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.156",nocase; classtype:trojan-activity; sid:100001923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.163",nocase; classtype:trojan-activity; sid:100001924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.17",nocase; classtype:trojan-activity; sid:100001925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.171",nocase; classtype:trojan-activity; sid:100001926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.178",nocase; classtype:trojan-activity; sid:100001927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.219",nocase; classtype:trojan-activity; sid:100001928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.237",nocase; classtype:trojan-activity; sid:100001929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.95",nocase; classtype:trojan-activity; sid:100001930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.111",nocase; classtype:trojan-activity; sid:100001931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.115",nocase; classtype:trojan-activity; sid:100001932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.141",nocase; classtype:trojan-activity; sid:100001933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.166",nocase; classtype:trojan-activity; sid:100001934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.168",nocase; classtype:trojan-activity; sid:100001935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.42",nocase; classtype:trojan-activity; sid:100001936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.43",nocase; classtype:trojan-activity; sid:100001937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.70",nocase; classtype:trojan-activity; sid:100001938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.8",nocase; classtype:trojan-activity; sid:100001939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.84",nocase; classtype:trojan-activity; sid:100001940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.192",nocase; classtype:trojan-activity; sid:100001941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.21",nocase; classtype:trojan-activity; sid:100001942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.230",nocase; classtype:trojan-activity; sid:100001943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.78",nocase; classtype:trojan-activity; sid:100001944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.96",nocase; classtype:trojan-activity; sid:100001945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.12",nocase; classtype:trojan-activity; sid:100001946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.155",nocase; classtype:trojan-activity; sid:100001947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.156",nocase; classtype:trojan-activity; sid:100001948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.158",nocase; classtype:trojan-activity; sid:100001949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.187",nocase; classtype:trojan-activity; sid:100001950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.190",nocase; classtype:trojan-activity; sid:100001951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.22",nocase; classtype:trojan-activity; sid:100001952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.231",nocase; classtype:trojan-activity; sid:100001953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.19",nocase; classtype:trojan-activity; sid:100001954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.202",nocase; classtype:trojan-activity; sid:100001955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.236",nocase; classtype:trojan-activity; sid:100001956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.186",nocase; classtype:trojan-activity; sid:100001957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.192",nocase; classtype:trojan-activity; sid:100001958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.199",nocase; classtype:trojan-activity; sid:100001959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.211",nocase; classtype:trojan-activity; sid:100001960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.228",nocase; classtype:trojan-activity; sid:100001961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.54",nocase; classtype:trojan-activity; sid:100001962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.93",nocase; classtype:trojan-activity; sid:100001963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.0",nocase; classtype:trojan-activity; sid:100001964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.36",nocase; classtype:trojan-activity; sid:100001965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.51",nocase; classtype:trojan-activity; sid:100001966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.55",nocase; classtype:trojan-activity; sid:100001967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.81",nocase; classtype:trojan-activity; sid:100001968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.83",nocase; classtype:trojan-activity; sid:100001969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.89",nocase; classtype:trojan-activity; sid:100001970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.116",nocase; classtype:trojan-activity; sid:100001971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.44",nocase; classtype:trojan-activity; sid:100001972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.66",nocase; classtype:trojan-activity; sid:100001973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.85",nocase; classtype:trojan-activity; sid:100001974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.111",nocase; classtype:trojan-activity; sid:100001975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.119",nocase; classtype:trojan-activity; sid:100001976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.128",nocase; classtype:trojan-activity; sid:100001977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.18",nocase; classtype:trojan-activity; sid:100001978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.6",nocase; classtype:trojan-activity; sid:100001979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.60",nocase; classtype:trojan-activity; sid:100001980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.71",nocase; classtype:trojan-activity; sid:100001981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.10",nocase; classtype:trojan-activity; sid:100001982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.109",nocase; classtype:trojan-activity; sid:100001983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.196",nocase; classtype:trojan-activity; sid:100001984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.218",nocase; classtype:trojan-activity; sid:100001985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.246",nocase; classtype:trojan-activity; sid:100001986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.5",nocase; classtype:trojan-activity; sid:100001987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.50",nocase; classtype:trojan-activity; sid:100001988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.71",nocase; classtype:trojan-activity; sid:100001989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.83",nocase; classtype:trojan-activity; sid:100001990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.93",nocase; classtype:trojan-activity; sid:100001991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.160",nocase; classtype:trojan-activity; sid:100001992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.45",nocase; classtype:trojan-activity; sid:100001993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.84",nocase; classtype:trojan-activity; sid:100001994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.108",nocase; classtype:trojan-activity; sid:100001995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.222",nocase; classtype:trojan-activity; sid:100001996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.30",nocase; classtype:trojan-activity; sid:100001997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.37",nocase; classtype:trojan-activity; sid:100001998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.47",nocase; classtype:trojan-activity; sid:100001999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.73.96",nocase; classtype:trojan-activity; sid:100002000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.182",nocase; classtype:trojan-activity; sid:100002001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.205",nocase; classtype:trojan-activity; sid:100002002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.48",nocase; classtype:trojan-activity; sid:100002003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.181",nocase; classtype:trojan-activity; sid:100002004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.19",nocase; classtype:trojan-activity; sid:100002005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.84",nocase; classtype:trojan-activity; sid:100002006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.87",nocase; classtype:trojan-activity; sid:100002007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.103",nocase; classtype:trojan-activity; sid:100002008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.109",nocase; classtype:trojan-activity; sid:100002009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.209",nocase; classtype:trojan-activity; sid:100002010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.21",nocase; classtype:trojan-activity; sid:100002011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.217",nocase; classtype:trojan-activity; sid:100002012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.83",nocase; classtype:trojan-activity; sid:100002013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.9",nocase; classtype:trojan-activity; sid:100002014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.248",nocase; classtype:trojan-activity; sid:100002015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.34",nocase; classtype:trojan-activity; sid:100002016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.46",nocase; classtype:trojan-activity; sid:100002017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.47",nocase; classtype:trojan-activity; sid:100002018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.198",nocase; classtype:trojan-activity; sid:100002019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.243",nocase; classtype:trojan-activity; sid:100002020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.57",nocase; classtype:trojan-activity; sid:100002021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.97",nocase; classtype:trojan-activity; sid:100002022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.17",nocase; classtype:trojan-activity; sid:100002023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.244",nocase; classtype:trojan-activity; sid:100002024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.247",nocase; classtype:trojan-activity; sid:100002025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.69",nocase; classtype:trojan-activity; sid:100002026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.100",nocase; classtype:trojan-activity; sid:100002027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.227",nocase; classtype:trojan-activity; sid:100002028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.64",nocase; classtype:trojan-activity; sid:100002029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.100",nocase; classtype:trojan-activity; sid:100002030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.129",nocase; classtype:trojan-activity; sid:100002031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.197",nocase; classtype:trojan-activity; sid:100002032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.20",nocase; classtype:trojan-activity; sid:100002033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.41",nocase; classtype:trojan-activity; sid:100002034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.61",nocase; classtype:trojan-activity; sid:100002035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.68",nocase; classtype:trojan-activity; sid:100002036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.79",nocase; classtype:trojan-activity; sid:100002037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.86",nocase; classtype:trojan-activity; sid:100002038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.89",nocase; classtype:trojan-activity; sid:100002039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.19",nocase; classtype:trojan-activity; sid:100002040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.192",nocase; classtype:trojan-activity; sid:100002041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.226",nocase; classtype:trojan-activity; sid:100002042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.232",nocase; classtype:trojan-activity; sid:100002043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.244",nocase; classtype:trojan-activity; sid:100002044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.253",nocase; classtype:trojan-activity; sid:100002045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.82.23",nocase; classtype:trojan-activity; sid:100002046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.82.73",nocase; classtype:trojan-activity; sid:100002047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.144",nocase; classtype:trojan-activity; sid:100002048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.2",nocase; classtype:trojan-activity; sid:100002049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.20",nocase; classtype:trojan-activity; sid:100002050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.247",nocase; classtype:trojan-activity; sid:100002051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.102",nocase; classtype:trojan-activity; sid:100002052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.159",nocase; classtype:trojan-activity; sid:100002053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.17",nocase; classtype:trojan-activity; sid:100002054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.215",nocase; classtype:trojan-activity; sid:100002055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.28",nocase; classtype:trojan-activity; sid:100002056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.42",nocase; classtype:trojan-activity; sid:100002057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.153",nocase; classtype:trojan-activity; sid:100002058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.183",nocase; classtype:trojan-activity; sid:100002059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.23",nocase; classtype:trojan-activity; sid:100002060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.230",nocase; classtype:trojan-activity; sid:100002061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.57",nocase; classtype:trojan-activity; sid:100002062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.119",nocase; classtype:trojan-activity; sid:100002063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.122",nocase; classtype:trojan-activity; sid:100002064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.36",nocase; classtype:trojan-activity; sid:100002065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.59",nocase; classtype:trojan-activity; sid:100002066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.126",nocase; classtype:trojan-activity; sid:100002067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.139",nocase; classtype:trojan-activity; sid:100002068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.144",nocase; classtype:trojan-activity; sid:100002069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.253",nocase; classtype:trojan-activity; sid:100002070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.160",nocase; classtype:trojan-activity; sid:100002071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.166",nocase; classtype:trojan-activity; sid:100002072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.181",nocase; classtype:trojan-activity; sid:100002073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.182",nocase; classtype:trojan-activity; sid:100002074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.24",nocase; classtype:trojan-activity; sid:100002075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.248",nocase; classtype:trojan-activity; sid:100002076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.69",nocase; classtype:trojan-activity; sid:100002077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.157",nocase; classtype:trojan-activity; sid:100002078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.169",nocase; classtype:trojan-activity; sid:100002079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.30",nocase; classtype:trojan-activity; sid:100002080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.125",nocase; classtype:trojan-activity; sid:100002081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.139",nocase; classtype:trojan-activity; sid:100002082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.175",nocase; classtype:trojan-activity; sid:100002083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.179",nocase; classtype:trojan-activity; sid:100002084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.198",nocase; classtype:trojan-activity; sid:100002085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.210",nocase; classtype:trojan-activity; sid:100002086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.215",nocase; classtype:trojan-activity; sid:100002087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.225",nocase; classtype:trojan-activity; sid:100002088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.64",nocase; classtype:trojan-activity; sid:100002089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.84",nocase; classtype:trojan-activity; sid:100002090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.95",nocase; classtype:trojan-activity; sid:100002091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.122",nocase; classtype:trojan-activity; sid:100002092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.167",nocase; classtype:trojan-activity; sid:100002093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.172",nocase; classtype:trojan-activity; sid:100002094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.185",nocase; classtype:trojan-activity; sid:100002095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.21",nocase; classtype:trojan-activity; sid:100002096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.4",nocase; classtype:trojan-activity; sid:100002097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.74",nocase; classtype:trojan-activity; sid:100002098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.81",nocase; classtype:trojan-activity; sid:100002099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.90",nocase; classtype:trojan-activity; sid:100002100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.108",nocase; classtype:trojan-activity; sid:100002101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.13",nocase; classtype:trojan-activity; sid:100002102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.15",nocase; classtype:trojan-activity; sid:100002103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.244",nocase; classtype:trojan-activity; sid:100002104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.253",nocase; classtype:trojan-activity; sid:100002105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.96",nocase; classtype:trojan-activity; sid:100002106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.132",nocase; classtype:trojan-activity; sid:100002107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.186",nocase; classtype:trojan-activity; sid:100002108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.200",nocase; classtype:trojan-activity; sid:100002109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.215",nocase; classtype:trojan-activity; sid:100002110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.231",nocase; classtype:trojan-activity; sid:100002111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.253",nocase; classtype:trojan-activity; sid:100002112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.45",nocase; classtype:trojan-activity; sid:100002113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.12",nocase; classtype:trojan-activity; sid:100002114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.143",nocase; classtype:trojan-activity; sid:100002115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.150",nocase; classtype:trojan-activity; sid:100002116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.159",nocase; classtype:trojan-activity; sid:100002117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.199",nocase; classtype:trojan-activity; sid:100002118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.44",nocase; classtype:trojan-activity; sid:100002119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.62",nocase; classtype:trojan-activity; sid:100002120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.195",nocase; classtype:trojan-activity; sid:100002121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.200",nocase; classtype:trojan-activity; sid:100002122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.27",nocase; classtype:trojan-activity; sid:100002123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.40",nocase; classtype:trojan-activity; sid:100002124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.55",nocase; classtype:trojan-activity; sid:100002125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.116",nocase; classtype:trojan-activity; sid:100002126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.141",nocase; classtype:trojan-activity; sid:100002127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.163",nocase; classtype:trojan-activity; sid:100002128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.17",nocase; classtype:trojan-activity; sid:100002129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.227",nocase; classtype:trojan-activity; sid:100002130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.4",nocase; classtype:trojan-activity; sid:100002131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.56",nocase; classtype:trojan-activity; sid:100002132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.81",nocase; classtype:trojan-activity; sid:100002133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.128",nocase; classtype:trojan-activity; sid:100002134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.135",nocase; classtype:trojan-activity; sid:100002135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.216",nocase; classtype:trojan-activity; sid:100002136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.228",nocase; classtype:trojan-activity; sid:100002137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.254",nocase; classtype:trojan-activity; sid:100002138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.29",nocase; classtype:trojan-activity; sid:100002139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.44",nocase; classtype:trojan-activity; sid:100002140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.68",nocase; classtype:trojan-activity; sid:100002141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.123",nocase; classtype:trojan-activity; sid:100002142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.130",nocase; classtype:trojan-activity; sid:100002143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.91",nocase; classtype:trojan-activity; sid:100002144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.19.183.14",nocase; classtype:trojan-activity; sid:100002145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.205.101.33",nocase; classtype:trojan-activity; sid:100002146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.21.164.68",nocase; classtype:trojan-activity; sid:100002147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.217.8.194",nocase; classtype:trojan-activity; sid:100002148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.22.117.102",nocase; classtype:trojan-activity; sid:100002149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.222.252.130",nocase; classtype:trojan-activity; sid:100002150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.34.183.30",nocase; classtype:trojan-activity; sid:100002151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.48.235.59",nocase; classtype:trojan-activity; sid:100002152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.92.246.246",nocase; classtype:trojan-activity; sid:100002153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.95.115.33",nocase; classtype:trojan-activity; sid:100002154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.95.136.35",nocase; classtype:trojan-activity; sid:100002155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.159.58.134",nocase; classtype:trojan-activity; sid:100002156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.4.187.39",nocase; classtype:trojan-activity; sid:100002157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.42.107.139",nocase; classtype:trojan-activity; sid:100002158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.43.157.173",nocase; classtype:trojan-activity; sid:100002159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.60.84.7",nocase; classtype:trojan-activity; sid:100002160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.99.210.161",nocase; classtype:trojan-activity; sid:100002161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.109.36.244",nocase; classtype:trojan-activity; sid:100002162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.111.101.141",nocase; classtype:trojan-activity; sid:100002163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.114.111.153",nocase; classtype:trojan-activity; sid:100002164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.116.203.220",nocase; classtype:trojan-activity; sid:100002165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.120.149.106",nocase; classtype:trojan-activity; sid:100002166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.122.13.227",nocase; classtype:trojan-activity; sid:100002167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.125.44.194",nocase; classtype:trojan-activity; sid:100002168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.157.66.204",nocase; classtype:trojan-activity; sid:100002169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.175.236.209",nocase; classtype:trojan-activity; sid:100002170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.105.41",nocase; classtype:trojan-activity; sid:100002171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.110.243",nocase; classtype:trojan-activity; sid:100002172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.165.230",nocase; classtype:trojan-activity; sid:100002173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.214.171",nocase; classtype:trojan-activity; sid:100002174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.34.51",nocase; classtype:trojan-activity; sid:100002175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.96.248",nocase; classtype:trojan-activity; sid:100002176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.104.65",nocase; classtype:trojan-activity; sid:100002177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.242.73",nocase; classtype:trojan-activity; sid:100002178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.218.5.171",nocase; classtype:trojan-activity; sid:100002179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.248.80.38",nocase; classtype:trojan-activity; sid:100002180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.253.99.109",nocase; classtype:trojan-activity; sid:100002181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.111.36",nocase; classtype:trojan-activity; sid:100002182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.53.93",nocase; classtype:trojan-activity; sid:100002183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.94.170.166",nocase; classtype:trojan-activity; sid:100002184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.138.154",nocase; classtype:trojan-activity; sid:100002185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.238",nocase; classtype:trojan-activity; sid:100002186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.6",nocase; classtype:trojan-activity; sid:100002187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.143.60.163",nocase; classtype:trojan-activity; sid:100002188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.193.107.10",nocase; classtype:trojan-activity; sid:100002189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.222",nocase; classtype:trojan-activity; sid:100002190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.230",nocase; classtype:trojan-activity; sid:100002191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.210.45.42",nocase; classtype:trojan-activity; sid:100002192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.215.47.82",nocase; classtype:trojan-activity; sid:100002193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.224.242.131",nocase; classtype:trojan-activity; sid:100002194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.236.4",nocase; classtype:trojan-activity; sid:100002195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.59.162",nocase; classtype:trojan-activity; sid:100002196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.28.118",nocase; classtype:trojan-activity; sid:100002197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.34.220",nocase; classtype:trojan-activity; sid:100002198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.43.249",nocase; classtype:trojan-activity; sid:100002199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.52.131",nocase; classtype:trojan-activity; sid:100002200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.238.197",nocase; classtype:trojan-activity; sid:100002201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.29.28",nocase; classtype:trojan-activity; sid:100002202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.105.40",nocase; classtype:trojan-activity; sid:100002203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.111.64",nocase; classtype:trojan-activity; sid:100002204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.64.27",nocase; classtype:trojan-activity; sid:100002205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.76.42",nocase; classtype:trojan-activity; sid:100002206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.79.103",nocase; classtype:trojan-activity; sid:100002207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.83.88",nocase; classtype:trojan-activity; sid:100002208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.92.90",nocase; classtype:trojan-activity; sid:100002209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.93.96",nocase; classtype:trojan-activity; sid:100002210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.104.106",nocase; classtype:trojan-activity; sid:100002211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.105.208",nocase; classtype:trojan-activity; sid:100002212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.108.244",nocase; classtype:trojan-activity; sid:100002213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.116.70",nocase; classtype:trojan-activity; sid:100002214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.118.250",nocase; classtype:trojan-activity; sid:100002215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.119.66",nocase; classtype:trojan-activity; sid:100002216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.36.175",nocase; classtype:trojan-activity; sid:100002217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.60.73",nocase; classtype:trojan-activity; sid:100002218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.61.252",nocase; classtype:trojan-activity; sid:100002219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.80.107",nocase; classtype:trojan-activity; sid:100002220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.94.196",nocase; classtype:trojan-activity; sid:100002221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.99.150",nocase; classtype:trojan-activity; sid:100002222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.13.57",nocase; classtype:trojan-activity; sid:100002223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.15.172",nocase; classtype:trojan-activity; sid:100002224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.25.120",nocase; classtype:trojan-activity; sid:100002225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.26.235",nocase; classtype:trojan-activity; sid:100002226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.29.220",nocase; classtype:trojan-activity; sid:100002227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.39.51",nocase; classtype:trojan-activity; sid:100002228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.43.27",nocase; classtype:trojan-activity; sid:100002229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.49.127",nocase; classtype:trojan-activity; sid:100002230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.118.146.181",nocase; classtype:trojan-activity; sid:100002231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.118.166.128",nocase; classtype:trojan-activity; sid:100002232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.100.135",nocase; classtype:trojan-activity; sid:100002233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.109.173",nocase; classtype:trojan-activity; sid:100002234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.118.218",nocase; classtype:trojan-activity; sid:100002235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.14.252",nocase; classtype:trojan-activity; sid:100002236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.15.78",nocase; classtype:trojan-activity; sid:100002237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.166.208",nocase; classtype:trojan-activity; sid:100002238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.166.76",nocase; classtype:trojan-activity; sid:100002239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.179.193",nocase; classtype:trojan-activity; sid:100002240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.197.123",nocase; classtype:trojan-activity; sid:100002241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.202.180",nocase; classtype:trojan-activity; sid:100002242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.21.68",nocase; classtype:trojan-activity; sid:100002243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.211.69",nocase; classtype:trojan-activity; sid:100002244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.214.120",nocase; classtype:trojan-activity; sid:100002245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.221.141",nocase; classtype:trojan-activity; sid:100002246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.226.84",nocase; classtype:trojan-activity; sid:100002247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.255.115",nocase; classtype:trojan-activity; sid:100002248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.7.54",nocase; classtype:trojan-activity; sid:100002249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.89.107",nocase; classtype:trojan-activity; sid:100002250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.22",nocase; classtype:trojan-activity; sid:100002251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.46",nocase; classtype:trojan-activity; sid:100002252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.37.251",nocase; classtype:trojan-activity; sid:100002253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.43.0",nocase; classtype:trojan-activity; sid:100002254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.129.163",nocase; classtype:trojan-activity; sid:100002255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.134.70",nocase; classtype:trojan-activity; sid:100002256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.15.223",nocase; classtype:trojan-activity; sid:100002257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.157.35",nocase; classtype:trojan-activity; sid:100002258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.205.201",nocase; classtype:trojan-activity; sid:100002259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.205.237",nocase; classtype:trojan-activity; sid:100002260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.207.195",nocase; classtype:trojan-activity; sid:100002261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.254.147",nocase; classtype:trojan-activity; sid:100002262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.55.106",nocase; classtype:trojan-activity; sid:100002263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.66.189",nocase; classtype:trojan-activity; sid:100002264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.9.117",nocase; classtype:trojan-activity; sid:100002265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.94.13",nocase; classtype:trojan-activity; sid:100002266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.202.18",nocase; classtype:trojan-activity; sid:100002267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.123.203.21",nocase; classtype:trojan-activity; sid:100002268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.123.211.239",nocase; classtype:trojan-activity; sid:100002269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.123.241.195",nocase; classtype:trojan-activity; sid:100002270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.123.107",nocase; classtype:trojan-activity; sid:100002271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.177.48",nocase; classtype:trojan-activity; sid:100002272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.19.87",nocase; classtype:trojan-activity; sid:100002273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.201.207",nocase; classtype:trojan-activity; sid:100002274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.88.122",nocase; classtype:trojan-activity; sid:100002275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.113.127",nocase; classtype:trojan-activity; sid:100002276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.123.19",nocase; classtype:trojan-activity; sid:100002277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.126.203",nocase; classtype:trojan-activity; sid:100002278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.127.254",nocase; classtype:trojan-activity; sid:100002279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.67.24",nocase; classtype:trojan-activity; sid:100002280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.83.79",nocase; classtype:trojan-activity; sid:100002281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.88.138",nocase; classtype:trojan-activity; sid:100002282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.0.16",nocase; classtype:trojan-activity; sid:100002283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.103.79",nocase; classtype:trojan-activity; sid:100002284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.104.235",nocase; classtype:trojan-activity; sid:100002285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.106.43",nocase; classtype:trojan-activity; sid:100002286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.152.3",nocase; classtype:trojan-activity; sid:100002287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.155.157",nocase; classtype:trojan-activity; sid:100002288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.221.243",nocase; classtype:trojan-activity; sid:100002289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.93.38",nocase; classtype:trojan-activity; sid:100002290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.160.98.250",nocase; classtype:trojan-activity; sid:100002291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.172.36.164",nocase; classtype:trojan-activity; sid:100002292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.233.0.252",nocase; classtype:trojan-activity; sid:100002293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.235.252.31",nocase; classtype:trojan-activity; sid:100002294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.53.197.62",nocase; classtype:trojan-activity; sid:100002295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.56.193.251",nocase; classtype:trojan-activity; sid:100002296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.59.235.150",nocase; classtype:trojan-activity; sid:100002297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.104.83",nocase; classtype:trojan-activity; sid:100002298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.225.154",nocase; classtype:trojan-activity; sid:100002299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.109.169.45",nocase; classtype:trojan-activity; sid:100002300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.11.238.228",nocase; classtype:trojan-activity; sid:100002301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.136.252.233",nocase; classtype:trojan-activity; sid:100002302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.150.244.122",nocase; classtype:trojan-activity; sid:100002303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.16.208.30",nocase; classtype:trojan-activity; sid:100002304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.185.112.19",nocase; classtype:trojan-activity; sid:100002305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.185.162.225",nocase; classtype:trojan-activity; sid:100002306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.187.163.176",nocase; classtype:trojan-activity; sid:100002307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.151.225",nocase; classtype:trojan-activity; sid:100002308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.180.116",nocase; classtype:trojan-activity; sid:100002309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.188.186",nocase; classtype:trojan-activity; sid:100002310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.228.38",nocase; classtype:trojan-activity; sid:100002311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.93.116",nocase; classtype:trojan-activity; sid:100002312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.105.21",nocase; classtype:trojan-activity; sid:100002313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.127.89",nocase; classtype:trojan-activity; sid:100002314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.26.115",nocase; classtype:trojan-activity; sid:100002315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.92.195.140",nocase; classtype:trojan-activity; sid:100002316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.97.22.14",nocase; classtype:trojan-activity; sid:100002317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.164.185.41",nocase; classtype:trojan-activity; sid:100002318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.175.115.10",nocase; classtype:trojan-activity; sid:100002319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.74.149.230",nocase; classtype:trojan-activity; sid:100002320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.106.209.68",nocase; classtype:trojan-activity; sid:100002321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.107.3.8",nocase; classtype:trojan-activity; sid:100002322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.172.110.235",nocase; classtype:trojan-activity; sid:100002323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.181.10.234",nocase; classtype:trojan-activity; sid:100002324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.112",nocase; classtype:trojan-activity; sid:100002325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.54",nocase; classtype:trojan-activity; sid:100002326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.77",nocase; classtype:trojan-activity; sid:100002327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.93",nocase; classtype:trojan-activity; sid:100002328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.219.133.122",nocase; classtype:trojan-activity; sid:100002329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.221.3.244",nocase; classtype:trojan-activity; sid:100002330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.228.141.74",nocase; classtype:trojan-activity; sid:100002331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.239.243.77",nocase; classtype:trojan-activity; sid:100002332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.245.96.94",nocase; classtype:trojan-activity; sid:100002333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.26.113.95",nocase; classtype:trojan-activity; sid:100002334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.34.16.231",nocase; classtype:trojan-activity; sid:100002335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.43.19.151",nocase; classtype:trojan-activity; sid:100002336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.45.103.212",nocase; classtype:trojan-activity; sid:100002337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.55.1.182",nocase; classtype:trojan-activity; sid:100002338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.68.230.207",nocase; classtype:trojan-activity; sid:100002339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.81.157.186",nocase; classtype:trojan-activity; sid:100002340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.185",nocase; classtype:trojan-activity; sid:100002341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.213",nocase; classtype:trojan-activity; sid:100002342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.160",nocase; classtype:trojan-activity; sid:100002343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.161",nocase; classtype:trojan-activity; sid:100002344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.219",nocase; classtype:trojan-activity; sid:100002345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.80",nocase; classtype:trojan-activity; sid:100002346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.90.166.56",nocase; classtype:trojan-activity; sid:100002347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.151.144.85",nocase; classtype:trojan-activity; sid:100002348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.219.164",nocase; classtype:trojan-activity; sid:100002349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.112",nocase; classtype:trojan-activity; sid:100002350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.77",nocase; classtype:trojan-activity; sid:100002351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.91",nocase; classtype:trojan-activity; sid:100002352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.253.150",nocase; classtype:trojan-activity; sid:100002353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.183.131.37",nocase; classtype:trojan-activity; sid:100002354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.225.120.173",nocase; classtype:trojan-activity; sid:100002355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.232.44.86",nocase; classtype:trojan-activity; sid:100002356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.28.60.184",nocase; classtype:trojan-activity; sid:100002357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.33.113.77",nocase; classtype:trojan-activity; sid:100002358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.4.125.48",nocase; classtype:trojan-activity; sid:100002359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.73.188.132",nocase; classtype:trojan-activity; sid:100002360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.12.10.98",nocase; classtype:trojan-activity; sid:100002361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.188.124.229",nocase; classtype:trojan-activity; sid:100002362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.212.200.162",nocase; classtype:trojan-activity; sid:100002363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.233.208.103",nocase; classtype:trojan-activity; sid:100002364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.33.71.68",nocase; classtype:trojan-activity; sid:100002365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.21.14",nocase; classtype:trojan-activity; sid:100002366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.231.246",nocase; classtype:trojan-activity; sid:100002367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.113.102.18",nocase; classtype:trojan-activity; sid:100002368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.113.81.17",nocase; classtype:trojan-activity; sid:100002369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.119.45.194",nocase; classtype:trojan-activity; sid:100002370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.13.179.87",nocase; classtype:trojan-activity; sid:100002371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.138.200.32",nocase; classtype:trojan-activity; sid:100002372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.152.41.141",nocase; classtype:trojan-activity; sid:100002373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.178.50",nocase; classtype:trojan-activity; sid:100002374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.179.151",nocase; classtype:trojan-activity; sid:100002375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.45.140",nocase; classtype:trojan-activity; sid:100002376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.167.159",nocase; classtype:trojan-activity; sid:100002377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.242.144",nocase; classtype:trojan-activity; sid:100002378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.81.100.83",nocase; classtype:trojan-activity; sid:100002379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.83.202.25",nocase; classtype:trojan-activity; sid:100002380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"189.222.157.241",nocase; classtype:trojan-activity; sid:100002381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"19.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.0.42.106",nocase; classtype:trojan-activity; sid:100002383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.109.178.139",nocase; classtype:trojan-activity; sid:100002384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.110.161.252",nocase; classtype:trojan-activity; sid:100002385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.111.151.164",nocase; classtype:trojan-activity; sid:100002386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.119.207.58",nocase; classtype:trojan-activity; sid:100002387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.12.99.194",nocase; classtype:trojan-activity; sid:100002388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.121.194.18",nocase; classtype:trojan-activity; sid:100002389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.160",nocase; classtype:trojan-activity; sid:100002390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.3",nocase; classtype:trojan-activity; sid:100002391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.37",nocase; classtype:trojan-activity; sid:100002392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.41",nocase; classtype:trojan-activity; sid:100002393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.42",nocase; classtype:trojan-activity; sid:100002394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.15.212",nocase; classtype:trojan-activity; sid:100002395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.20.14",nocase; classtype:trojan-activity; sid:100002396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.141.117.41",nocase; classtype:trojan-activity; sid:100002397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.147.16.184",nocase; classtype:trojan-activity; sid:100002398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.159.240.9",nocase; classtype:trojan-activity; sid:100002399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.187.55.150",nocase; classtype:trojan-activity; sid:100002400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.210.214.130",nocase; classtype:trojan-activity; sid:100002401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.177.39",nocase; classtype:trojan-activity; sid:100002402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.226.63",nocase; classtype:trojan-activity; sid:100002403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.49.207",nocase; classtype:trojan-activity; sid:100002404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.214.24.194",nocase; classtype:trojan-activity; sid:100002405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.216.140.123",nocase; classtype:trojan-activity; sid:100002406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.35.225.36",nocase; classtype:trojan-activity; sid:100002407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.65.206.162",nocase; classtype:trojan-activity; sid:100002408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.73.12.149",nocase; classtype:trojan-activity; sid:100002409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.92.4.231",nocase; classtype:trojan-activity; sid:100002410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.135",nocase; classtype:trojan-activity; sid:100002411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.200",nocase; classtype:trojan-activity; sid:100002412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.41.33",nocase; classtype:trojan-activity; sid:100002413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"191.255.248.220",nocase; classtype:trojan-activity; sid:100002414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.175.130",nocase; classtype:trojan-activity; sid:100002415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.241.200",nocase; classtype:trojan-activity; sid:100002416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.209.27",nocase; classtype:trojan-activity; sid:100002417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.220.55",nocase; classtype:trojan-activity; sid:100002418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.228.67",nocase; classtype:trojan-activity; sid:100002419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.3.152.166",nocase; classtype:trojan-activity; sid:100002420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.3.73.205",nocase; classtype:trojan-activity; sid:100002421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.99.240.77",nocase; classtype:trojan-activity; sid:100002422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.142.146.25",nocase; classtype:trojan-activity; sid:100002423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.228.135.144",nocase; classtype:trojan-activity; sid:100002424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.38.55.9",nocase; classtype:trojan-activity; sid:100002425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.91.131.237",nocase; classtype:trojan-activity; sid:100002426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.147.142.230",nocase; classtype:trojan-activity; sid:100002427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.15.36.167",nocase; classtype:trojan-activity; sid:100002428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.152.35.139",nocase; classtype:trojan-activity; sid:100002429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.38.20.199",nocase; classtype:trojan-activity; sid:100002430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.139.126.51",nocase; classtype:trojan-activity; sid:100002431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.228.231.218",nocase; classtype:trojan-activity; sid:100002432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.24.94.187",nocase; classtype:trojan-activity; sid:100002433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.202.26.182",nocase; classtype:trojan-activity; sid:100002434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.218.48.82",nocase; classtype:trojan-activity; sid:100002435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.148.90",nocase; classtype:trojan-activity; sid:100002436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.166.203",nocase; classtype:trojan-activity; sid:100002437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.159.2.106",nocase; classtype:trojan-activity; sid:100002438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.50.27.115",nocase; classtype:trojan-activity; sid:100002439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.133.218",nocase; classtype:trojan-activity; sid:100002440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.207.121",nocase; classtype:trojan-activity; sid:100002441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.251.105",nocase; classtype:trojan-activity; sid:100002442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.251.72.110",nocase; classtype:trojan-activity; sid:100002443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.201.76",nocase; classtype:trojan-activity; sid:100002444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.202.7",nocase; classtype:trojan-activity; sid:100002445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"199.188.101.109",nocase; classtype:trojan-activity; sid:100002446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1am.co.nz",nocase; classtype:trojan-activity; sid:100002447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.229.89.119",nocase; classtype:trojan-activity; sid:100002448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.249.161.188",nocase; classtype:trojan-activity; sid:100002449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.111.158",nocase; classtype:trojan-activity; sid:100002450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.4.24",nocase; classtype:trojan-activity; sid:100002451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.125.182",nocase; classtype:trojan-activity; sid:100002452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.58.69.44",nocase; classtype:trojan-activity; sid:100002453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.83.152.16",nocase; classtype:trojan-activity; sid:100002454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"20.185.42.197",nocase; classtype:trojan-activity; sid:100002455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"20.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.105.167.98",nocase; classtype:trojan-activity; sid:100002457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.111.189.70",nocase; classtype:trojan-activity; sid:100002458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.194.4.24",nocase; classtype:trojan-activity; sid:100002459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.2.161.171",nocase; classtype:trojan-activity; sid:100002460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.30.132.50",nocase; classtype:trojan-activity; sid:100002461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.142.147.89",nocase; classtype:trojan-activity; sid:100002462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.163.170",nocase; classtype:trojan-activity; sid:100002463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.248.190",nocase; classtype:trojan-activity; sid:100002464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.187.102.73",nocase; classtype:trojan-activity; sid:100002465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.200.254.86",nocase; classtype:trojan-activity; sid:100002466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.203.221.20",nocase; classtype:trojan-activity; sid:100002467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.203.27.37",nocase; classtype:trojan-activity; sid:100002468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.215.84.97",nocase; classtype:trojan-activity; sid:100002469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.218.97.142",nocase; classtype:trojan-activity; sid:100002470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.107.233.41",nocase; classtype:trojan-activity; sid:100002471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.150.176.100",nocase; classtype:trojan-activity; sid:100002472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.164.153.80",nocase; classtype:trojan-activity; sid:100002473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.166.217.54",nocase; classtype:trojan-activity; sid:100002474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.22",nocase; classtype:trojan-activity; sid:100002475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.37",nocase; classtype:trojan-activity; sid:100002476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.52",nocase; classtype:trojan-activity; sid:100002477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.29.95.12",nocase; classtype:trojan-activity; sid:100002478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.4.124.58",nocase; classtype:trojan-activity; sid:100002479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.176.114",nocase; classtype:trojan-activity; sid:100002480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.191.174",nocase; classtype:trojan-activity; sid:100002481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.74.236.9",nocase; classtype:trojan-activity; sid:100002482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.109.201.243",nocase; classtype:trojan-activity; sid:100002483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.130.69.205",nocase; classtype:trojan-activity; sid:100002484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.189.156.107",nocase; classtype:trojan-activity; sid:100002485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.204.232.18",nocase; classtype:trojan-activity; sid:100002486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.229.21.56",nocase; classtype:trojan-activity; sid:100002487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.236.190.28",nocase; classtype:trojan-activity; sid:100002488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.70.166.107",nocase; classtype:trojan-activity; sid:100002489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.77.80.159",nocase; classtype:trojan-activity; sid:100002490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.119.166",nocase; classtype:trojan-activity; sid:100002491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.171.138",nocase; classtype:trojan-activity; sid:100002492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.82.36.34",nocase; classtype:trojan-activity; sid:100002493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.82.49.122",nocase; classtype:trojan-activity; sid:100002494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.93.6.28",nocase; classtype:trojan-activity; sid:100002495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"204.195.116.171",nocase; classtype:trojan-activity; sid:100002496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"205.185.115.74",nocase; classtype:trojan-activity; sid:100002497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.248.137.132",nocase; classtype:trojan-activity; sid:100002498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.47.41.166",nocase; classtype:trojan-activity; sid:100002499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.5.32.6",nocase; classtype:trojan-activity; sid:100002500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.163.58.18",nocase; classtype:trojan-activity; sid:100002501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.39.50",nocase; classtype:trojan-activity; sid:100002502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.190",nocase; classtype:trojan-activity; sid:100002503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.31",nocase; classtype:trojan-activity; sid:100002504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.145.60.38",nocase; classtype:trojan-activity; sid:100002505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.124.149.19",nocase; classtype:trojan-activity; sid:100002506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.152.122",nocase; classtype:trojan-activity; sid:100002507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.153.142",nocase; classtype:trojan-activity; sid:100002508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.234.131",nocase; classtype:trojan-activity; sid:100002509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.234.93",nocase; classtype:trojan-activity; sid:100002510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.237.70",nocase; classtype:trojan-activity; sid:100002511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.245.109",nocase; classtype:trojan-activity; sid:100002512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.68.242.114",nocase; classtype:trojan-activity; sid:100002513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.96.116.236",nocase; classtype:trojan-activity; sid:100002514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.116.220.37",nocase; classtype:trojan-activity; sid:100002515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.172.11.169",nocase; classtype:trojan-activity; sid:100002516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.179.43.109",nocase; classtype:trojan-activity; sid:100002517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.132.204",nocase; classtype:trojan-activity; sid:100002518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.75.220",nocase; classtype:trojan-activity; sid:100002519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.204.215.157",nocase; classtype:trojan-activity; sid:100002520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.66.179",nocase; classtype:trojan-activity; sid:100002521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.93.93",nocase; classtype:trojan-activity; sid:100002522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.216.66.105",nocase; classtype:trojan-activity; sid:100002523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.114.96",nocase; classtype:trojan-activity; sid:100002524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.120.13",nocase; classtype:trojan-activity; sid:100002525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.246.137",nocase; classtype:trojan-activity; sid:100002526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.238.83.238",nocase; classtype:trojan-activity; sid:100002527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.113.49",nocase; classtype:trojan-activity; sid:100002528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.5.96",nocase; classtype:trojan-activity; sid:100002529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.36.174.137",nocase; classtype:trojan-activity; sid:100002530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.47.102.51",nocase; classtype:trojan-activity; sid:100002531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.51.174.149",nocase; classtype:trojan-activity; sid:100002532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.122.86.105",nocase; classtype:trojan-activity; sid:100002533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.143.227.22",nocase; classtype:trojan-activity; sid:100002534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.156.215.178",nocase; classtype:trojan-activity; sid:100002535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.46.197.114",nocase; classtype:trojan-activity; sid:100002536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.56.197.230",nocase; classtype:trojan-activity; sid:100002537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.119.74.202",nocase; classtype:trojan-activity; sid:100002538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.123.206.197",nocase; classtype:trojan-activity; sid:100002539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.135.178.253",nocase; classtype:trojan-activity; sid:100002540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.14.173.117",nocase; classtype:trojan-activity; sid:100002541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.182.113",nocase; classtype:trojan-activity; sid:100002542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.190.193",nocase; classtype:trojan-activity; sid:100002543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.12",nocase; classtype:trojan-activity; sid:100002544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.138",nocase; classtype:trojan-activity; sid:100002545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.7",nocase; classtype:trojan-activity; sid:100002546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.99",nocase; classtype:trojan-activity; sid:100002547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.100",nocase; classtype:trojan-activity; sid:100002548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.135",nocase; classtype:trojan-activity; sid:100002549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.225",nocase; classtype:trojan-activity; sid:100002550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.237",nocase; classtype:trojan-activity; sid:100002551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.51",nocase; classtype:trojan-activity; sid:100002552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.155",nocase; classtype:trojan-activity; sid:100002553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.191",nocase; classtype:trojan-activity; sid:100002554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.80",nocase; classtype:trojan-activity; sid:100002555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.1",nocase; classtype:trojan-activity; sid:100002556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.11",nocase; classtype:trojan-activity; sid:100002557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.26",nocase; classtype:trojan-activity; sid:100002558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.33",nocase; classtype:trojan-activity; sid:100002559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.71",nocase; classtype:trojan-activity; sid:100002560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.132",nocase; classtype:trojan-activity; sid:100002561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.181",nocase; classtype:trojan-activity; sid:100002562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.192",nocase; classtype:trojan-activity; sid:100002563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.197",nocase; classtype:trojan-activity; sid:100002564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.203",nocase; classtype:trojan-activity; sid:100002565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.33",nocase; classtype:trojan-activity; sid:100002566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.85",nocase; classtype:trojan-activity; sid:100002567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.117.122",nocase; classtype:trojan-activity; sid:100002568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.117.151",nocase; classtype:trojan-activity; sid:100002569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.117.97",nocase; classtype:trojan-activity; sid:100002570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.129",nocase; classtype:trojan-activity; sid:100002571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.144",nocase; classtype:trojan-activity; sid:100002572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.236",nocase; classtype:trojan-activity; sid:100002573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.238",nocase; classtype:trojan-activity; sid:100002574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.119.24",nocase; classtype:trojan-activity; sid:100002575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.119.240",nocase; classtype:trojan-activity; sid:100002576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.20",nocase; classtype:trojan-activity; sid:100002577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.243",nocase; classtype:trojan-activity; sid:100002578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.249",nocase; classtype:trojan-activity; sid:100002579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.60",nocase; classtype:trojan-activity; sid:100002580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.7",nocase; classtype:trojan-activity; sid:100002581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.84",nocase; classtype:trojan-activity; sid:100002582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.204",nocase; classtype:trojan-activity; sid:100002583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.217",nocase; classtype:trojan-activity; sid:100002584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.242",nocase; classtype:trojan-activity; sid:100002585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.46",nocase; classtype:trojan-activity; sid:100002586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.189.178.163",nocase; classtype:trojan-activity; sid:100002587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.240.218.15",nocase; classtype:trojan-activity; sid:100002588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.249.156.189",nocase; classtype:trojan-activity; sid:100002589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.27.8.6",nocase; classtype:trojan-activity; sid:100002590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.80.44.17",nocase; classtype:trojan-activity; sid:100002591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.87.87.173",nocase; classtype:trojan-activity; sid:100002592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.254.52",nocase; classtype:trojan-activity; sid:100002593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.36",nocase; classtype:trojan-activity; sid:100002594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.84",nocase; classtype:trojan-activity; sid:100002595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.127.185.150",nocase; classtype:trojan-activity; sid:100002596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.170.240.98",nocase; classtype:trojan-activity; sid:100002597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.183.54.169",nocase; classtype:trojan-activity; sid:100002598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.36.12.98",nocase; classtype:trojan-activity; sid:100002599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.11.75.162",nocase; classtype:trojan-activity; sid:100002600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.127.133.214",nocase; classtype:trojan-activity; sid:100002601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.8.228.92",nocase; classtype:trojan-activity; sid:100002602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.12.162.39",nocase; classtype:trojan-activity; sid:100002603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.12.181.110",nocase; classtype:trojan-activity; sid:100002604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.2.40.34",nocase; classtype:trojan-activity; sid:100002605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.215.243.65",nocase; classtype:trojan-activity; sid:100002606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.238.246.3",nocase; classtype:trojan-activity; sid:100002607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.28.160.174",nocase; classtype:trojan-activity; sid:100002608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.207.119",nocase; classtype:trojan-activity; sid:100002609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.227.133",nocase; classtype:trojan-activity; sid:100002610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.68.35",nocase; classtype:trojan-activity; sid:100002611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.81.81",nocase; classtype:trojan-activity; sid:100002612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.48.135.50",nocase; classtype:trojan-activity; sid:100002613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.56.93.129",nocase; classtype:trojan-activity; sid:100002614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.57.109.48",nocase; classtype:trojan-activity; sid:100002615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.57.53.55",nocase; classtype:trojan-activity; sid:100002616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.59.116.203",nocase; classtype:trojan-activity; sid:100002617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.72.198.15",nocase; classtype:trojan-activity; sid:100002618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.79.103.159",nocase; classtype:trojan-activity; sid:100002619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.63",nocase; classtype:trojan-activity; sid:100002620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.75",nocase; classtype:trojan-activity; sid:100002621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.103.40",nocase; classtype:trojan-activity; sid:100002622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.114.45",nocase; classtype:trojan-activity; sid:100002623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.115.250",nocase; classtype:trojan-activity; sid:100002624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.116.168",nocase; classtype:trojan-activity; sid:100002625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.126.205",nocase; classtype:trojan-activity; sid:100002626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.142.35",nocase; classtype:trojan-activity; sid:100002627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.143.132",nocase; classtype:trojan-activity; sid:100002628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.147.58",nocase; classtype:trojan-activity; sid:100002629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.148.116",nocase; classtype:trojan-activity; sid:100002630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.173.163",nocase; classtype:trojan-activity; sid:100002631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.178.138",nocase; classtype:trojan-activity; sid:100002632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.41.36",nocase; classtype:trojan-activity; sid:100002633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.102.14",nocase; classtype:trojan-activity; sid:100002634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.11.252",nocase; classtype:trojan-activity; sid:100002635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.113.58",nocase; classtype:trojan-activity; sid:100002636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.14.17",nocase; classtype:trojan-activity; sid:100002637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.209.253",nocase; classtype:trojan-activity; sid:100002638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.24.246",nocase; classtype:trojan-activity; sid:100002639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.243.184",nocase; classtype:trojan-activity; sid:100002640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.26.204",nocase; classtype:trojan-activity; sid:100002641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.29.165",nocase; classtype:trojan-activity; sid:100002642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.31.15",nocase; classtype:trojan-activity; sid:100002643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.31.67",nocase; classtype:trojan-activity; sid:100002644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.86.156",nocase; classtype:trojan-activity; sid:100002645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.98.64",nocase; classtype:trojan-activity; sid:100002646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.131.116",nocase; classtype:trojan-activity; sid:100002647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.17.217",nocase; classtype:trojan-activity; sid:100002648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.176.153",nocase; classtype:trojan-activity; sid:100002649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.23.29",nocase; classtype:trojan-activity; sid:100002650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.60.224",nocase; classtype:trojan-activity; sid:100002651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.65.47",nocase; classtype:trojan-activity; sid:100002652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.88.219",nocase; classtype:trojan-activity; sid:100002653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.11.39",nocase; classtype:trojan-activity; sid:100002654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.146.200",nocase; classtype:trojan-activity; sid:100002655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.147.87",nocase; classtype:trojan-activity; sid:100002656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.150.91",nocase; classtype:trojan-activity; sid:100002657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.178.201",nocase; classtype:trojan-activity; sid:100002658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.178.210",nocase; classtype:trojan-activity; sid:100002659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.183.29",nocase; classtype:trojan-activity; sid:100002660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.214.235",nocase; classtype:trojan-activity; sid:100002661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.223.241",nocase; classtype:trojan-activity; sid:100002662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.42.228",nocase; classtype:trojan-activity; sid:100002663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.67.171",nocase; classtype:trojan-activity; sid:100002664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.241.6.180",nocase; classtype:trojan-activity; sid:100002665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.148",nocase; classtype:trojan-activity; sid:100002666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.84",nocase; classtype:trojan-activity; sid:100002667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.163.7",nocase; classtype:trojan-activity; sid:100002668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.171.144",nocase; classtype:trojan-activity; sid:100002669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.245.63",nocase; classtype:trojan-activity; sid:100002670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.251.32",nocase; classtype:trojan-activity; sid:100002671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.5.140",nocase; classtype:trojan-activity; sid:100002672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.69.71.186",nocase; classtype:trojan-activity; sid:100002673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.80.217.209",nocase; classtype:trojan-activity; sid:100002674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.85.145.194",nocase; classtype:trojan-activity; sid:100002675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"21robo.com",nocase; classtype:trojan-activity; sid:100002676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.118.168.155",nocase; classtype:trojan-activity; sid:100002677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.126.237.74",nocase; classtype:trojan-activity; sid:100002678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.133.30.200",nocase; classtype:trojan-activity; sid:100002679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.200.22.163",nocase; classtype:trojan-activity; sid:100002680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.71.239.115",nocase; classtype:trojan-activity; sid:100002681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.90.159.188",nocase; classtype:trojan-activity; sid:100002682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.1.162.82",nocase; classtype:trojan-activity; sid:100002683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.124.78.15",nocase; classtype:trojan-activity; sid:100002684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.122.127",nocase; classtype:trojan-activity; sid:100002685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.165.237",nocase; classtype:trojan-activity; sid:100002686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.185.105",nocase; classtype:trojan-activity; sid:100002687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.47.162",nocase; classtype:trojan-activity; sid:100002688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.47.189",nocase; classtype:trojan-activity; sid:100002689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.57.175",nocase; classtype:trojan-activity; sid:100002690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.108.55",nocase; classtype:trojan-activity; sid:100002691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.112.103",nocase; classtype:trojan-activity; sid:100002692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.125.190",nocase; classtype:trojan-activity; sid:100002693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.155.186",nocase; classtype:trojan-activity; sid:100002694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.190.2",nocase; classtype:trojan-activity; sid:100002695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.234.159",nocase; classtype:trojan-activity; sid:100002696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.237.107",nocase; classtype:trojan-activity; sid:100002697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.250.213",nocase; classtype:trojan-activity; sid:100002698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.253.236",nocase; classtype:trojan-activity; sid:100002699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.54.237",nocase; classtype:trojan-activity; sid:100002700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.55.56",nocase; classtype:trojan-activity; sid:100002701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.157.191.178",nocase; classtype:trojan-activity; sid:100002702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.136.213",nocase; classtype:trojan-activity; sid:100002703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.104",nocase; classtype:trojan-activity; sid:100002704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.107",nocase; classtype:trojan-activity; sid:100002705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.224",nocase; classtype:trojan-activity; sid:100002706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.196.12.96",nocase; classtype:trojan-activity; sid:100002707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.198.167.192",nocase; classtype:trojan-activity; sid:100002708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.2.190.22",nocase; classtype:trojan-activity; sid:100002709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.202.232.230",nocase; classtype:trojan-activity; sid:100002710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.130.147",nocase; classtype:trojan-activity; sid:100002711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.224.184",nocase; classtype:trojan-activity; sid:100002712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.251.109",nocase; classtype:trojan-activity; sid:100002713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.116.167",nocase; classtype:trojan-activity; sid:100002714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.172.207",nocase; classtype:trojan-activity; sid:100002715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.184.31",nocase; classtype:trojan-activity; sid:100002716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.237.220",nocase; classtype:trojan-activity; sid:100002717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.252.64",nocase; classtype:trojan-activity; sid:100002718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.8.64",nocase; classtype:trojan-activity; sid:100002719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.1.82",nocase; classtype:trojan-activity; sid:100002720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.179.70",nocase; classtype:trojan-activity; sid:100002721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.137.36",nocase; classtype:trojan-activity; sid:100002722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.142.206",nocase; classtype:trojan-activity; sid:100002723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.112.125",nocase; classtype:trojan-activity; sid:100002724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.32.88",nocase; classtype:trojan-activity; sid:100002725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.34.43",nocase; classtype:trojan-activity; sid:100002726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.43.223",nocase; classtype:trojan-activity; sid:100002727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.68.16",nocase; classtype:trojan-activity; sid:100002728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.108.17.64",nocase; classtype:trojan-activity; sid:100002729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.119.65.145",nocase; classtype:trojan-activity; sid:100002730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.132.125.138",nocase; classtype:trojan-activity; sid:100002731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.102.202",nocase; classtype:trojan-activity; sid:100002732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.103.120",nocase; classtype:trojan-activity; sid:100002733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.105.87",nocase; classtype:trojan-activity; sid:100002734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.219.29",nocase; classtype:trojan-activity; sid:100002735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.26.161",nocase; classtype:trojan-activity; sid:100002736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.67.115",nocase; classtype:trojan-activity; sid:100002737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.136.53.227",nocase; classtype:trojan-activity; sid:100002738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.136.77.190",nocase; classtype:trojan-activity; sid:100002739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.101.251",nocase; classtype:trojan-activity; sid:100002740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.101.33",nocase; classtype:trojan-activity; sid:100002741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.121.127",nocase; classtype:trojan-activity; sid:100002742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.137.5",nocase; classtype:trojan-activity; sid:100002743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.138.252",nocase; classtype:trojan-activity; sid:100002744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.148.192",nocase; classtype:trojan-activity; sid:100002745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.161.88",nocase; classtype:trojan-activity; sid:100002746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.172.250",nocase; classtype:trojan-activity; sid:100002747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.198.247",nocase; classtype:trojan-activity; sid:100002748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.220.215",nocase; classtype:trojan-activity; sid:100002749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.237.203",nocase; classtype:trojan-activity; sid:100002750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.239.124",nocase; classtype:trojan-activity; sid:100002751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.49.36",nocase; classtype:trojan-activity; sid:100002752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.53.193",nocase; classtype:trojan-activity; sid:100002753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.72.146",nocase; classtype:trojan-activity; sid:100002754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.96.9",nocase; classtype:trojan-activity; sid:100002755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.118.192",nocase; classtype:trojan-activity; sid:100002756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.143.84",nocase; classtype:trojan-activity; sid:100002757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.151.100",nocase; classtype:trojan-activity; sid:100002758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.189.138",nocase; classtype:trojan-activity; sid:100002759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.201.241",nocase; classtype:trojan-activity; sid:100002760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.213.235",nocase; classtype:trojan-activity; sid:100002761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.226.142",nocase; classtype:trojan-activity; sid:100002762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.96.79",nocase; classtype:trojan-activity; sid:100002763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.139.106.55",nocase; classtype:trojan-activity; sid:100002764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.162.140",nocase; classtype:trojan-activity; sid:100002765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.163.112",nocase; classtype:trojan-activity; sid:100002766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.17.245",nocase; classtype:trojan-activity; sid:100002767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.179.142",nocase; classtype:trojan-activity; sid:100002768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.208.18",nocase; classtype:trojan-activity; sid:100002769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.209.222",nocase; classtype:trojan-activity; sid:100002770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.39.66",nocase; classtype:trojan-activity; sid:100002771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.101.39",nocase; classtype:trojan-activity; sid:100002772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.120.26",nocase; classtype:trojan-activity; sid:100002773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.13.77",nocase; classtype:trojan-activity; sid:100002774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.40.69",nocase; classtype:trojan-activity; sid:100002775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.46.119",nocase; classtype:trojan-activity; sid:100002776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.9.0",nocase; classtype:trojan-activity; sid:100002777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.192.66",nocase; classtype:trojan-activity; sid:100002778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.209.231",nocase; classtype:trojan-activity; sid:100002779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.179.215.189",nocase; classtype:trojan-activity; sid:100002780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.185.116.233",nocase; classtype:trojan-activity; sid:100002781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.187.9.178",nocase; classtype:trojan-activity; sid:100002782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.211.72.66",nocase; classtype:trojan-activity; sid:100002783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.214.54.208",nocase; classtype:trojan-activity; sid:100002784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.218.220.219",nocase; classtype:trojan-activity; sid:100002785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.236.85.220",nocase; classtype:trojan-activity; sid:100002786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.238.230.7",nocase; classtype:trojan-activity; sid:100002787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.239.83.232",nocase; classtype:trojan-activity; sid:100002788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.248.64.253",nocase; classtype:trojan-activity; sid:100002789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.81.156.229",nocase; classtype:trojan-activity; sid:100002790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.92.9.126",nocase; classtype:trojan-activity; sid:100002791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.99.171.192",nocase; classtype:trojan-activity; sid:100002792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.166.117.210",nocase; classtype:trojan-activity; sid:100002793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.167.118.17",nocase; classtype:trojan-activity; sid:100002794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.225.68",nocase; classtype:trojan-activity; sid:100002795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.234.84",nocase; classtype:trojan-activity; sid:100002796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.5.29",nocase; classtype:trojan-activity; sid:100002797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.73.175",nocase; classtype:trojan-activity; sid:100002798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.125.186.135",nocase; classtype:trojan-activity; sid:100002799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.126.120.25",nocase; classtype:trojan-activity; sid:100002800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.228.143.58",nocase; classtype:trojan-activity; sid:100002801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.24.213.121",nocase; classtype:trojan-activity; sid:100002802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.149.13",nocase; classtype:trojan-activity; sid:100002803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.21.167",nocase; classtype:trojan-activity; sid:100002804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.95.89.21",nocase; classtype:trojan-activity; sid:100002805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.103.74.180",nocase; classtype:trojan-activity; sid:100002806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.11.141.134",nocase; classtype:trojan-activity; sid:100002807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.119.158.74",nocase; classtype:trojan-activity; sid:100002808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.137.147.95",nocase; classtype:trojan-activity; sid:100002809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.152.235.88",nocase; classtype:trojan-activity; sid:100002810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.158.25.98",nocase; classtype:trojan-activity; sid:100002811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.176.206.12",nocase; classtype:trojan-activity; sid:100002812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.184.1.41",nocase; classtype:trojan-activity; sid:100002813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.192.191.109",nocase; classtype:trojan-activity; sid:100002814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.225.114.161",nocase; classtype:trojan-activity; sid:100002815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.227.190.78",nocase; classtype:trojan-activity; sid:100002816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.35.245.52",nocase; classtype:trojan-activity; sid:100002817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.181.18",nocase; classtype:trojan-activity; sid:100002818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.34.242",nocase; classtype:trojan-activity; sid:100002819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.42.229.143",nocase; classtype:trojan-activity; sid:100002820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.45.4.1",nocase; classtype:trojan-activity; sid:100002821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.51.91.113",nocase; classtype:trojan-activity; sid:100002822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.10",nocase; classtype:trojan-activity; sid:100002823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.9",nocase; classtype:trojan-activity; sid:100002824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.16",nocase; classtype:trojan-activity; sid:100002826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.7",nocase; classtype:trojan-activity; sid:100002827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.106.201",nocase; classtype:trojan-activity; sid:100002828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.152.107",nocase; classtype:trojan-activity; sid:100002829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.116.84.57",nocase; classtype:trojan-activity; sid:100002830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.12.245.238",nocase; classtype:trojan-activity; sid:100002831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.141.218.17",nocase; classtype:trojan-activity; sid:100002832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.29.52",nocase; classtype:trojan-activity; sid:100002833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.40.128",nocase; classtype:trojan-activity; sid:100002834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.153.142.115",nocase; classtype:trojan-activity; sid:100002835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.184.244.14",nocase; classtype:trojan-activity; sid:100002836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.184.54.199",nocase; classtype:trojan-activity; sid:100002837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.187.248.22",nocase; classtype:trojan-activity; sid:100002838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.187.250.192",nocase; classtype:trojan-activity; sid:100002839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.196.190",nocase; classtype:trojan-activity; sid:100002840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.217.210",nocase; classtype:trojan-activity; sid:100002841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.149.142",nocase; classtype:trojan-activity; sid:100002842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.192.66",nocase; classtype:trojan-activity; sid:100002843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.210.20",nocase; classtype:trojan-activity; sid:100002844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.17.88",nocase; classtype:trojan-activity; sid:100002845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.22.217",nocase; classtype:trojan-activity; sid:100002846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.23.215",nocase; classtype:trojan-activity; sid:100002847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.24.175",nocase; classtype:trojan-activity; sid:100002848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.28.84",nocase; classtype:trojan-activity; sid:100002849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.148.189",nocase; classtype:trojan-activity; sid:100002850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.232.65",nocase; classtype:trojan-activity; sid:100002851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.3.194",nocase; classtype:trojan-activity; sid:100002852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.34.48",nocase; classtype:trojan-activity; sid:100002853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.110.211",nocase; classtype:trojan-activity; sid:100002854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.140.229",nocase; classtype:trojan-activity; sid:100002855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.2.163",nocase; classtype:trojan-activity; sid:100002856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.23.62",nocase; classtype:trojan-activity; sid:100002857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.32.146",nocase; classtype:trojan-activity; sid:100002858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.201.183.149",nocase; classtype:trojan-activity; sid:100002859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.182.201",nocase; classtype:trojan-activity; sid:100002860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.66.46",nocase; classtype:trojan-activity; sid:100002861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.102.12",nocase; classtype:trojan-activity; sid:100002862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.126.194",nocase; classtype:trojan-activity; sid:100002863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.154.105",nocase; classtype:trojan-activity; sid:100002864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.165.138",nocase; classtype:trojan-activity; sid:100002865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.175.203",nocase; classtype:trojan-activity; sid:100002866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.185.42",nocase; classtype:trojan-activity; sid:100002867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.213.79",nocase; classtype:trojan-activity; sid:100002868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.246.96",nocase; classtype:trojan-activity; sid:100002869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.255.42",nocase; classtype:trojan-activity; sid:100002870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.28.115",nocase; classtype:trojan-activity; sid:100002871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.4.188",nocase; classtype:trojan-activity; sid:100002872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.68.144",nocase; classtype:trojan-activity; sid:100002873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.87.75",nocase; classtype:trojan-activity; sid:100002874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.94.134",nocase; classtype:trojan-activity; sid:100002875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.204.253.74",nocase; classtype:trojan-activity; sid:100002876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.205.178.110",nocase; classtype:trojan-activity; sid:100002877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.136.101",nocase; classtype:trojan-activity; sid:100002878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.148.106",nocase; classtype:trojan-activity; sid:100002879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.154.122",nocase; classtype:trojan-activity; sid:100002880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.26.218",nocase; classtype:trojan-activity; sid:100002881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.80.209",nocase; classtype:trojan-activity; sid:100002882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.81.66",nocase; classtype:trojan-activity; sid:100002883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.83.48",nocase; classtype:trojan-activity; sid:100002884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.97.81",nocase; classtype:trojan-activity; sid:100002885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.151.126",nocase; classtype:trojan-activity; sid:100002886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.155.31",nocase; classtype:trojan-activity; sid:100002887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.170.203",nocase; classtype:trojan-activity; sid:100002888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.54.91",nocase; classtype:trojan-activity; sid:100002889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.144.57",nocase; classtype:trojan-activity; sid:100002890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.152.10",nocase; classtype:trojan-activity; sid:100002891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.160.177",nocase; classtype:trojan-activity; sid:100002892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.164.18",nocase; classtype:trojan-activity; sid:100002893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.166.13",nocase; classtype:trojan-activity; sid:100002894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.201.212",nocase; classtype:trojan-activity; sid:100002895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.247.130",nocase; classtype:trojan-activity; sid:100002896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.25.59",nocase; classtype:trojan-activity; sid:100002897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.34.2",nocase; classtype:trojan-activity; sid:100002898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.70.115",nocase; classtype:trojan-activity; sid:100002899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.92.64",nocase; classtype:trojan-activity; sid:100002900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.160.222",nocase; classtype:trojan-activity; sid:100002901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.231.15",nocase; classtype:trojan-activity; sid:100002902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.60.21",nocase; classtype:trojan-activity; sid:100002903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.107.125",nocase; classtype:trojan-activity; sid:100002904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.127.11",nocase; classtype:trojan-activity; sid:100002905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.172.245",nocase; classtype:trojan-activity; sid:100002906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.234.28",nocase; classtype:trojan-activity; sid:100002907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.236.134",nocase; classtype:trojan-activity; sid:100002908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.63.243",nocase; classtype:trojan-activity; sid:100002909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.211.251.162",nocase; classtype:trojan-activity; sid:100002910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.104.201",nocase; classtype:trojan-activity; sid:100002911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.109.105",nocase; classtype:trojan-activity; sid:100002912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.109.58",nocase; classtype:trojan-activity; sid:100002913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.145.221",nocase; classtype:trojan-activity; sid:100002914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.166.50",nocase; classtype:trojan-activity; sid:100002915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.167.175",nocase; classtype:trojan-activity; sid:100002916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.175.208",nocase; classtype:trojan-activity; sid:100002917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.220.5",nocase; classtype:trojan-activity; sid:100002918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.255.202",nocase; classtype:trojan-activity; sid:100002919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.255.6",nocase; classtype:trojan-activity; sid:100002920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.84.74",nocase; classtype:trojan-activity; sid:100002921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.214.37.129",nocase; classtype:trojan-activity; sid:100002922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.139.242",nocase; classtype:trojan-activity; sid:100002923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.190.172",nocase; classtype:trojan-activity; sid:100002924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.212.209",nocase; classtype:trojan-activity; sid:100002925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.212.80",nocase; classtype:trojan-activity; sid:100002926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.253.149",nocase; classtype:trojan-activity; sid:100002927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.27.143",nocase; classtype:trojan-activity; sid:100002928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.34.242",nocase; classtype:trojan-activity; sid:100002929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.38.119",nocase; classtype:trojan-activity; sid:100002930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.38.166",nocase; classtype:trojan-activity; sid:100002931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.71.243",nocase; classtype:trojan-activity; sid:100002932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.98.242",nocase; classtype:trojan-activity; sid:100002933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.131.66",nocase; classtype:trojan-activity; sid:100002934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.144.66",nocase; classtype:trojan-activity; sid:100002935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.193.217",nocase; classtype:trojan-activity; sid:100002936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.197.193",nocase; classtype:trojan-activity; sid:100002937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.223.246",nocase; classtype:trojan-activity; sid:100002938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.225.28",nocase; classtype:trojan-activity; sid:100002939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.227.95",nocase; classtype:trojan-activity; sid:100002940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.234.98",nocase; classtype:trojan-activity; sid:100002941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.46.85",nocase; classtype:trojan-activity; sid:100002942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.95.56",nocase; classtype:trojan-activity; sid:100002943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.120.226",nocase; classtype:trojan-activity; sid:100002944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.133.53",nocase; classtype:trojan-activity; sid:100002945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.191.58",nocase; classtype:trojan-activity; sid:100002946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.76.48",nocase; classtype:trojan-activity; sid:100002947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.180.172",nocase; classtype:trojan-activity; sid:100002948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.219.228",nocase; classtype:trojan-activity; sid:100002949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.240.158",nocase; classtype:trojan-activity; sid:100002950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.248.121",nocase; classtype:trojan-activity; sid:100002951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.119.149",nocase; classtype:trojan-activity; sid:100002952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.132.71",nocase; classtype:trojan-activity; sid:100002953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.151.83",nocase; classtype:trojan-activity; sid:100002954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.160.112",nocase; classtype:trojan-activity; sid:100002955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.172.175",nocase; classtype:trojan-activity; sid:100002956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.173.180",nocase; classtype:trojan-activity; sid:100002957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.176.72",nocase; classtype:trojan-activity; sid:100002958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.184.94",nocase; classtype:trojan-activity; sid:100002959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.192.223",nocase; classtype:trojan-activity; sid:100002960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.83.244",nocase; classtype:trojan-activity; sid:100002961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.40.189",nocase; classtype:trojan-activity; sid:100002962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.80.93",nocase; classtype:trojan-activity; sid:100002963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.85.168",nocase; classtype:trojan-activity; sid:100002964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.221.239.223",nocase; classtype:trojan-activity; sid:100002965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.241.223",nocase; classtype:trojan-activity; sid:100002966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.249.210",nocase; classtype:trojan-activity; sid:100002967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.42.189",nocase; classtype:trojan-activity; sid:100002968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.50.170",nocase; classtype:trojan-activity; sid:100002969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.223.242.164",nocase; classtype:trojan-activity; sid:100002970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.24.28.134",nocase; classtype:trojan-activity; sid:100002971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.107.66",nocase; classtype:trojan-activity; sid:100002972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.129.198",nocase; classtype:trojan-activity; sid:100002973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.154.13",nocase; classtype:trojan-activity; sid:100002974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.212.124",nocase; classtype:trojan-activity; sid:100002975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.58.5",nocase; classtype:trojan-activity; sid:100002976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.159.28",nocase; classtype:trojan-activity; sid:100002977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.37.155",nocase; classtype:trojan-activity; sid:100002978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.9.105",nocase; classtype:trojan-activity; sid:100002979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.9.44",nocase; classtype:trojan-activity; sid:100002980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.97.36",nocase; classtype:trojan-activity; sid:100002981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.43.108.78",nocase; classtype:trojan-activity; sid:100002982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.43.111.161",nocase; classtype:trojan-activity; sid:100002983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.43.117.66",nocase; classtype:trojan-activity; sid:100002984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.23.10",nocase; classtype:trojan-activity; sid:100002985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.44.130",nocase; classtype:trojan-activity; sid:100002986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.44.153",nocase; classtype:trojan-activity; sid:100002987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.45.86",nocase; classtype:trojan-activity; sid:100002988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.46.100",nocase; classtype:trojan-activity; sid:100002989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.46.252",nocase; classtype:trojan-activity; sid:100002990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.23.69",nocase; classtype:trojan-activity; sid:100002991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.47.16",nocase; classtype:trojan-activity; sid:100002992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.6.240.171",nocase; classtype:trojan-activity; sid:100002993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.6.38.96",nocase; classtype:trojan-activity; sid:100002994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.0.98.131",nocase; classtype:trojan-activity; sid:100002995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.11.51.57",nocase; classtype:trojan-activity; sid:100002996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.13.23.180",nocase; classtype:trojan-activity; sid:100002997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.154.234.3",nocase; classtype:trojan-activity; sid:100002998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.163.191.11",nocase; classtype:trojan-activity; sid:100002999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.124.130",nocase; classtype:trojan-activity; sid:100003000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.179.83",nocase; classtype:trojan-activity; sid:100003001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.184.59",nocase; classtype:trojan-activity; sid:100003002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.191.243",nocase; classtype:trojan-activity; sid:100003003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.194.67",nocase; classtype:trojan-activity; sid:100003004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.216.132",nocase; classtype:trojan-activity; sid:100003005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.219.28",nocase; classtype:trojan-activity; sid:100003006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.24.115",nocase; classtype:trojan-activity; sid:100003007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.30.65",nocase; classtype:trojan-activity; sid:100003008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.60.234",nocase; classtype:trojan-activity; sid:100003009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.63.203",nocase; classtype:trojan-activity; sid:100003010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.65.233",nocase; classtype:trojan-activity; sid:100003011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.94.16",nocase; classtype:trojan-activity; sid:100003012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.179.201.26",nocase; classtype:trojan-activity; sid:100003013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.195.84.250",nocase; classtype:trojan-activity; sid:100003014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.177",nocase; classtype:trojan-activity; sid:100003015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.69",nocase; classtype:trojan-activity; sid:100003016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.28.7.159",nocase; classtype:trojan-activity; sid:100003017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.30.119.23",nocase; classtype:trojan-activity; sid:100003018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32.208.157.193",nocase; classtype:trojan-activity; sid:100003019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32.218.180.9",nocase; classtype:trojan-activity; sid:100003020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32792.prolocksmithwinterpark.com",nocase; classtype:trojan-activity; sid:100003021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"35.184.169.169",nocase; classtype:trojan-activity; sid:100003022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.108.231.218",nocase; classtype:trojan-activity; sid:100003023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.250.203.246",nocase; classtype:trojan-activity; sid:100003024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.157.225",nocase; classtype:trojan-activity; sid:100003025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.18.18",nocase; classtype:trojan-activity; sid:100003026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.18.63",nocase; classtype:trojan-activity; sid:100003027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.19.88",nocase; classtype:trojan-activity; sid:100003028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.51.244",nocase; classtype:trojan-activity; sid:100003029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.255.90.219",nocase; classtype:trojan-activity; sid:100003030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.128.60",nocase; classtype:trojan-activity; sid:100003031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.160.167",nocase; classtype:trojan-activity; sid:100003032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.34.150.236",nocase; classtype:trojan-activity; sid:100003033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.36.243.67",nocase; classtype:trojan-activity; sid:100003034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.43.11.16",nocase; classtype:trojan-activity; sid:100003035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.105.159",nocase; classtype:trojan-activity; sid:100003036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.111.203",nocase; classtype:trojan-activity; sid:100003037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.133.125",nocase; classtype:trojan-activity; sid:100003038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.139.36",nocase; classtype:trojan-activity; sid:100003039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.67.152.161",nocase; classtype:trojan-activity; sid:100003040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.81.23.38",nocase; classtype:trojan-activity; sid:100003041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.89.18.133",nocase; classtype:trojan-activity; sid:100003042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.96.187.93",nocase; classtype:trojan-activity; sid:100003043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360.lcy2zzx.pw",nocase; classtype:trojan-activity; sid:100003044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360down7.miiyun.cn",nocase; classtype:trojan-activity; sid:100003045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.222.98.51",nocase; classtype:trojan-activity; sid:100003046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.233.60.68",nocase; classtype:trojan-activity; sid:100003047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.179.221",nocase; classtype:trojan-activity; sid:100003048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.180.172",nocase; classtype:trojan-activity; sid:100003049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.44.238.35",nocase; classtype:trojan-activity; sid:100003050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.49.229.154",nocase; classtype:trojan-activity; sid:100003051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.49.230.152",nocase; classtype:trojan-activity; sid:100003052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.52.117.132",nocase; classtype:trojan-activity; sid:100003053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.14.36",nocase; classtype:trojan-activity; sid:100003054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"38.77.14.237",nocase; classtype:trojan-activity; sid:100003055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.245.254",nocase; classtype:trojan-activity; sid:100003056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.98.136",nocase; classtype:trojan-activity; sid:100003057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.114.137.102",nocase; classtype:trojan-activity; sid:100003058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.117.31.162",nocase; classtype:trojan-activity; sid:100003059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.162.104.119",nocase; classtype:trojan-activity; sid:100003060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.64.28.214",nocase; classtype:trojan-activity; sid:100003061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.196.34",nocase; classtype:trojan-activity; sid:100003062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.59.160",nocase; classtype:trojan-activity; sid:100003063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.115.94",nocase; classtype:trojan-activity; sid:100003064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.129.163",nocase; classtype:trojan-activity; sid:100003065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.44.109",nocase; classtype:trojan-activity; sid:100003066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.104.83",nocase; classtype:trojan-activity; sid:100003067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.125.186",nocase; classtype:trojan-activity; sid:100003068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.146.60",nocase; classtype:trojan-activity; sid:100003069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.148.163",nocase; classtype:trojan-activity; sid:100003070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.124.76",nocase; classtype:trojan-activity; sid:100003071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.171.125",nocase; classtype:trojan-activity; sid:100003072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.249.255",nocase; classtype:trojan-activity; sid:100003073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.60.61",nocase; classtype:trojan-activity; sid:100003074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.167.202",nocase; classtype:trojan-activity; sid:100003075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.5.175",nocase; classtype:trojan-activity; sid:100003076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.67.64",nocase; classtype:trojan-activity; sid:100003077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.10.198",nocase; classtype:trojan-activity; sid:100003078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.163.231",nocase; classtype:trojan-activity; sid:100003079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.203.225",nocase; classtype:trojan-activity; sid:100003080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.104.228",nocase; classtype:trojan-activity; sid:100003081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.184.222",nocase; classtype:trojan-activity; sid:100003082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.31.192",nocase; classtype:trojan-activity; sid:100003083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.68.182",nocase; classtype:trojan-activity; sid:100003084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.194.65",nocase; classtype:trojan-activity; sid:100003085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.33.191",nocase; classtype:trojan-activity; sid:100003086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.79.43",nocase; classtype:trojan-activity; sid:100003087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.97.16",nocase; classtype:trojan-activity; sid:100003088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.113.201",nocase; classtype:trojan-activity; sid:100003089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.114.45",nocase; classtype:trojan-activity; sid:100003090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.136.47",nocase; classtype:trojan-activity; sid:100003091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.14.27",nocase; classtype:trojan-activity; sid:100003092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.150.203",nocase; classtype:trojan-activity; sid:100003093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.197.81",nocase; classtype:trojan-activity; sid:100003094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.209.209",nocase; classtype:trojan-activity; sid:100003095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.48.213",nocase; classtype:trojan-activity; sid:100003096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.94.189",nocase; classtype:trojan-activity; sid:100003097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.95.50",nocase; classtype:trojan-activity; sid:100003098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.146.67",nocase; classtype:trojan-activity; sid:100003099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.163.188",nocase; classtype:trojan-activity; sid:100003100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.166.31",nocase; classtype:trojan-activity; sid:100003101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.218.46",nocase; classtype:trojan-activity; sid:100003102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.62.43",nocase; classtype:trojan-activity; sid:100003103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.91.244",nocase; classtype:trojan-activity; sid:100003104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.93.171",nocase; classtype:trojan-activity; sid:100003105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.127.214",nocase; classtype:trojan-activity; sid:100003106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.18.140",nocase; classtype:trojan-activity; sid:100003107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.191.137",nocase; classtype:trojan-activity; sid:100003108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.205.255",nocase; classtype:trojan-activity; sid:100003109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.24.54",nocase; classtype:trojan-activity; sid:100003110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.36.151",nocase; classtype:trojan-activity; sid:100003111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.37.182",nocase; classtype:trojan-activity; sid:100003112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.251.0",nocase; classtype:trojan-activity; sid:100003113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.27.15",nocase; classtype:trojan-activity; sid:100003114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.29.231",nocase; classtype:trojan-activity; sid:100003115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.82.86.105",nocase; classtype:trojan-activity; sid:100003116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.83.94.11",nocase; classtype:trojan-activity; sid:100003117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.115.152",nocase; classtype:trojan-activity; sid:100003118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.157.52",nocase; classtype:trojan-activity; sid:100003119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.34.217",nocase; classtype:trojan-activity; sid:100003120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.95.200",nocase; classtype:trojan-activity; sid:100003121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.191",nocase; classtype:trojan-activity; sid:100003122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.4",nocase; classtype:trojan-activity; sid:100003123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.129.233",nocase; classtype:trojan-activity; sid:100003124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.13.0",nocase; classtype:trojan-activity; sid:100003125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.170.209",nocase; classtype:trojan-activity; sid:100003126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.184.164",nocase; classtype:trojan-activity; sid:100003127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.211.20",nocase; classtype:trojan-activity; sid:100003128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.216.144",nocase; classtype:trojan-activity; sid:100003129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.234.187",nocase; classtype:trojan-activity; sid:100003130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.248.91",nocase; classtype:trojan-activity; sid:100003131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.66.24",nocase; classtype:trojan-activity; sid:100003132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.73.100",nocase; classtype:trojan-activity; sid:100003133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.63.58",nocase; classtype:trojan-activity; sid:100003134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.90.210",nocase; classtype:trojan-activity; sid:100003135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.93.109",nocase; classtype:trojan-activity; sid:100003136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.141.172",nocase; classtype:trojan-activity; sid:100003137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.155.96",nocase; classtype:trojan-activity; sid:100003138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.233.131",nocase; classtype:trojan-activity; sid:100003139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.67.238",nocase; classtype:trojan-activity; sid:100003140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.72.9",nocase; classtype:trojan-activity; sid:100003141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.198",nocase; classtype:trojan-activity; sid:100003142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.36",nocase; classtype:trojan-activity; sid:100003143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.157.140",nocase; classtype:trojan-activity; sid:100003144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.63.23",nocase; classtype:trojan-activity; sid:100003145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.90.86.212",nocase; classtype:trojan-activity; sid:100003146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"40.88.2.151",nocase; classtype:trojan-activity; sid:100003147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.139.209.46",nocase; classtype:trojan-activity; sid:100003148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.165.130.43",nocase; classtype:trojan-activity; sid:100003149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.193.192.100",nocase; classtype:trojan-activity; sid:100003150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.219.185.171",nocase; classtype:trojan-activity; sid:100003151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.230.31.58",nocase; classtype:trojan-activity; sid:100003152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.72.203.82",nocase; classtype:trojan-activity; sid:100003153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.133",nocase; classtype:trojan-activity; sid:100003154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.148",nocase; classtype:trojan-activity; sid:100003155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.157",nocase; classtype:trojan-activity; sid:100003156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.164",nocase; classtype:trojan-activity; sid:100003157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.165",nocase; classtype:trojan-activity; sid:100003158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.71",nocase; classtype:trojan-activity; sid:100003159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.19.206",nocase; classtype:trojan-activity; sid:100003160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.19.80",nocase; classtype:trojan-activity; sid:100003161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.38",nocase; classtype:trojan-activity; sid:100003162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.44",nocase; classtype:trojan-activity; sid:100003163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.62",nocase; classtype:trojan-activity; sid:100003164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.142",nocase; classtype:trojan-activity; sid:100003165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.198",nocase; classtype:trojan-activity; sid:100003166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.206",nocase; classtype:trojan-activity; sid:100003167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.176.112.72",nocase; classtype:trojan-activity; sid:100003168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.177.164.171",nocase; classtype:trojan-activity; sid:100003169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.179.162.208",nocase; classtype:trojan-activity; sid:100003170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.179.163.177",nocase; classtype:trojan-activity; sid:100003171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.202.101.147",nocase; classtype:trojan-activity; sid:100003172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.122.183",nocase; classtype:trojan-activity; sid:100003173; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.122.39",nocase; classtype:trojan-activity; sid:100003174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.169.111",nocase; classtype:trojan-activity; sid:100003175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.171.104",nocase; classtype:trojan-activity; sid:100003176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.172.125",nocase; classtype:trojan-activity; sid:100003177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.18.165",nocase; classtype:trojan-activity; sid:100003178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.171.104",nocase; classtype:trojan-activity; sid:100003175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.172.125",nocase; classtype:trojan-activity; sid:100003176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.188.223",nocase; classtype:trojan-activity; sid:100003177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.189.79",nocase; classtype:trojan-activity; sid:100003178; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.19.55",nocase; classtype:trojan-activity; sid:100003179; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.220.37",nocase; classtype:trojan-activity; sid:100003180; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.233.247",nocase; classtype:trojan-activity; sid:100003181; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.234.23",nocase; classtype:trojan-activity; sid:100003182; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.245.91",nocase; classtype:trojan-activity; sid:100003183; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.249.160",nocase; classtype:trojan-activity; sid:100003184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.36.220",nocase; classtype:trojan-activity; sid:100003185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.56.81",nocase; classtype:trojan-activity; sid:100003186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.69.11",nocase; classtype:trojan-activity; sid:100003187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.70.213",nocase; classtype:trojan-activity; sid:100003188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.120.122",nocase; classtype:trojan-activity; sid:100003189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.205.191",nocase; classtype:trojan-activity; sid:100003190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.241.5",nocase; classtype:trojan-activity; sid:100003191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.226.89.25",nocase; classtype:trojan-activity; sid:100003192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.194.95",nocase; classtype:trojan-activity; sid:100003193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.196.123",nocase; classtype:trojan-activity; sid:100003194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.66.88",nocase; classtype:trojan-activity; sid:100003195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.39.232",nocase; classtype:trojan-activity; sid:100003196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.40.56",nocase; classtype:trojan-activity; sid:100003197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.60.114",nocase; classtype:trojan-activity; sid:100003198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.67.135",nocase; classtype:trojan-activity; sid:100003199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.68.118",nocase; classtype:trojan-activity; sid:100003200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.70.126",nocase; classtype:trojan-activity; sid:100003201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.70.231",nocase; classtype:trojan-activity; sid:100003202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.84.206",nocase; classtype:trojan-activity; sid:100003203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.153.183",nocase; classtype:trojan-activity; sid:100003204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.219.175",nocase; classtype:trojan-activity; sid:100003205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.249.188",nocase; classtype:trojan-activity; sid:100003185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.3.187",nocase; classtype:trojan-activity; sid:100003186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.36.220",nocase; classtype:trojan-activity; sid:100003187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.52.81",nocase; classtype:trojan-activity; sid:100003188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.68.72",nocase; classtype:trojan-activity; sid:100003189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.69.11",nocase; classtype:trojan-activity; sid:100003190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.70.213",nocase; classtype:trojan-activity; sid:100003191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.120.122",nocase; classtype:trojan-activity; sid:100003192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.205.191",nocase; classtype:trojan-activity; sid:100003193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.241.5",nocase; classtype:trojan-activity; sid:100003194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.194.95",nocase; classtype:trojan-activity; sid:100003195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.196.123",nocase; classtype:trojan-activity; sid:100003196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.66.88",nocase; classtype:trojan-activity; sid:100003197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.196.68",nocase; classtype:trojan-activity; sid:100003198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.40.56",nocase; classtype:trojan-activity; sid:100003199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.60.114",nocase; classtype:trojan-activity; sid:100003200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.67.135",nocase; classtype:trojan-activity; sid:100003201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.68.118",nocase; classtype:trojan-activity; sid:100003202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.70.126",nocase; classtype:trojan-activity; sid:100003203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.70.231",nocase; classtype:trojan-activity; sid:100003204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.218.252",nocase; classtype:trojan-activity; sid:100003205; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.25.164",nocase; classtype:trojan-activity; sid:100003206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.48.162",nocase; classtype:trojan-activity; sid:100003207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.231.95.195",nocase; classtype:trojan-activity; sid:100003208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.232.102.163",nocase; classtype:trojan-activity; sid:100003209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.232.23.76",nocase; classtype:trojan-activity; sid:100003210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.233.78.236",nocase; classtype:trojan-activity; sid:100003211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.233.90.183",nocase; classtype:trojan-activity; sid:100003212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.234.85.184",nocase; classtype:trojan-activity; sid:100003213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.23.163",nocase; classtype:trojan-activity; sid:100003214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.3.187",nocase; classtype:trojan-activity; sid:100003215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.82.129",nocase; classtype:trojan-activity; sid:100003216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.86.211",nocase; classtype:trojan-activity; sid:100003217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.90.32",nocase; classtype:trojan-activity; sid:100003218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.95.254",nocase; classtype:trojan-activity; sid:100003219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.148.201",nocase; classtype:trojan-activity; sid:100003220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.237.252.159",nocase; classtype:trojan-activity; sid:100003221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.21.27",nocase; classtype:trojan-activity; sid:100003222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.98.70",nocase; classtype:trojan-activity; sid:100003223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.242.200.90",nocase; classtype:trojan-activity; sid:100003224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.56.15.227",nocase; classtype:trojan-activity; sid:100003225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.61.99.155",nocase; classtype:trojan-activity; sid:100003226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.84.37.198",nocase; classtype:trojan-activity; sid:100003227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.87.29.162",nocase; classtype:trojan-activity; sid:100003228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.230.156.44",nocase; classtype:trojan-activity; sid:100003229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.241.106.183",nocase; classtype:trojan-activity; sid:100003230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.137",nocase; classtype:trojan-activity; sid:100003231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.139",nocase; classtype:trojan-activity; sid:100003232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.242",nocase; classtype:trojan-activity; sid:100003233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.203.192",nocase; classtype:trojan-activity; sid:100003234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.135.134.228",nocase; classtype:trojan-activity; sid:100003235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.182",nocase; classtype:trojan-activity; sid:100003236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.204",nocase; classtype:trojan-activity; sid:100003237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.244",nocase; classtype:trojan-activity; sid:100003238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.66",nocase; classtype:trojan-activity; sid:100003239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.141.84.184",nocase; classtype:trojan-activity; sid:100003240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.142",nocase; classtype:trojan-activity; sid:100003241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.65",nocase; classtype:trojan-activity; sid:100003242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.47",nocase; classtype:trojan-activity; sid:100003243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.94",nocase; classtype:trojan-activity; sid:100003244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.116",nocase; classtype:trojan-activity; sid:100003245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.22",nocase; classtype:trojan-activity; sid:100003246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.248",nocase; classtype:trojan-activity; sid:100003247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.110.99",nocase; classtype:trojan-activity; sid:100003248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.154",nocase; classtype:trojan-activity; sid:100003249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.16",nocase; classtype:trojan-activity; sid:100003250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.202",nocase; classtype:trojan-activity; sid:100003251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.84",nocase; classtype:trojan-activity; sid:100003252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.178.101.22",nocase; classtype:trojan-activity; sid:100003253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.179.171.252",nocase; classtype:trojan-activity; sid:100003254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.22.209.58",nocase; classtype:trojan-activity; sid:100003255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.23.22.186",nocase; classtype:trojan-activity; sid:100003256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.231.210.27",nocase; classtype:trojan-activity; sid:100003257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.27.253.137",nocase; classtype:trojan-activity; sid:100003258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.33.112.19",nocase; classtype:trojan-activity; sid:100003259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.51.104.59",nocase; classtype:trojan-activity; sid:100003260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.81.235.31",nocase; classtype:trojan-activity; sid:100003261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.9.148.37",nocase; classtype:trojan-activity; sid:100003262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.151.155.218",nocase; classtype:trojan-activity; sid:100003263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.172.75.231",nocase; classtype:trojan-activity; sid:100003264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.175.184.121",nocase; classtype:trojan-activity; sid:100003265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.182.173.246",nocase; classtype:trojan-activity; sid:100003266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.182.173.247",nocase; classtype:trojan-activity; sid:100003267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.20.63.218",nocase; classtype:trojan-activity; sid:100003268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.21.153.231",nocase; classtype:trojan-activity; sid:100003269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.214.27.4",nocase; classtype:trojan-activity; sid:100003270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.24.130.254",nocase; classtype:trojan-activity; sid:100003271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.243.179.115",nocase; classtype:trojan-activity; sid:100003272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.249.33.79",nocase; classtype:trojan-activity; sid:100003273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.25.242.211",nocase; classtype:trojan-activity; sid:100003274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.118.86",nocase; classtype:trojan-activity; sid:100003275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.86.128",nocase; classtype:trojan-activity; sid:100003276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.97.76.242",nocase; classtype:trojan-activity; sid:100003277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.145.152.26",nocase; classtype:trojan-activity; sid:100003278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.151.23.172",nocase; classtype:trojan-activity; sid:100003279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.157.97.71",nocase; classtype:trojan-activity; sid:100003280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.16.131.51",nocase; classtype:trojan-activity; sid:100003281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.197.0.119",nocase; classtype:trojan-activity; sid:100003282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.21.202.98",nocase; classtype:trojan-activity; sid:100003283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.46.231.38",nocase; classtype:trojan-activity; sid:100003284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.162.113",nocase; classtype:trojan-activity; sid:100003285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.87.36",nocase; classtype:trojan-activity; sid:100003286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.143.32.36",nocase; classtype:trojan-activity; sid:100003287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.143.43.93",nocase; classtype:trojan-activity; sid:100003288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.156.35.166",nocase; classtype:trojan-activity; sid:100003289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.158.201.200",nocase; classtype:trojan-activity; sid:100003290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.20.121",nocase; classtype:trojan-activity; sid:100003291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.21.3",nocase; classtype:trojan-activity; sid:100003292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.174.182.99",nocase; classtype:trojan-activity; sid:100003293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.170.49",nocase; classtype:trojan-activity; sid:100003294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.178.183",nocase; classtype:trojan-activity; sid:100003295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.179.129",nocase; classtype:trojan-activity; sid:100003296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.68.221.252",nocase; classtype:trojan-activity; sid:100003297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.68.249.121",nocase; classtype:trojan-activity; sid:100003298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.70.15.16",nocase; classtype:trojan-activity; sid:100003299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.146.202.18",nocase; classtype:trojan-activity; sid:100003300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.181.135.114",nocase; classtype:trojan-activity; sid:100003301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.2.70.50",nocase; classtype:trojan-activity; sid:100003302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.53.146.179",nocase; classtype:trojan-activity; sid:100003303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.8.10.62",nocase; classtype:trojan-activity; sid:100003304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.102",nocase; classtype:trojan-activity; sid:100003305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.106",nocase; classtype:trojan-activity; sid:100003306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.121.91.255",nocase; classtype:trojan-activity; sid:100003307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.252.47.29",nocase; classtype:trojan-activity; sid:100003308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"51.171.146.13",nocase; classtype:trojan-activity; sid:100003309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"51.222.56.159",nocase; classtype:trojan-activity; sid:100003310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.114.136",nocase; classtype:trojan-activity; sid:100003311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.180.122",nocase; classtype:trojan-activity; sid:100003312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.114.246.26",nocase; classtype:trojan-activity; sid:100003313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.162.92",nocase; classtype:trojan-activity; sid:100003314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.174.4",nocase; classtype:trojan-activity; sid:100003315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.125.191.4",nocase; classtype:trojan-activity; sid:100003316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.126.247.118",nocase; classtype:trojan-activity; sid:100003317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.141.122.109",nocase; classtype:trojan-activity; sid:100003318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.166.120",nocase; classtype:trojan-activity; sid:100003319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.200.124",nocase; classtype:trojan-activity; sid:100003320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.143.142.142",nocase; classtype:trojan-activity; sid:100003321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.143.189.75",nocase; classtype:trojan-activity; sid:100003322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.18.103.109",nocase; classtype:trojan-activity; sid:100003323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.19.249.50",nocase; classtype:trojan-activity; sid:100003324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.218.67.253",nocase; classtype:trojan-activity; sid:100003325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.22.212.107",nocase; classtype:trojan-activity; sid:100003326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.226.129.29",nocase; classtype:trojan-activity; sid:100003327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.229.194.122",nocase; classtype:trojan-activity; sid:100003328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.23.245.24",nocase; classtype:trojan-activity; sid:100003329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.230.89.42",nocase; classtype:trojan-activity; sid:100003330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.238.42.192",nocase; classtype:trojan-activity; sid:100003331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.240.147.97",nocase; classtype:trojan-activity; sid:100003332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.57.237",nocase; classtype:trojan-activity; sid:100003333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.78.55",nocase; classtype:trojan-activity; sid:100003334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.243.126.133",nocase; classtype:trojan-activity; sid:100003335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.112.254",nocase; classtype:trojan-activity; sid:100003336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.140.46",nocase; classtype:trojan-activity; sid:100003337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.143.240",nocase; classtype:trojan-activity; sid:100003338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.144.122",nocase; classtype:trojan-activity; sid:100003339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.144.88",nocase; classtype:trojan-activity; sid:100003340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.147.235",nocase; classtype:trojan-activity; sid:100003341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.151.128",nocase; classtype:trojan-activity; sid:100003342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.153.224",nocase; classtype:trojan-activity; sid:100003343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.76.23",nocase; classtype:trojan-activity; sid:100003344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.77.38",nocase; classtype:trojan-activity; sid:100003345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.82.34",nocase; classtype:trojan-activity; sid:100003346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.12.80",nocase; classtype:trojan-activity; sid:100003347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.14.53",nocase; classtype:trojan-activity; sid:100003348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.16.173",nocase; classtype:trojan-activity; sid:100003349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.19.127",nocase; classtype:trojan-activity; sid:100003350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.23.58",nocase; classtype:trojan-activity; sid:100003351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.73.182",nocase; classtype:trojan-activity; sid:100003352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.74.197",nocase; classtype:trojan-activity; sid:100003353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.74.245",nocase; classtype:trojan-activity; sid:100003354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.75.107",nocase; classtype:trojan-activity; sid:100003355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.75.158",nocase; classtype:trojan-activity; sid:100003356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.77.88",nocase; classtype:trojan-activity; sid:100003357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.79.62",nocase; classtype:trojan-activity; sid:100003358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.82.35",nocase; classtype:trojan-activity; sid:100003359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.86.11",nocase; classtype:trojan-activity; sid:100003360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.87.54",nocase; classtype:trojan-activity; sid:100003361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.88.218",nocase; classtype:trojan-activity; sid:100003362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.252.176.71",nocase; classtype:trojan-activity; sid:100003363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.253.13.50",nocase; classtype:trojan-activity; sid:100003364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.48.154.143",nocase; classtype:trojan-activity; sid:100003365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.50.221.148",nocase; classtype:trojan-activity; sid:100003366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.153",nocase; classtype:trojan-activity; sid:100003367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.39",nocase; classtype:trojan-activity; sid:100003368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.76.151.189",nocase; classtype:trojan-activity; sid:100003369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.97.206.33",nocase; classtype:trojan-activity; sid:100003370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.0.211.161",nocase; classtype:trojan-activity; sid:100003371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.102.168.189",nocase; classtype:trojan-activity; sid:100003372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.202.3",nocase; classtype:trojan-activity; sid:100003373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.214.4",nocase; classtype:trojan-activity; sid:100003374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.29.133.229",nocase; classtype:trojan-activity; sid:100003375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.32.97.190",nocase; classtype:trojan-activity; sid:100003376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.42.62.0",nocase; classtype:trojan-activity; sid:100003377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.45.235.176",nocase; classtype:trojan-activity; sid:100003378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.58.104.244",nocase; classtype:trojan-activity; sid:100003379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.58.117.226",nocase; classtype:trojan-activity; sid:100003380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.7.124.148",nocase; classtype:trojan-activity; sid:100003381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.8.35.22",nocase; classtype:trojan-activity; sid:100003382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.176.186",nocase; classtype:trojan-activity; sid:100003383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.18.43",nocase; classtype:trojan-activity; sid:100003384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.181.100",nocase; classtype:trojan-activity; sid:100003385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.182.21",nocase; classtype:trojan-activity; sid:100003386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.182.84",nocase; classtype:trojan-activity; sid:100003387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.218.209",nocase; classtype:trojan-activity; sid:100003388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.218.254",nocase; classtype:trojan-activity; sid:100003389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.17.66",nocase; classtype:trojan-activity; sid:100003390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.18.37",nocase; classtype:trojan-activity; sid:100003391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.22.45",nocase; classtype:trojan-activity; sid:100003392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.94.180.222",nocase; classtype:trojan-activity; sid:100003393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.94.181.124",nocase; classtype:trojan-activity; sid:100003394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.94.183.163",nocase; classtype:trojan-activity; sid:100003395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.95.174.230",nocase; classtype:trojan-activity; sid:100003396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.95.175.37",nocase; classtype:trojan-activity; sid:100003397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.96.38.154",nocase; classtype:trojan-activity; sid:100003398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.96.38.182",nocase; classtype:trojan-activity; sid:100003399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.168.127",nocase; classtype:trojan-activity; sid:100003400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.169.111",nocase; classtype:trojan-activity; sid:100003401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.169.173",nocase; classtype:trojan-activity; sid:100003402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.171.61",nocase; classtype:trojan-activity; sid:100003403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.172.0",nocase; classtype:trojan-activity; sid:100003404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.173.49",nocase; classtype:trojan-activity; sid:100003405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.174.151",nocase; classtype:trojan-activity; sid:100003406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.175.163",nocase; classtype:trojan-activity; sid:100003407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.136.22",nocase; classtype:trojan-activity; sid:100003408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.136.63",nocase; classtype:trojan-activity; sid:100003409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.138.83",nocase; classtype:trojan-activity; sid:100003410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.139.190",nocase; classtype:trojan-activity; sid:100003411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.141.237",nocase; classtype:trojan-activity; sid:100003412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.40.173",nocase; classtype:trojan-activity; sid:100003413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.40.27",nocase; classtype:trojan-activity; sid:100003414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.41.192",nocase; classtype:trojan-activity; sid:100003415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.44.136",nocase; classtype:trojan-activity; sid:100003416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.44.201",nocase; classtype:trojan-activity; sid:100003417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.44.5",nocase; classtype:trojan-activity; sid:100003418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.47.220",nocase; classtype:trojan-activity; sid:100003419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.47.96",nocase; classtype:trojan-activity; sid:100003420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.93.136",nocase; classtype:trojan-activity; sid:100003421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.94.181",nocase; classtype:trojan-activity; sid:100003422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.13.61.12",nocase; classtype:trojan-activity; sid:100003423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.14.48.221",nocase; classtype:trojan-activity; sid:100003424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.16.247.78",nocase; classtype:trojan-activity; sid:100003425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.162.122.36",nocase; classtype:trojan-activity; sid:100003426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.164.130.220",nocase; classtype:trojan-activity; sid:100003427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.176.249.56",nocase; classtype:trojan-activity; sid:100003428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.184.149.169",nocase; classtype:trojan-activity; sid:100003429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.20.217.142",nocase; classtype:trojan-activity; sid:100003430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.208.135.42",nocase; classtype:trojan-activity; sid:100003431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.122.57",nocase; classtype:trojan-activity; sid:100003432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.186.185",nocase; classtype:trojan-activity; sid:100003433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.216.23",nocase; classtype:trojan-activity; sid:100003434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.233.94",nocase; classtype:trojan-activity; sid:100003435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.33.5",nocase; classtype:trojan-activity; sid:100003436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.19.63",nocase; classtype:trojan-activity; sid:100003437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.6.112",nocase; classtype:trojan-activity; sid:100003438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.100.83",nocase; classtype:trojan-activity; sid:100003439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.162.152",nocase; classtype:trojan-activity; sid:100003440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.202.218",nocase; classtype:trojan-activity; sid:100003441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.206.246",nocase; classtype:trojan-activity; sid:100003442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.218.31",nocase; classtype:trojan-activity; sid:100003443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.220.167",nocase; classtype:trojan-activity; sid:100003444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.23.84",nocase; classtype:trojan-activity; sid:100003445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.254.178",nocase; classtype:trojan-activity; sid:100003446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.162.59",nocase; classtype:trojan-activity; sid:100003447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.58.188",nocase; classtype:trojan-activity; sid:100003448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.83.55",nocase; classtype:trojan-activity; sid:100003449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.214.73.6",nocase; classtype:trojan-activity; sid:100003450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.214.93.166",nocase; classtype:trojan-activity; sid:100003451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.165.64",nocase; classtype:trojan-activity; sid:100003452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.195.111",nocase; classtype:trojan-activity; sid:100003453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.207.11",nocase; classtype:trojan-activity; sid:100003454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.4.239",nocase; classtype:trojan-activity; sid:100003455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.177.196",nocase; classtype:trojan-activity; sid:100003456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.86.208",nocase; classtype:trojan-activity; sid:100003457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.223.84.102",nocase; classtype:trojan-activity; sid:100003458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.25.109.240",nocase; classtype:trojan-activity; sid:100003459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.25.115.48",nocase; classtype:trojan-activity; sid:100003460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.25.76.224",nocase; classtype:trojan-activity; sid:100003461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.15.104",nocase; classtype:trojan-activity; sid:100003462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.39.88",nocase; classtype:trojan-activity; sid:100003463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.42.72",nocase; classtype:trojan-activity; sid:100003464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.51.127",nocase; classtype:trojan-activity; sid:100003465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.8.81",nocase; classtype:trojan-activity; sid:100003466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.26.17.221",nocase; classtype:trojan-activity; sid:100003467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.10.121",nocase; classtype:trojan-activity; sid:100003468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.8.43",nocase; classtype:trojan-activity; sid:100003469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.99.254",nocase; classtype:trojan-activity; sid:100003470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.102.243.124",nocase; classtype:trojan-activity; sid:100003471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.162.169.210",nocase; classtype:trojan-activity; sid:100003472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.162.55.42",nocase; classtype:trojan-activity; sid:100003473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.163.142.96",nocase; classtype:trojan-activity; sid:100003474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.164.96.98",nocase; classtype:trojan-activity; sid:100003475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.171.60",nocase; classtype:trojan-activity; sid:100003476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.194",nocase; classtype:trojan-activity; sid:100003477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.230",nocase; classtype:trojan-activity; sid:100003478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.18.112.48",nocase; classtype:trojan-activity; sid:100003479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.192.73.253",nocase; classtype:trojan-activity; sid:100003480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.213.118.28",nocase; classtype:trojan-activity; sid:100003481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.247.224.66",nocase; classtype:trojan-activity; sid:100003482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.253.94.230",nocase; classtype:trojan-activity; sid:100003483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.124.126",nocase; classtype:trojan-activity; sid:100003484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.124.8",nocase; classtype:trojan-activity; sid:100003485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.127.102",nocase; classtype:trojan-activity; sid:100003486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.149.89",nocase; classtype:trojan-activity; sid:100003487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.47.220.169",nocase; classtype:trojan-activity; sid:100003488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.103.144",nocase; classtype:trojan-activity; sid:100003489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.11.87",nocase; classtype:trojan-activity; sid:100003490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.159.231",nocase; classtype:trojan-activity; sid:100003491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.195.226",nocase; classtype:trojan-activity; sid:100003492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.212.191",nocase; classtype:trojan-activity; sid:100003493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.214.11",nocase; classtype:trojan-activity; sid:100003494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.237.212",nocase; classtype:trojan-activity; sid:100003495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.242.56",nocase; classtype:trojan-activity; sid:100003496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.48.40",nocase; classtype:trojan-activity; sid:100003497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.76.72",nocase; classtype:trojan-activity; sid:100003498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.9.166",nocase; classtype:trojan-activity; sid:100003499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.9.62",nocase; classtype:trojan-activity; sid:100003500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.99.161",nocase; classtype:trojan-activity; sid:100003501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.100.87",nocase; classtype:trojan-activity; sid:100003502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.102.137",nocase; classtype:trojan-activity; sid:100003503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.117.115",nocase; classtype:trojan-activity; sid:100003504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.119.161",nocase; classtype:trojan-activity; sid:100003505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.122.161",nocase; classtype:trojan-activity; sid:100003506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.123.162",nocase; classtype:trojan-activity; sid:100003507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.192.49",nocase; classtype:trojan-activity; sid:100003508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.2.35",nocase; classtype:trojan-activity; sid:100003509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.201.162",nocase; classtype:trojan-activity; sid:100003510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.54.255",nocase; classtype:trojan-activity; sid:100003511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.72.250",nocase; classtype:trojan-activity; sid:100003512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.81.18",nocase; classtype:trojan-activity; sid:100003513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.99.179",nocase; classtype:trojan-activity; sid:100003514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.103.56",nocase; classtype:trojan-activity; sid:100003515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.168.35",nocase; classtype:trojan-activity; sid:100003516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.232.45",nocase; classtype:trojan-activity; sid:100003517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.40.202",nocase; classtype:trojan-activity; sid:100003518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.58.190",nocase; classtype:trojan-activity; sid:100003519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.58.20",nocase; classtype:trojan-activity; sid:100003520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.63.23",nocase; classtype:trojan-activity; sid:100003521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.64.104",nocase; classtype:trojan-activity; sid:100003522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.76.122",nocase; classtype:trojan-activity; sid:100003523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.77.175",nocase; classtype:trojan-activity; sid:100003524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.180.67",nocase; classtype:trojan-activity; sid:100003525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.181.7",nocase; classtype:trojan-activity; sid:100003526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.57.96.116",nocase; classtype:trojan-activity; sid:100003527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.170.60",nocase; classtype:trojan-activity; sid:100003528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.73.220",nocase; classtype:trojan-activity; sid:100003529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.61.218.23",nocase; classtype:trojan-activity; sid:100003530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.65.172.121",nocase; classtype:trojan-activity; sid:100003531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.0.22",nocase; classtype:trojan-activity; sid:100003532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.104.46",nocase; classtype:trojan-activity; sid:100003533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.110.59",nocase; classtype:trojan-activity; sid:100003534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.195",nocase; classtype:trojan-activity; sid:100003535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.86",nocase; classtype:trojan-activity; sid:100003536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.255.60",nocase; classtype:trojan-activity; sid:100003537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.45.130",nocase; classtype:trojan-activity; sid:100003538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.98.144.75",nocase; classtype:trojan-activity; sid:100003539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.1.98.131",nocase; classtype:trojan-activity; sid:100003540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.117.124.114",nocase; classtype:trojan-activity; sid:100003541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.141.73.58",nocase; classtype:trojan-activity; sid:100003542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.131.205",nocase; classtype:trojan-activity; sid:100003543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.143.46",nocase; classtype:trojan-activity; sid:100003544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.155.61",nocase; classtype:trojan-activity; sid:100003545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.227.31",nocase; classtype:trojan-activity; sid:100003546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.31.126.33",nocase; classtype:trojan-activity; sid:100003547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.149.66",nocase; classtype:trojan-activity; sid:100003548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.222.98",nocase; classtype:trojan-activity; sid:100003549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.43.207.148",nocase; classtype:trojan-activity; sid:100003550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.90.165.236",nocase; classtype:trojan-activity; sid:100003551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"63.245.122.93",nocase; classtype:trojan-activity; sid:100003552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"64.233.154.99",nocase; classtype:trojan-activity; sid:100003553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.125.128.196",nocase; classtype:trojan-activity; sid:100003554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.21.58.252",nocase; classtype:trojan-activity; sid:100003555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.26.155.131",nocase; classtype:trojan-activity; sid:100003556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.35.61.255",nocase; classtype:trojan-activity; sid:100003557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.153.233.87",nocase; classtype:trojan-activity; sid:100003558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.229.214.115",nocase; classtype:trojan-activity; sid:100003559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.57.55.210",nocase; classtype:trojan-activity; sid:100003560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.74.7.197",nocase; classtype:trojan-activity; sid:100003561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.91.21.31",nocase; classtype:trojan-activity; sid:100003562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.196",nocase; classtype:trojan-activity; sid:100003563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.213",nocase; classtype:trojan-activity; sid:100003564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.245.151.203",nocase; classtype:trojan-activity; sid:100003565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.3.169.223",nocase; classtype:trojan-activity; sid:100003566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.8.138.101",nocase; classtype:trojan-activity; sid:100003567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.81.98.111",nocase; classtype:trojan-activity; sid:100003568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.82.242.243",nocase; classtype:trojan-activity; sid:100003569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.83.49.234",nocase; classtype:trojan-activity; sid:100003570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.84.138.165",nocase; classtype:trojan-activity; sid:100003571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.151.244.128",nocase; classtype:trojan-activity; sid:100003572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.174.182.226",nocase; classtype:trojan-activity; sid:100003573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.175.107.153",nocase; classtype:trojan-activity; sid:100003574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.188.144.143",nocase; classtype:trojan-activity; sid:100003575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.204.88.29",nocase; classtype:trojan-activity; sid:100003576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.106.84",nocase; classtype:trojan-activity; sid:100003577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.119.241",nocase; classtype:trojan-activity; sid:100003578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.78.33.33",nocase; classtype:trojan-activity; sid:100003579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.115.37.205",nocase; classtype:trojan-activity; sid:100003580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.120.237.255",nocase; classtype:trojan-activity; sid:100003581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.123.245.151",nocase; classtype:trojan-activity; sid:100003582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.124.231.110",nocase; classtype:trojan-activity; sid:100003583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.127.214.47",nocase; classtype:trojan-activity; sid:100003584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.146.232.34",nocase; classtype:trojan-activity; sid:100003585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.165.173.49",nocase; classtype:trojan-activity; sid:100003586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.196.158.227",nocase; classtype:trojan-activity; sid:100003587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.222.157.166",nocase; classtype:trojan-activity; sid:100003588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.229.0.133",nocase; classtype:trojan-activity; sid:100003589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.63.73.234",nocase; classtype:trojan-activity; sid:100003590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.115.194",nocase; classtype:trojan-activity; sid:100003591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.227.186",nocase; classtype:trojan-activity; sid:100003592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.76.240.206",nocase; classtype:trojan-activity; sid:100003593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.115.31.30",nocase; classtype:trojan-activity; sid:100003594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.118.240.88",nocase; classtype:trojan-activity; sid:100003595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.167.10.180",nocase; classtype:trojan-activity; sid:100003596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.236.190.250",nocase; classtype:trojan-activity; sid:100003597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.25.5.105",nocase; classtype:trojan-activity; sid:100003598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.93.129.118",nocase; classtype:trojan-activity; sid:100003599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.127.148.69",nocase; classtype:trojan-activity; sid:100003600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.146.190.91",nocase; classtype:trojan-activity; sid:100003601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.167.164.113",nocase; classtype:trojan-activity; sid:100003602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.19.150.93",nocase; classtype:trojan-activity; sid:100003603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.204.63.239",nocase; classtype:trojan-activity; sid:100003604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.29.48.164",nocase; classtype:trojan-activity; sid:100003605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.34.191.213",nocase; classtype:trojan-activity; sid:100003606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.40.234.166",nocase; classtype:trojan-activity; sid:100003607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.106.142",nocase; classtype:trojan-activity; sid:100003608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.2.122",nocase; classtype:trojan-activity; sid:100003609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.235.106",nocase; classtype:trojan-activity; sid:100003610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.47.133.58",nocase; classtype:trojan-activity; sid:100003611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.71.60.69",nocase; classtype:trojan-activity; sid:100003612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.85.106.211",nocase; classtype:trojan-activity; sid:100003613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.17.22.30",nocase; classtype:trojan-activity; sid:100003614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.186.139.38",nocase; classtype:trojan-activity; sid:100003615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.180.98",nocase; classtype:trojan-activity; sid:100003616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.200.62",nocase; classtype:trojan-activity; sid:100003617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.214.69.226",nocase; classtype:trojan-activity; sid:100003618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.230.118",nocase; classtype:trojan-activity; sid:100003619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.35.40",nocase; classtype:trojan-activity; sid:100003620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.204.216.103",nocase; classtype:trojan-activity; sid:100003621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.101.1.159",nocase; classtype:trojan-activity; sid:100003622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.108.224.112",nocase; classtype:trojan-activity; sid:100003623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.194.117.165",nocase; classtype:trojan-activity; sid:100003624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.195.115.176",nocase; classtype:trojan-activity; sid:100003625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.199.84.77",nocase; classtype:trojan-activity; sid:100003626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.64.139.223",nocase; classtype:trojan-activity; sid:100003627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.75.165.81",nocase; classtype:trojan-activity; sid:100003628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.127.141.52",nocase; classtype:trojan-activity; sid:100003629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.176.213.114",nocase; classtype:trojan-activity; sid:100003630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.83.102.27",nocase; classtype:trojan-activity; sid:100003631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.99.213.61",nocase; classtype:trojan-activity; sid:100003632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.108.199.153",nocase; classtype:trojan-activity; sid:100003633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.170.11.82",nocase; classtype:trojan-activity; sid:100003634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.178.22.145",nocase; classtype:trojan-activity; sid:100003635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.250.199.133",nocase; classtype:trojan-activity; sid:100003636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.254.129.227",nocase; classtype:trojan-activity; sid:100003637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.84.134.33",nocase; classtype:trojan-activity; sid:100003638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.95.12.137",nocase; classtype:trojan-activity; sid:100003639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.237.25.210",nocase; classtype:trojan-activity; sid:100003640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.50.153",nocase; classtype:trojan-activity; sid:100003641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.52.220",nocase; classtype:trojan-activity; sid:100003642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.79.191.32",nocase; classtype:trojan-activity; sid:100003643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.89.203.238",nocase; classtype:trojan-activity; sid:100003644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.186.155.18",nocase; classtype:trojan-activity; sid:100003645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.141.144",nocase; classtype:trojan-activity; sid:100003646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.240.125",nocase; classtype:trojan-activity; sid:100003647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.41.200",nocase; classtype:trojan-activity; sid:100003648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.168.64",nocase; classtype:trojan-activity; sid:100003649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.188.141",nocase; classtype:trojan-activity; sid:100003650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.104.157",nocase; classtype:trojan-activity; sid:100003651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.176.163",nocase; classtype:trojan-activity; sid:100003652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.23.172.81",nocase; classtype:trojan-activity; sid:100003653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.8.225.77",nocase; classtype:trojan-activity; sid:100003654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.11.195.121",nocase; classtype:trojan-activity; sid:100003655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.13.49.221",nocase; classtype:trojan-activity; sid:100003656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.130.253.13",nocase; classtype:trojan-activity; sid:100003657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.147.123.48",nocase; classtype:trojan-activity; sid:100003658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.170.31.56",nocase; classtype:trojan-activity; sid:100003659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.175.42.244",nocase; classtype:trojan-activity; sid:100003660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.21.84.63",nocase; classtype:trojan-activity; sid:100003661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.7.170.58",nocase; classtype:trojan-activity; sid:100003662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.79.58.94",nocase; classtype:trojan-activity; sid:100003663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.8.70.162",nocase; classtype:trojan-activity; sid:100003664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.9.88.185",nocase; classtype:trojan-activity; sid:100003665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.107.89.207",nocase; classtype:trojan-activity; sid:100003666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.19.101.218",nocase; classtype:trojan-activity; sid:100003667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.211.181.77",nocase; classtype:trojan-activity; sid:100003668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.217.12.7",nocase; classtype:trojan-activity; sid:100003669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.67.32.66",nocase; classtype:trojan-activity; sid:100003670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.99.128.61",nocase; classtype:trojan-activity; sid:100003671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.136.146.213",nocase; classtype:trojan-activity; sid:100003672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.165.44.109",nocase; classtype:trojan-activity; sid:100003673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.191.40.58",nocase; classtype:trojan-activity; sid:100003674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.111.60",nocase; classtype:trojan-activity; sid:100003675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.141.184",nocase; classtype:trojan-activity; sid:100003676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.215.199.29",nocase; classtype:trojan-activity; sid:100003677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.187.113",nocase; classtype:trojan-activity; sid:100003678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.195.216",nocase; classtype:trojan-activity; sid:100003679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.237.128.200",nocase; classtype:trojan-activity; sid:100003680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.246.225.203",nocase; classtype:trojan-activity; sid:100003681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.92.36.96",nocase; classtype:trojan-activity; sid:100003682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.103.108.72",nocase; classtype:trojan-activity; sid:100003683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.135.196.130",nocase; classtype:trojan-activity; sid:100003684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.212.178",nocase; classtype:trojan-activity; sid:100003685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.85.112",nocase; classtype:trojan-activity; sid:100003686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.207.61.194",nocase; classtype:trojan-activity; sid:100003687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.209.250.155",nocase; classtype:trojan-activity; sid:100003688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.211.156.38",nocase; classtype:trojan-activity; sid:100003689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.110.252",nocase; classtype:trojan-activity; sid:100003690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.53.77",nocase; classtype:trojan-activity; sid:100003691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.138.72",nocase; classtype:trojan-activity; sid:100003692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.139.92",nocase; classtype:trojan-activity; sid:100003693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.154.214",nocase; classtype:trojan-activity; sid:100003694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.187.109",nocase; classtype:trojan-activity; sid:100003695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.100.54",nocase; classtype:trojan-activity; sid:100003696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.106.65",nocase; classtype:trojan-activity; sid:100003697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.108.172",nocase; classtype:trojan-activity; sid:100003698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.131.158",nocase; classtype:trojan-activity; sid:100003699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.19.42",nocase; classtype:trojan-activity; sid:100003700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.197.254",nocase; classtype:trojan-activity; sid:100003701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.215.149",nocase; classtype:trojan-activity; sid:100003702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.232.68",nocase; classtype:trojan-activity; sid:100003703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.234.195",nocase; classtype:trojan-activity; sid:100003704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.246.96",nocase; classtype:trojan-activity; sid:100003705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.28.57",nocase; classtype:trojan-activity; sid:100003706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.4.57",nocase; classtype:trojan-activity; sid:100003707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.55.84",nocase; classtype:trojan-activity; sid:100003708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.73.245",nocase; classtype:trojan-activity; sid:100003709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.9.62",nocase; classtype:trojan-activity; sid:100003710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.98.51",nocase; classtype:trojan-activity; sid:100003711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.165.237.163",nocase; classtype:trojan-activity; sid:100003712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.147.99",nocase; classtype:trojan-activity; sid:100003713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.218.42",nocase; classtype:trojan-activity; sid:100003714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.242.253.154",nocase; classtype:trojan-activity; sid:100003715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.252.9.37",nocase; classtype:trojan-activity; sid:100003716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.208",nocase; classtype:trojan-activity; sid:100003717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.213",nocase; classtype:trojan-activity; sid:100003718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.212.219.127",nocase; classtype:trojan-activity; sid:100003719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.224.162.170",nocase; classtype:trojan-activity; sid:100003720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.50.118",nocase; classtype:trojan-activity; sid:100003721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.95.204",nocase; classtype:trojan-activity; sid:100003722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.247.83.74",nocase; classtype:trojan-activity; sid:100003723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.254.39.129",nocase; classtype:trojan-activity; sid:100003724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.33.111.227",nocase; classtype:trojan-activity; sid:100003725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.40.127.242",nocase; classtype:trojan-activity; sid:100003726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.42.20.217",nocase; classtype:trojan-activity; sid:100003727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com",nocase; classtype:trojan-activity; sid:100003728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.11.216",nocase; classtype:trojan-activity; sid:100003729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.123.251",nocase; classtype:trojan-activity; sid:100003730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.135.187",nocase; classtype:trojan-activity; sid:100003731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.208.25",nocase; classtype:trojan-activity; sid:100003732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.224.141",nocase; classtype:trojan-activity; sid:100003733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.241.2",nocase; classtype:trojan-activity; sid:100003734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.214.149.236",nocase; classtype:trojan-activity; sid:100003735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.64.181.50",nocase; classtype:trojan-activity; sid:100003736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.74.215.180",nocase; classtype:trojan-activity; sid:100003737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.130.227",nocase; classtype:trojan-activity; sid:100003738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.195.129",nocase; classtype:trojan-activity; sid:100003739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"86.35.43.220",nocase; classtype:trojan-activity; sid:100003740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.61.89.40",nocase; classtype:trojan-activity; sid:100003741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.119.171.253",nocase; classtype:trojan-activity; sid:100003742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.208.71",nocase; classtype:trojan-activity; sid:100003743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.219.179",nocase; classtype:trojan-activity; sid:100003744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.225.222.128",nocase; classtype:trojan-activity; sid:100003745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.247.96.19",nocase; classtype:trojan-activity; sid:100003746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.136.231",nocase; classtype:trojan-activity; sid:100003747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.51.139",nocase; classtype:trojan-activity; sid:100003748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.249.244.180",nocase; classtype:trojan-activity; sid:100003749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.204.12",nocase; classtype:trojan-activity; sid:100003750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.226.26",nocase; classtype:trojan-activity; sid:100003751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.254.90",nocase; classtype:trojan-activity; sid:100003752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.122.183.130",nocase; classtype:trojan-activity; sid:100003753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.29.213.33",nocase; classtype:trojan-activity; sid:100003754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.34.26.165",nocase; classtype:trojan-activity; sid:100003755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.35.62.96",nocase; classtype:trojan-activity; sid:100003756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.85.166",nocase; classtype:trojan-activity; sid:100003757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.87.5",nocase; classtype:trojan-activity; sid:100003758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.46.237.89",nocase; classtype:trojan-activity; sid:100003759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8poieq.bn.files.1drv.com",nocase; classtype:trojan-activity; sid:100003760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"90.152.144.139",nocase; classtype:trojan-activity; sid:100003761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"90.63.176.144",nocase; classtype:trojan-activity; sid:100003762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.177.139.132",nocase; classtype:trojan-activity; sid:100003763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.187.103.32",nocase; classtype:trojan-activity; sid:100003764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.212.150.241",nocase; classtype:trojan-activity; sid:100003765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.217.104.185",nocase; classtype:trojan-activity; sid:100003766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.233.112.188",nocase; classtype:trojan-activity; sid:100003767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.234.60.94",nocase; classtype:trojan-activity; sid:100003768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.239.168.83",nocase; classtype:trojan-activity; sid:100003769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.244.169.139",nocase; classtype:trojan-activity; sid:100003770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.92.16.244",nocase; classtype:trojan-activity; sid:100003771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.98.4.181",nocase; classtype:trojan-activity; sid:100003772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.113.93.34",nocase; classtype:trojan-activity; sid:100003773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.114.191.82",nocase; classtype:trojan-activity; sid:100003774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.241.78.114",nocase; classtype:trojan-activity; sid:100003775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.27.246.202",nocase; classtype:trojan-activity; sid:100003776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.54.237.143",nocase; classtype:trojan-activity; sid:100003777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.54.237.237",nocase; classtype:trojan-activity; sid:100003778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.83.62.139",nocase; classtype:trojan-activity; sid:100003779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.85.18.138",nocase; classtype:trojan-activity; sid:100003780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.171.157.73",nocase; classtype:trojan-activity; sid:100003781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.21.224.154",nocase; classtype:trojan-activity; sid:100003782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.115.176",nocase; classtype:trojan-activity; sid:100003783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.137.16",nocase; classtype:trojan-activity; sid:100003784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.182.249",nocase; classtype:trojan-activity; sid:100003785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.206.56",nocase; classtype:trojan-activity; sid:100003786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.57.43.233",nocase; classtype:trojan-activity; sid:100003787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.73.99.102",nocase; classtype:trojan-activity; sid:100003788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.136.69.199",nocase; classtype:trojan-activity; sid:100003789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.143.53.34",nocase; classtype:trojan-activity; sid:100003790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.17.170",nocase; classtype:trojan-activity; sid:100003791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.82.190",nocase; classtype:trojan-activity; sid:100003792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.200.16.22",nocase; classtype:trojan-activity; sid:100003793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.224.83.208",nocase; classtype:trojan-activity; sid:100003794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.53.120.109",nocase; classtype:trojan-activity; sid:100003795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.132.129.250",nocase; classtype:trojan-activity; sid:100003796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.153.241.63",nocase; classtype:trojan-activity; sid:100003797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.154.20.231",nocase; classtype:trojan-activity; sid:100003798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.158.19.130",nocase; classtype:trojan-activity; sid:100003799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.113.52",nocase; classtype:trojan-activity; sid:100003800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.201.34",nocase; classtype:trojan-activity; sid:100003801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.181.155.112",nocase; classtype:trojan-activity; sid:100003802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.146.134",nocase; classtype:trojan-activity; sid:100003803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.6.114",nocase; classtype:trojan-activity; sid:100003804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.66.196.63",nocase; classtype:trojan-activity; sid:100003805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.9.120.40",nocase; classtype:trojan-activity; sid:100003806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.239.73.246",nocase; classtype:trojan-activity; sid:100003807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.47.147.169",nocase; classtype:trojan-activity; sid:100003808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.103.64.196",nocase; classtype:trojan-activity; sid:100003809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.68.140.254",nocase; classtype:trojan-activity; sid:100003810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.96.199.75",nocase; classtype:trojan-activity; sid:100003811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.210.218",nocase; classtype:trojan-activity; sid:100003812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.239.142",nocase; classtype:trojan-activity; sid:100003813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.113.239.207",nocase; classtype:trojan-activity; sid:100003814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.116.72.119",nocase; classtype:trojan-activity; sid:100003815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.128.147.115",nocase; classtype:trojan-activity; sid:100003816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.178.242.44",nocase; classtype:trojan-activity; sid:100003817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.249.236.11",nocase; classtype:trojan-activity; sid:100003818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.28.200.139",nocase; classtype:trojan-activity; sid:100003819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.30.24.54",nocase; classtype:trojan-activity; sid:100003820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.150.245.203",nocase; classtype:trojan-activity; sid:100003821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.33.195.164",nocase; classtype:trojan-activity; sid:100003822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99centsdigitals.com",nocase; classtype:trojan-activity; sid:100003823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abcd.bg",nocase; classtype:trojan-activity; sid:100003824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abclicks.in",nocase; classtype:trojan-activity; sid:100003825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abissnet.net",nocase; classtype:trojan-activity; sid:100003826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aboveandbelow.com.au",nocase; classtype:trojan-activity; sid:100003827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absoftechworld.com",nocase; classtype:trojan-activity; sid:100003828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absupplies.co.uk",nocase; classtype:trojan-activity; sid:100003829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abyssos.eu",nocase; classtype:trojan-activity; sid:100003830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acbick.com",nocase; classtype:trojan-activity; sid:100003831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"accounts.thesmarttechhub.com",nocase; classtype:trojan-activity; sid:100003832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aceeprc.com.aceeprc.com",nocase; classtype:trojan-activity; sid:100003833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acellr.co.uk",nocase; classtype:trojan-activity; sid:100003834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aciabogados.com",nocase; classtype:trojan-activity; sid:100003835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acteon.com.ar",nocase; classtype:trojan-activity; sid:100003836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"activateyourdiscount.com",nocase; classtype:trojan-activity; sid:100003837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"activecost.com.au",nocase; classtype:trojan-activity; sid:100003838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adamorinmusic.com",nocase; classtype:trojan-activity; sid:100003839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"addahealingmusic.com",nocase; classtype:trojan-activity; sid:100003840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.com",nocase; classtype:trojan-activity; sid:100003841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.memengers.com",nocase; classtype:trojan-activity; sid:100003842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.erapor.smk-alasror.net",nocase; classtype:trojan-activity; sid:100003843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.gentbcn.org",nocase; classtype:trojan-activity; sid:100003844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.grandoceanvilla.com",nocase; classtype:trojan-activity; sid:100003845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adventureexplorer.in",nocase; classtype:trojan-activity; sid:100003846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aeropilates.cl",nocase; classtype:trojan-activity; sid:100003847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afrimedspecialist.com",nocase; classtype:trojan-activity; sid:100003848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agemn.co.za",nocase; classtype:trojan-activity; sid:100003849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciadigitalwdys.com",nocase; classtype:trojan-activity; sid:100003850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciatabletshouse.com.br",nocase; classtype:trojan-activity; sid:100003851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenda.gmelloinformatica.com.br",nocase; classtype:trojan-activity; sid:100003852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agentt.ac.ug",nocase; classtype:trojan-activity; sid:100003853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agile8studio.com",nocase; classtype:trojan-activity; sid:100003854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agmcarpetcare.co.uk",nocase; classtype:trojan-activity; sid:100003855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiqtest.com",nocase; classtype:trojan-activity; sid:100003856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajpharmaholding.com",nocase; classtype:trojan-activity; sid:100003857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajstudiollc.com",nocase; classtype:trojan-activity; sid:100003858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"akivj07.top",nocase; classtype:trojan-activity; sid:100003859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"al-wahd.com",nocase; classtype:trojan-activity; sid:100003860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alasdemariposas.org",nocase; classtype:trojan-activity; sid:100003861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alemelektronik.com",nocase; classtype:trojan-activity; sid:100003862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alena1971.es",nocase; classtype:trojan-activity; sid:100003863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alexdubai.com.aldiabsteel.com",nocase; classtype:trojan-activity; sid:100003864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"algreenstdykelveskbg.dns.army",nocase; classtype:trojan-activity; sid:100003865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alka.institute",nocase; classtype:trojan-activity; sid:100003866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"allforcreative.com.au",nocase; classtype:trojan-activity; sid:100003867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alltheway.travel",nocase; classtype:trojan-activity; sid:100003868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alpaylar.com.tr",nocase; classtype:trojan-activity; sid:100003869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"am-concepts.ca",nocase; classtype:trojan-activity; sid:100003870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amamontajes.com",nocase; classtype:trojan-activity; sid:100003871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarresdeamorymaestroshechiceros.com",nocase; classtype:trojan-activity; sid:100003872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarteargentina.com.ar",nocase; classtype:trojan-activity; sid:100003873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amenyan.zouri.jp",nocase; classtype:trojan-activity; sid:100003874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amos524.org",nocase; classtype:trojan-activity; sid:100003875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ams.alvinasschools.org.ng",nocase; classtype:trojan-activity; sid:100003876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anantam.net.in",nocase; classtype:trojan-activity; sid:100003877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreelapeyre.com",nocase; classtype:trojan-activity; sid:100003878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andremaraisbeleggings.co.za",nocase; classtype:trojan-activity; sid:100003879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ac.ug",nocase; classtype:trojan-activity; sid:100003880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ug",nocase; classtype:trojan-activity; sid:100003881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreshconcejal.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelazgheibld.com",nocase; classtype:trojan-activity; sid:100003883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelsdetour.com",nocase; classtype:trojan-activity; sid:100003884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angloteste.bigprime.com.br",nocase; classtype:trojan-activity; sid:100003885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anhung1102.vn",nocase; classtype:trojan-activity; sid:100003886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anysbergbiltong.co.za",nocase; classtype:trojan-activity; sid:100003887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apartamentoscitta.com",nocase; classtype:trojan-activity; sid:100003888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api-ms.cobainaja.id",nocase; classtype:trojan-activity; sid:100003889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.cstdevs.com",nocase; classtype:trojan-activity; sid:100003890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.quocbao.biz",nocase; classtype:trojan-activity; sid:100003891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.sampy.io",nocase; classtype:trojan-activity; sid:100003892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apoolcondo.com",nocase; classtype:trojan-activity; sid:100003893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.adsensearticle.com",nocase; classtype:trojan-activity; sid:100003894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.explicitsurveys.co.uk",nocase; classtype:trojan-activity; sid:100003895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.prerana.info",nocase; classtype:trojan-activity; sid:100003896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apps.saintsoporte.com",nocase; classtype:trojan-activity; sid:100003897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aqv.news",nocase; classtype:trojan-activity; sid:100003898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"areyoulivingwell.com",nocase; classtype:trojan-activity; sid:100003899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"arsapetrolab.com",nocase; classtype:trojan-activity; sid:100003900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"artedibujoyarquitectura.com",nocase; classtype:trojan-activity; sid:100003901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ask-regard.call-save.biz",nocase; classtype:trojan-activity; sid:100003902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atfile.com",nocase; classtype:trojan-activity; sid:100003903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"athenacapsg.com",nocase; classtype:trojan-activity; sid:100003904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atlasconcreteworks.com",nocase; classtype:trojan-activity; sid:100003905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atnetech.com",nocase; classtype:trojan-activity; sid:100003906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"attach.66rpg.com",nocase; classtype:trojan-activity; sid:100003907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atteuqpotentialunlimited.com",nocase; classtype:trojan-activity; sid:100003908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"augustair.com",nocase; classtype:trojan-activity; sid:100003909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aulist.com",nocase; classtype:trojan-activity; sid:100003910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"australiafashions.com",nocase; classtype:trojan-activity; sid:100003911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"automaticrefreshments.com",nocase; classtype:trojan-activity; sid:100003912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"avadhanagames.com",nocase; classtype:trojan-activity; sid:100003913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"avissrilanka.com",nocase; classtype:trojan-activity; sid:100003914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayamallah.com",nocase; classtype:trojan-activity; sid:100003915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azmeasurement.com",nocase; classtype:trojan-activity; sid:100003916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azraktours.com",nocase; classtype:trojan-activity; sid:100003917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"b2b.toptanakaryakit.com.tr",nocase; classtype:trojan-activity; sid:100003918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"backgrounds.pk",nocase; classtype:trojan-activity; sid:100003919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"badeggdesign.com",nocase; classtype:trojan-activity; sid:100003920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"balealgodon.mx",nocase; classtype:trojan-activity; sid:100003921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangkok-orchids.com",nocase; classtype:trojan-activity; sid:100003922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"barcionstw.eastus.cloudapp.azure.com",nocase; classtype:trojan-activity; sid:100003923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bary.sz4h.com",nocase; classtype:trojan-activity; sid:100003924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bash.givemexyz.in",nocase; classtype:trojan-activity; sid:100003925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"basma.com.kw",nocase; classtype:trojan-activity; sid:100003926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk",nocase; classtype:trojan-activity; sid:100003927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bavhome.com",nocase; classtype:trojan-activity; sid:100003928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bbia.co.uk",nocase; classtype:trojan-activity; sid:100003929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcmt.elin.co.za",nocase; classtype:trojan-activity; sid:100003930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcrg.co.za",nocase; classtype:trojan-activity; sid:100003931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bearcatpumps.com.cn",nocase; classtype:trojan-activity; sid:100003932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beautincollagen.rs",nocase; classtype:trojan-activity; sid:100003933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bekape.co.id",nocase; classtype:trojan-activity; sid:100003934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bespokeweddings.ie",nocase; classtype:trojan-activity; sid:100003935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bestcarenepal.com",nocase; classtype:trojan-activity; sid:100003936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betone.co.kr",nocase; classtype:trojan-activity; sid:100003937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betycopaints.com",nocase; classtype:trojan-activity; sid:100003938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beveragesmiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bhavaniengineering.com",nocase; classtype:trojan-activity; sid:100003940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bigbag.wootraining.certificacion.cl",nocase; classtype:trojan-activity; sid:100003941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilbosaquet.ug",nocase; classtype:trojan-activity; sid:100003942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilhen.co.za",nocase; classtype:trojan-activity; sid:100003943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"billing.rahitechnosoft.com",nocase; classtype:trojan-activity; sid:100003944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"binoy.stalphonsamissionva.org",nocase; classtype:trojan-activity; sid:100003945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birdi.elin.co.za",nocase; classtype:trojan-activity; sid:100003946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birminghamlink.org",nocase; classtype:trojan-activity; sid:100003947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.callensaxen.com",nocase; classtype:trojan-activity; sid:100003948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.oyinblogs.com",nocase; classtype:trojan-activity; sid:100003949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.takbelit.com",nocase; classtype:trojan-activity; sid:100003950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bmlifestyle.co.uk",nocase; classtype:trojan-activity; sid:100003951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bnrbook.com",nocase; classtype:trojan-activity; sid:100003952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bnrnews.id",nocase; classtype:trojan-activity; sid:100003953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bodenstein.co.za",nocase; classtype:trojan-activity; sid:100003954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"booksearch.com",nocase; classtype:trojan-activity; sid:100003955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bounces.mi-fs.com",nocase; classtype:trojan-activity; sid:100003956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bpo.correct.go.th",nocase; classtype:trojan-activity; sid:100003957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brandtrust.com.pk",nocase; classtype:trojan-activity; sid:100003958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brendanquine.com",nocase; classtype:trojan-activity; sid:100003959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brideofmessiah.com",nocase; classtype:trojan-activity; sid:100003960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bridesofmaldives.com",nocase; classtype:trojan-activity; sid:100003961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightmega.com",nocase; classtype:trojan-activity; sid:100003962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightonrooms.co.uk",nocase; classtype:trojan-activity; sid:100003963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightstarshop.com",nocase; classtype:trojan-activity; sid:100003964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"browardinsurancemiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bt2.elin.co.za",nocase; classtype:trojan-activity; sid:100003966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"btdapi.robotake.com",nocase; classtype:trojan-activity; sid:100003967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bucrinsuranlceonlines.com",nocase; classtype:trojan-activity; sid:100003968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buenavista.co",nocase; classtype:trojan-activity; sid:100003969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buigiaphat.com.vn",nocase; classtype:trojan-activity; sid:100003970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bullseyemedia.in",nocase; classtype:trojan-activity; sid:100003971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"busandvanrentalmalaysia.com",nocase; classtype:trojan-activity; sid:100003972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buscascolegios.diit.cl",nocase; classtype:trojan-activity; sid:100003973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business.softberg.ro",nocase; classtype:trojan-activity; sid:100003974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buyingmusiconline.com",nocase; classtype:trojan-activity; sid:100003975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bwsr.eu",nocase; classtype:trojan-activity; sid:100003976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c.oooooooooo.ga",nocase; classtype:trojan-activity; sid:100003977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c0140529.ferozo.com",nocase; classtype:trojan-activity; sid:100003978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"caballo.com.au",nocase; classtype:trojan-activity; sid:100003979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"calgaryautorepairservice.com",nocase; classtype:trojan-activity; sid:100003980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"callbury.in",nocase; classtype:trojan-activity; sid:100003981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"camminachetipassa.it",nocase; classtype:trojan-activity; sid:100003982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"campusvirtual.cepsanjuanbosco.net.pe",nocase; classtype:trojan-activity; sid:100003983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cancer.educandome.co",nocase; classtype:trojan-activity; sid:100003984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalgroup-kw.com",nocase; classtype:trojan-activity; sid:100003985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalnewsagency.com",nocase; classtype:trojan-activity; sid:100003986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capoeiraventrelivre.com",nocase; classtype:trojan-activity; sid:100003987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cashyinvestment.org",nocase; classtype:trojan-activity; sid:100003988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchpoolshetlands.co.uk",nocase; classtype:trojan-activity; sid:100003989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cazyacustomfurniture.com",nocase; classtype:trojan-activity; sid:100003990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ccauthority.net",nocase; classtype:trojan-activity; sid:100003991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdaonline.com.ar",nocase; classtype:trojan-activity; sid:100003992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cec.asso.ac-amiens.fr",nocase; classtype:trojan-activity; sid:100003993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cellas.sk",nocase; classtype:trojan-activity; sid:100003994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cendekiabinaaksara.com",nocase; classtype:trojan-activity; sid:100003995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cespol-bote.com.mx",nocase; classtype:trojan-activity; sid:100003996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cfs5.tistory.com",nocase; classtype:trojan-activity; sid:100003997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ch.rmu.ac.th",nocase; classtype:trojan-activity; sid:100003998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"changematterscounselling.com",nocase; classtype:trojan-activity; sid:100003999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chardhamdodham.com",nocase; classtype:trojan-activity; sid:100004000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cheacrilnsurances.com",nocase; classtype:trojan-activity; sid:100004001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chealablilitycarinsurances.com",nocase; classtype:trojan-activity; sid:100004002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chezalice.co.za",nocase; classtype:trojan-activity; sid:100004003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"childselect.com",nocase; classtype:trojan-activity; sid:100004004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile.myvnc.com",nocase; classtype:trojan-activity; sid:100004005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile80.myvnc.com",nocase; classtype:trojan-activity; sid:100004006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cible-energy.com",nocase; classtype:trojan-activity; sid:100004007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cifeer.net",nocase; classtype:trojan-activity; sid:100004008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citycapproperty.ru",nocase; classtype:trojan-activity; sid:100004009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cityglobalgospel.com",nocase; classtype:trojan-activity; sid:100004010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"civi.istmejia.com",nocase; classtype:trojan-activity; sid:100004011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cleanbydesignllc.com",nocase; classtype:trojan-activity; sid:100004012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloud.fc.co.mz",nocase; classtype:trojan-activity; sid:100004013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codsambal.com",nocase; classtype:trojan-activity; sid:100004014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colinde.pricesne.com",nocase; classtype:trojan-activity; sid:100004015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colorpak.pl",nocase; classtype:trojan-activity; sid:100004016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"competancy.indigoconsult.net",nocase; classtype:trojan-activity; sid:100004017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"config.cqhbkjzx.com",nocase; classtype:trojan-activity; sid:100004018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"constructoralyon.com",nocase; classtype:trojan-activity; sid:100004019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"consulateins.solucioneslink.com",nocase; classtype:trojan-activity; sid:100004020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"contributeindustry.com",nocase; classtype:trojan-activity; sid:100004021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"controladoradeplagasmm.com",nocase; classtype:trojan-activity; sid:100004022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"controleautomacao.com.br",nocase; classtype:trojan-activity; sid:100004023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"copelandscapes.com",nocase; classtype:trojan-activity; sid:100004024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"coulsongraphics.com",nocase; classtype:trojan-activity; sid:100004025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"coutler.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"covid19.cyberschool.or.id",nocase; classtype:trojan-activity; sid:100004027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cr-sq.com",nocase; classtype:trojan-activity; sid:100004028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"craftnesia.id",nocase; classtype:trojan-activity; sid:100004029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"creationskateboards.com",nocase; classtype:trojan-activity; sid:100004030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crecerco.com",nocase; classtype:trojan-activity; sid:100004031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crittersbythebay.com",nocase; classtype:trojan-activity; sid:100004032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crm.notariavieitoyvelamazan.com",nocase; classtype:trojan-activity; sid:100004033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crscorretordeimoveis.com.br",nocase; classtype:trojan-activity; sid:100004034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cse-engineer.com",nocase; classtype:trojan-activity; sid:100004035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"csnserver.com",nocase; classtype:trojan-activity; sid:100004036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubescargoexpress.com",nocase; classtype:trojan-activity; sid:100004037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubrebocasenpuebla.com.mx",nocase; classtype:trojan-activity; sid:100004038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"curasoles.co.za",nocase; classtype:trojan-activity; sid:100004039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"currantmedia.com",nocase; classtype:trojan-activity; sid:100004040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cwa.mx",nocase; classtype:trojan-activity; sid:100004041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyber.searchkero.com",nocase; classtype:trojan-activity; sid:100004042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyclomove.com",nocase; classtype:trojan-activity; sid:100004043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cynkon.kairoscs.net",nocase; classtype:trojan-activity; sid:100004044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czas.dbstrony.pl",nocase; classtype:trojan-activity; sid:100004045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czsl.91756.cn",nocase; classtype:trojan-activity; sid:100004046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d.powerofwish.com",nocase; classtype:trojan-activity; sid:100004047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d9.99ddd.com",nocase; classtype:trojan-activity; sid:100004048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"da.alibuf.com",nocase; classtype:trojan-activity; sid:100004049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"damagedessentialtelecommunications.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100004050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dandyair.com",nocase; classtype:trojan-activity; sid:100004051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dartoonpictures.com",nocase; classtype:trojan-activity; sid:100004052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.cdevelop.org",nocase; classtype:trojan-activity; sid:100004053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.over-blog-kiwi.com",nocase; classtype:trojan-activity; sid:100004054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datapolish.com",nocase; classtype:trojan-activity; sid:100004055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dating.khokhas.co.za",nocase; classtype:trojan-activity; sid:100004056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datsom.vn",nocase; classtype:trojan-activity; sid:100004057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"daunhotq10.com",nocase; classtype:trojan-activity; sid:100004058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davethompson.me.uk",nocase; classtype:trojan-activity; sid:100004059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davidmcguinness.info",nocase; classtype:trojan-activity; sid:100004060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dayspringdaisies.com",nocase; classtype:trojan-activity; sid:100004061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dd.qiyuea.cn",nocase; classtype:trojan-activity; sid:100004062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"de.gsearch.com.de",nocase; classtype:trojan-activity; sid:100004063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"decifrar.com.br",nocase; classtype:trojan-activity; sid:100004064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deigratia2.elin.co.za",nocase; classtype:trojan-activity; sid:100004065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dekovizyon.com",nocase; classtype:trojan-activity; sid:100004066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo-cliente.mindcreative.com.br",nocase; classtype:trojan-activity; sid:100004067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo6.hiites.com",nocase; classtype:trojan-activity; sid:100004068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dent-estet.com",nocase; classtype:trojan-activity; sid:100004069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dental.xiaoxiao.media",nocase; classtype:trojan-activity; sid:100004070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dentalalliance.se",nocase; classtype:trojan-activity; sid:100004071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"designerliving.co.za",nocase; classtype:trojan-activity; sid:100004072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"desiringhands.com",nocase; classtype:trojan-activity; sid:100004073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"despertaresi.com.br",nocase; classtype:trojan-activity; sid:100004074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"destinymc.co.za",nocase; classtype:trojan-activity; sid:100004075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"detorre.es",nocase; classtype:trojan-activity; sid:100004076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev-interestingtech.pantheonsite.io",nocase; classtype:trojan-activity; sid:100004077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.sayse-tienda.com",nocase; classtype:trojan-activity; sid:100004078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.sebpo.net",nocase; classtype:trojan-activity; sid:100004079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfcf.91756.cn",nocase; classtype:trojan-activity; sid:100004080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfsfcsfcdsfsdvcfsvcscv.com",nocase; classtype:trojan-activity; sid:100004081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"diamantenegro.mi-fs.com",nocase; classtype:trojan-activity; sid:100004082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dienmayminhhung.com",nocase; classtype:trojan-activity; sid:100004083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digilib.dianhusada.ac.id",nocase; classtype:trojan-activity; sid:100004084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"djking.f3322.net",nocase; classtype:trojan-activity; sid:100004085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.1003b.56a.com",nocase; classtype:trojan-activity; sid:100004086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.198424.com",nocase; classtype:trojan-activity; sid:100004087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.installcdn-aws.com",nocase; classtype:trojan-activity; sid:100004088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.packetstormsecurity.net",nocase; classtype:trojan-activity; sid:100004089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.rina-roleplay.com",nocase; classtype:trojan-activity; sid:100004090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.zkytech.com",nocase; classtype:trojan-activity; sid:100004091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dns.cyberium.cc",nocase; classtype:trojan-activity; sid:100004092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dockerupdate.anondns.net",nocase; classtype:trojan-activity; sid:100004093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docman.orientalservices.in",nocase; classtype:trojan-activity; sid:100004094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dodsonimaging.com",nocase; classtype:trojan-activity; sid:100004095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dokan.blueberrytec.com",nocase; classtype:trojan-activity; sid:100004096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom-chel74.ru",nocase; classtype:trojan-activity; sid:100004097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom.daf.free.fr",nocase; classtype:trojan-activity; sid:100004098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doncedyhall.com",nocase; classtype:trojan-activity; sid:100004099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donghobinhminh.com",nocase; classtype:trojan-activity; sid:100004100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dongphuctop.com",nocase; classtype:trojan-activity; sid:100004101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donwnloasecury.ath.cx",nocase; classtype:trojan-activity; sid:100004102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosame.com",nocase; classtype:trojan-activity; sid:100004103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosman.pl",nocase; classtype:trojan-activity; sid:100004104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dovberger.com",nocase; classtype:trojan-activity; sid:100004105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.flash-plays.com",nocase; classtype:trojan-activity; sid:100004106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.pcclear.com",nocase; classtype:trojan-activity; sid:100004107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.udashi.com",nocase; classtype:trojan-activity; sid:100004108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.webbora.com",nocase; classtype:trojan-activity; sid:100004109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down1.arpun.com",nocase; classtype:trojan-activity; sid:100004110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.caihong.com",nocase; classtype:trojan-activity; sid:100004111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.doumaibiji.cn",nocase; classtype:trojan-activity; sid:100004112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.exrnybuf.cn",nocase; classtype:trojan-activity; sid:100004113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.kaobeitu.com",nocase; classtype:trojan-activity; sid:100004114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.pdf00.cn",nocase; classtype:trojan-activity; sid:100004115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.rising.com.cn",nocase; classtype:trojan-activity; sid:100004116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.skycn.com",nocase; classtype:trojan-activity; sid:100004117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.zjsyawqj.cn",nocase; classtype:trojan-activity; sid:100004118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"downloads.jxtsteel.cn",nocase; classtype:trojan-activity; sid:100004119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dragonsknot.com",nocase; classtype:trojan-activity; sid:100004120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drbaby.com.sa",nocase; classtype:trojan-activity; sid:100004121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drohnen.ensenanzainteligente.com",nocase; classtype:trojan-activity; sid:100004122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drools-moved.46999.n3.nabble.com",nocase; classtype:trojan-activity; sid:100004123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drsha.innovativesolutions.mobi",nocase; classtype:trojan-activity; sid:100004124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsenterprize.co.za",nocase; classtype:trojan-activity; sid:100004125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsspainting.com",nocase; classtype:trojan-activity; sid:100004126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"du-wizards.com",nocase; classtype:trojan-activity; sid:100004127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duque.guantanameratravel.com",nocase; classtype:trojan-activity; sid:100004128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dutapp.wisolve.co.za",nocase; classtype:trojan-activity; sid:100004129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duvalcharter.dekitout.com",nocase; classtype:trojan-activity; sid:100004130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dx.qqyewu.com",nocase; classtype:trojan-activity; sid:100004131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dzinestudio87.co.uk",nocase; classtype:trojan-activity; sid:100004132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-commerce.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100004133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e.sldov.ru",nocase; classtype:trojan-activity; sid:100004134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ebruyatkin.com",nocase; classtype:trojan-activity; sid:100004135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"econews.treegle.org",nocase; classtype:trojan-activity; sid:100004136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"efficientegroup.com",nocase; classtype:trojan-activity; sid:100004137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"elliot.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"en.baoend.com",nocase; classtype:trojan-activity; sid:100004139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enc-tech.com",nocase; classtype:trojan-activity; sid:100004140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"endurotanzania.co.tz",nocase; classtype:trojan-activity; sid:100004141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ennovate.elin.co.za",nocase; classtype:trojan-activity; sid:100004142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enriquecendocomconsorcio.com.br",nocase; classtype:trojan-activity; sid:100004143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"envios.petpienso.cl",nocase; classtype:trojan-activity; sid:100004144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"equimination.ee",nocase; classtype:trojan-activity; sid:100004145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"escola.probommar.org.br",nocase; classtype:trojan-activity; sid:100004146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"esnconsultants.com",nocase; classtype:trojan-activity; sid:100004147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"essentia.org.br",nocase; classtype:trojan-activity; sid:100004148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eubanks7.com",nocase; classtype:trojan-activity; sid:100004149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evidencemarketing.ca",nocase; classtype:trojan-activity; sid:100004150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exilum.com",nocase; classtype:trojan-activity; sid:100004151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exitoalfaomega.co",nocase; classtype:trojan-activity; sid:100004152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"extrovertoffers.com",nocase; classtype:trojan-activity; sid:100004153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"f1sol.com",nocase; classtype:trojan-activity; sid:100004154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"familydentist.site",nocase; classtype:trojan-activity; sid:100004155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"farmaciasdrogaminas.com.br",nocase; classtype:trojan-activity; sid:100004156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fate3.xyz",nocase; classtype:trojan-activity; sid:100004157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"faveraprojects.com",nocase; classtype:trojan-activity; sid:100004158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fc.co.mz",nocase; classtype:trojan-activity; sid:100004159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"felicienne.nl",nocase; classtype:trojan-activity; sid:100004160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fi.bonitastores.com",nocase; classtype:trojan-activity; sid:100004161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.martellexpress.us",nocase; classtype:trojan-activity; sid:100004162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"final.makkahkmcc.com",nocase; classtype:trojan-activity; sid:100004163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fineartgallerym.com",nocase; classtype:trojan-activity; sid:100004164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fkd.derpcity.ru",nocase; classtype:trojan-activity; sid:100004165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flintspin.com",nocase; classtype:trojan-activity; sid:100004166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flyingbuddhadesign.com",nocase; classtype:trojan-activity; sid:100004167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fmjplastering.co.uk",nocase; classtype:trojan-activity; sid:100004168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fms.buladde.or.ug",nocase; classtype:trojan-activity; sid:100004169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foothills.com.br",nocase; classtype:trojan-activity; sid:100004170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"footweardirect.elin.co.za",nocase; classtype:trojan-activity; sid:100004171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"forum.mdb.nu",nocase; classtype:trojan-activity; sid:100004172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fotoobjetivo.com",nocase; classtype:trojan-activity; sid:100004173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foundationrepairhoustontx.net",nocase; classtype:trojan-activity; sid:100004174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foxeps.com.br",nocase; classtype:trojan-activity; sid:100004175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freecnetdownload.com",nocase; classtype:trojan-activity; sid:100004176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freedombookshop.tickme.lk",nocase; classtype:trojan-activity; sid:100004177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freisites.com.br",nocase; classtype:trojan-activity; sid:100004178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ftp.n3twork30cm.ml",nocase; classtype:trojan-activity; sid:100004179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fullelectronica.com.ar",nocase; classtype:trojan-activity; sid:100004180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"funletters.net",nocase; classtype:trojan-activity; sid:100004181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fusionfiresolutions.com",nocase; classtype:trojan-activity; sid:100004182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gametwogame.com",nocase; classtype:trojan-activity; sid:100004183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garciadogshow.com",nocase; classtype:trojan-activity; sid:100004184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow.myvnc.com",nocase; classtype:trojan-activity; sid:100004185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow4.myvnc.com",nocase; classtype:trojan-activity; sid:100004186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gbbulls.co.uk",nocase; classtype:trojan-activity; sid:100004187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gcpc.co.id.chronoscurtain.com",nocase; classtype:trojan-activity; sid:100004188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"generaldeviales.com",nocase; classtype:trojan-activity; sid:100004189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfmodd1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100004190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfold1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100004191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghettohub.co.za",nocase; classtype:trojan-activity; sid:100004192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghislain.dartois.pagesperso-orange.fr",nocase; classtype:trojan-activity; sid:100004193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giadungg7.com",nocase; classtype:trojan-activity; sid:100004194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giddos.ga",nocase; classtype:trojan-activity; sid:100004195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gilliem.com",nocase; classtype:trojan-activity; sid:100004196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"girotexuniformes.com",nocase; classtype:trojan-activity; sid:100004197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giteletropical.com",nocase; classtype:trojan-activity; sid:100004198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"globaltask.ar",nocase; classtype:trojan-activity; sid:100004199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"glowinmedia.co.ke",nocase; classtype:trojan-activity; sid:100004200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmtransformationacademy.com",nocase; classtype:trojan-activity; sid:100004201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmvadmission.org",nocase; classtype:trojan-activity; sid:100004202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnimelf.net",nocase; classtype:trojan-activity; sid:100004203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnscrew.ro",nocase; classtype:trojan-activity; sid:100004204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gold.investforex.id",nocase; classtype:trojan-activity; sid:100004205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcake.co.id",nocase; classtype:trojan-activity; sid:100004206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com",nocase; classtype:trojan-activity; sid:100004207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com.au",nocase; classtype:trojan-activity; sid:100004208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcupmortgage.com",nocase; classtype:trojan-activity; sid:100004209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"golden-memories-funerals.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldmen.in",nocase; classtype:trojan-activity; sid:100004211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"grupoinmare.com",nocase; classtype:trojan-activity; sid:100004212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gruposelt.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gs.monerorx.com",nocase; classtype:trojan-activity; sid:100004214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gulfac-house.com",nocase; classtype:trojan-activity; sid:100004215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gvpcdpgc.edu.in",nocase; classtype:trojan-activity; sid:100004216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"habbotips.free.fr",nocase; classtype:trojan-activity; sid:100004217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hagebakken.no",nocase; classtype:trojan-activity; sid:100004218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"harshraval.in",nocase; classtype:trojan-activity; sid:100004219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hd11315.com",nocase; classtype:trojan-activity; sid:100004220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hdkamera2003.hu",nocase; classtype:trojan-activity; sid:100004221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hds.sz4h.com",nocase; classtype:trojan-activity; sid:100004222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"healthy20.net",nocase; classtype:trojan-activity; sid:100004223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"heavymaq.cl",nocase; classtype:trojan-activity; sid:100004224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com",nocase; classtype:trojan-activity; sid:100004225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hellogorgeous.com.au",nocase; classtype:trojan-activity; sid:100004226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"help.hizuko.com",nocase; classtype:trojan-activity; sid:100004227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"herchinfitout.com.sg",nocase; classtype:trojan-activity; sid:100004228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hhaward.org",nocase; classtype:trojan-activity; sid:100004229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandroadcoc.com",nocase; classtype:trojan-activity; sid:100004230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandslasvegas.atakdev.com",nocase; classtype:trojan-activity; sid:100004231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hindi.factsriver.com",nocase; classtype:trojan-activity; sid:100004232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hiptool.net",nocase; classtype:trojan-activity; sid:100004233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitpe.com",nocase; classtype:trojan-activity; sid:100004234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitstation.nl",nocase; classtype:trojan-activity; sid:100004235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hmpmall.co.kr",nocase; classtype:trojan-activity; sid:100004236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoagietesting10.com",nocase; classtype:trojan-activity; sid:100004237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoayeuthuong-my.sharepoint.com",nocase; classtype:trojan-activity; sid:100004238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"homefindersolutions.com",nocase; classtype:trojan-activity; sid:100004239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hongluosi.com",nocase; classtype:trojan-activity; sid:100004240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hookedupboatclub.com",nocase; classtype:trojan-activity; sid:100004241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostelkielce.com",nocase; classtype:trojan-activity; sid:100004242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostzaa.com",nocase; classtype:trojan-activity; sid:100004243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"houstonshutters.site",nocase; classtype:trojan-activity; sid:100004244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hr2019.vrcom7.com",nocase; classtype:trojan-activity; sid:100004245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hseda.com",nocase; classtype:trojan-activity; sid:100004246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsmwebapp.com",nocase; classtype:trojan-activity; sid:100004247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"htownbars.com",nocase; classtype:trojan-activity; sid:100004248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hubtech.co.za",nocase; classtype:trojan-activity; sid:100004249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hunggiang.vn",nocase; classtype:trojan-activity; sid:100004250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"husamiyahschool.com",nocase; classtype:trojan-activity; sid:100004251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iam313.com",nocase; classtype:trojan-activity; sid:100004252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"icon.shatangmu.cn",nocase; classtype:trojan-activity; sid:100004253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idea-secure-login.com",nocase; classtype:trojan-activity; sid:100004254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idilsoft.com",nocase; classtype:trojan-activity; sid:100004255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idj.no",nocase; classtype:trojan-activity; sid:100004256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idvindia.com",nocase; classtype:trojan-activity; sid:100004257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iesanjosemonitos.edu.co",nocase; classtype:trojan-activity; sid:100004258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ikexpert.com",nocase; classtype:trojan-activity; sid:100004259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ilrafrica.com",nocase; classtype:trojan-activity; sid:100004260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"images.jermiau.com",nocase; classtype:trojan-activity; sid:100004261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"imbueautoworx.co.za",nocase; classtype:trojan-activity; sid:100004262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incodimsa.com",nocase; classtype:trojan-activity; sid:100004263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incrediblepixels.com",nocase; classtype:trojan-activity; sid:100004264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incredicole.com",nocase; classtype:trojan-activity; sid:100004265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infair.vn",nocase; classtype:trojan-activity; sid:100004266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infovator.com",nocase; classtype:trojan-activity; sid:100004267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"innatosbrand.com",nocase; classtype:trojan-activity; sid:100004268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inodesthetotaldesigners.com",nocase; classtype:trojan-activity; sid:100004269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inovations.searchkero.com",nocase; classtype:trojan-activity; sid:100004270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inrajahmundry.co.in",nocase; classtype:trojan-activity; sid:100004271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"insignificantfinecore.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100004272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"instantindialoan.com",nocase; classtype:trojan-activity; sid:100004273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intellectsmart.in",nocase; classtype:trojan-activity; sid:100004274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intersel-idf.org",nocase; classtype:trojan-activity; sid:100004275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intuitiveideas.com.my",nocase; classtype:trojan-activity; sid:100004276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inversiones.arrayanfinanciero.cl",nocase; classtype:trojan-activity; sid:100004277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"invest.xpcorporative.com.br",nocase; classtype:trojan-activity; sid:100004278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ipmes.ma",nocase; classtype:trojan-activity; sid:100004279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iremart.es",nocase; classtype:trojan-activity; sid:100004280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isaac.mikhailmotoringschool.com",nocase; classtype:trojan-activity; sid:100004281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iscamenabe.com",nocase; classtype:trojan-activity; sid:100004282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ismf.com.ng",nocase; classtype:trojan-activity; sid:100004283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iso-dubai.net",nocase; classtype:trojan-activity; sid:100004284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"israrulhaq.me",nocase; classtype:trojan-activity; sid:100004285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isrorg.com",nocase; classtype:trojan-activity; sid:100004286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isso.ps",nocase; classtype:trojan-activity; sid:100004287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"it123.ru",nocase; classtype:trojan-activity; sid:100004288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itc-demo.softgig.co.ke",nocase; classtype:trojan-activity; sid:100004289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itconsultus.com.co",nocase; classtype:trojan-activity; sid:100004290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamesjorgensen.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamiekaylive.com",nocase; classtype:trojan-activity; sid:100004292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamshed.pk",nocase; classtype:trojan-activity; sid:100004293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jansen-heesch.nl",nocase; classtype:trojan-activity; sid:100004294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jathra.co.uk",nocase; classtype:trojan-activity; sid:100004295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jay.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100004296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jebs.net.au",nocase; classtype:trojan-activity; sid:100004297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jeffdahlke.com",nocase; classtype:trojan-activity; sid:100004298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jewsjuice.com",nocase; classtype:trojan-activity; sid:100004299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jhayesconsulting.com",nocase; classtype:trojan-activity; sid:100004300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jiaoyuzixun.cn",nocase; classtype:trojan-activity; sid:100004301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jing-da.com.tw",nocase; classtype:trojan-activity; sid:100004302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jmcomputacion.com.ar",nocase; classtype:trojan-activity; sid:100004303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jmtc.91756.cn",nocase; classtype:trojan-activity; sid:100004304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jnanbharati.com",nocase; classtype:trojan-activity; sid:100004305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jobs.thebeessolution.com",nocase; classtype:trojan-activity; sid:100004306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"joelbonissilver.com",nocase; classtype:trojan-activity; sid:100004307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"join.cl8movement.co.za",nocase; classtype:trojan-activity; sid:100004308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josegene.com",nocase; classtype:trojan-activity; sid:100004309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josuarochoa.com",nocase; classtype:trojan-activity; sid:100004310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jpwoodfordco.com",nocase; classtype:trojan-activity; sid:100004311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jumpmanualjacobhiller.com",nocase; classtype:trojan-activity; sid:100004312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jupiter.toxsl.in",nocase; classtype:trojan-activity; sid:100004313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jurgensen.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"justinscott.com.au",nocase; classtype:trojan-activity; sid:100004315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kaizenjanitorial.com",nocase; classtype:trojan-activity; sid:100004316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalawatihomes.com",nocase; classtype:trojan-activity; sid:100004317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalpataru-elitus-mulund.thakkers.in",nocase; classtype:trojan-activity; sid:100004318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karer.by",nocase; classtype:trojan-activity; sid:100004319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"katanvetov.co.il",nocase; classtype:trojan-activity; sid:100004320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kbdom.com",nocase; classtype:trojan-activity; sid:100004321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kensingtondriving.com",nocase; classtype:trojan-activity; sid:100004322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kevinjewelry.com.co",nocase; classtype:trojan-activity; sid:100004323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"keywatch.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kingssa.co.za",nocase; classtype:trojan-activity; sid:100004325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kjcpromo.com",nocase; classtype:trojan-activity; sid:100004326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kleinendeli.co.za",nocase; classtype:trojan-activity; sid:100004327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"korrectconceptservices.com",nocase; classtype:trojan-activity; sid:100004328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ktb.sch.id",nocase; classtype:trojan-activity; sid:100004329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kubatoglubaklava.com.tr",nocase; classtype:trojan-activity; sid:100004330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kumaralok.in",nocase; classtype:trojan-activity; sid:100004331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kwanfromhongkong.com",nocase; classtype:trojan-activity; sid:100004332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kz.sldov.ru",nocase; classtype:trojan-activity; sid:100004333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lacasadelosalebrijes.com",nocase; classtype:trojan-activity; sid:100004334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ladylabonde.com",nocase; classtype:trojan-activity; sid:100004335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lameguard.ru",nocase; classtype:trojan-activity; sid:100004336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laodongnhat.vn",nocase; classtype:trojan-activity; sid:100004337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laravel.pointersoftwares.com.br",nocase; classtype:trojan-activity; sid:100004338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lasermobilesounds.co.uk",nocase; classtype:trojan-activity; sid:100004339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lauratomismith.com",nocase; classtype:trojan-activity; sid:100004340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lautarosanmiguel.com",nocase; classtype:trojan-activity; sid:100004341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawforall.edu.lk",nocase; classtype:trojan-activity; sid:100004342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lceventos.net",nocase; classtype:trojan-activity; sid:100004343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ld.mediaget.com",nocase; classtype:trojan-activity; sid:100004344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ldgcorp.com",nocase; classtype:trojan-activity; sid:100004345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"learning.real-academy.net",nocase; classtype:trojan-activity; sid:100004346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leasiacherise.com",nocase; classtype:trojan-activity; sid:100004347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leczkregoslup.acelero.pl",nocase; classtype:trojan-activity; sid:100004348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"legend.nu",nocase; classtype:trojan-activity; sid:100004349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leluibuffet.com.br",nocase; classtype:trojan-activity; sid:100004350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lestesteux.ca",nocase; classtype:trojan-activity; sid:100004351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"libantravel.pl",nocase; classtype:trojan-activity; sid:100004352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.arihantmbainstitute.ac.in",nocase; classtype:trojan-activity; sid:100004353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.uib.ac.id",nocase; classtype:trojan-activity; sid:100004354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lidoraggiodisole.it",nocase; classtype:trojan-activity; sid:100004355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lifebeam.elin.co.za",nocase; classtype:trojan-activity; sid:100004356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lindnerelektroanlagen.de",nocase; classtype:trojan-activity; sid:100004357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linkintec.cn",nocase; classtype:trojan-activity; sid:100004358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"litroxlitro.com",nocase; classtype:trojan-activity; sid:100004359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"livetrack.in",nocase; classtype:trojan-activity; sid:100004360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lloydsindian.co.uk",nocase; classtype:trojan-activity; sid:100004361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lm.stagingarea.co.za",nocase; classtype:trojan-activity; sid:100004362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmaancha.co.il",nocase; classtype:trojan-activity; sid:100004363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.cstdevs.com",nocase; classtype:trojan-activity; sid:100004364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.login2.in",nocase; classtype:trojan-activity; sid:100004365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmvirtualbookkeeping.com",nocase; classtype:trojan-activity; sid:100004366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lnt-rejuve-360.thakkers.in",nocase; classtype:trojan-activity; sid:100004367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"location-voitures.ma",nocase; classtype:trojan-activity; sid:100004368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"login.trezor.com.stockfootagesindia.com",nocase; classtype:trojan-activity; sid:100004369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"logotypfabriken.se",nocase; classtype:trojan-activity; sid:100004370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotix.de",nocase; classtype:trojan-activity; sid:100004371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotusanddragonfly.com",nocase; classtype:trojan-activity; sid:100004372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.carrduci.com",nocase; classtype:trojan-activity; sid:100004373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.definerisco.com",nocase; classtype:trojan-activity; sid:100004374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.difusodesign.com",nocase; classtype:trojan-activity; sid:100004375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.juancamilogarciareyes.com",nocase; classtype:trojan-activity; sid:100004376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.tecnimasdecolombia.com.co",nocase; classtype:trojan-activity; sid:100004377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ltc.typoten.com",nocase; classtype:trojan-activity; sid:100004378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luckybrownie.com",nocase; classtype:trojan-activity; sid:100004379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luminouspneuma.com",nocase; classtype:trojan-activity; sid:100004380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luxomodels.com",nocase; classtype:trojan-activity; sid:100004381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m-technics.kz",nocase; classtype:trojan-activity; sid:100004382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m.estudiomoros.com.ar",nocase; classtype:trojan-activity; sid:100004383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"madicon.co.za",nocase; classtype:trojan-activity; sid:100004384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"magianegramagiablancayamarres.com",nocase; classtype:trojan-activity; sid:100004385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.bs-eiendomme.co.za",nocase; classtype:trojan-activity; sid:100004386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.golimoapp.com",nocase; classtype:trojan-activity; sid:100004387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.jeffsono.org",nocase; classtype:trojan-activity; sid:100004388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maksi.feb.unib.ac.id",nocase; classtype:trojan-activity; sid:100004389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malaya.tv",nocase; classtype:trojan-activity; sid:100004390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malwarecoding.github.io",nocase; classtype:trojan-activity; sid:100004391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managed.oss-cn-beijing.aliyuncs.com",nocase; classtype:trojan-activity; sid:100004392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managemysalon.in",nocase; classtype:trojan-activity; sid:100004393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manantialesdelnorte.uy",nocase; classtype:trojan-activity; sid:100004394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manhtien.net",nocase; classtype:trojan-activity; sid:100004395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marcapinyo.ru",nocase; classtype:trojan-activity; sid:100004396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mario-sunjic.com",nocase; classtype:trojan-activity; sid:100004397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariobrown.net",nocase; classtype:trojan-activity; sid:100004398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariotessarollo.com",nocase; classtype:trojan-activity; sid:100004399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketinfosales.com",nocase; classtype:trojan-activity; sid:100004400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketing.enexusgroup.com.au",nocase; classtype:trojan-activity; sid:100004401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marksidfgs.ug",nocase; classtype:trojan-activity; sid:100004402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"masjidhabeebiyarazviya.mysunni.com",nocase; classtype:trojan-activity; sid:100004403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"materialescantu.com",nocase; classtype:trojan-activity; sid:100004404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"matruchhaya.co.in",nocase; classtype:trojan-activity; sid:100004405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mattysplayground.com",nocase; classtype:trojan-activity; sid:100004406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxtox.com.pk",nocase; classtype:trojan-activity; sid:100004407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbgrm.com",nocase; classtype:trojan-activity; sid:100004408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbsolutions.ge",nocase; classtype:trojan-activity; sid:100004409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mdasa.elin.co.za",nocase; classtype:trojan-activity; sid:100004410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medevlb.org",nocase; classtype:trojan-activity; sid:100004411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"media-server.skyinternet.com.pk",nocase; classtype:trojan-activity; sid:100004412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mediamaster.co.za",nocase; classtype:trojan-activity; sid:100004413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medianews.ge",nocase; classtype:trojan-activity; sid:100004414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medistaffconsulting.com",nocase; classtype:trojan-activity; sid:100004415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meeweb.com",nocase; classtype:trojan-activity; sid:100004416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megamart.afnan-amc.com",nocase; classtype:trojan-activity; sid:100004417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merbay.ru",nocase; classtype:trojan-activity; sid:100004418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merkathink.com",nocase; classtype:trojan-activity; sid:100004419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mertlog.com",nocase; classtype:trojan-activity; sid:100004420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"metalin-cr.com",nocase; classtype:trojan-activity; sid:100004421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mettaanand.org",nocase; classtype:trojan-activity; sid:100004422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meuoculosnanet.com.br",nocase; classtype:trojan-activity; sid:100004423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mfevr.com",nocase; classtype:trojan-activity; sid:100004424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot.myvnc.com",nocase; classtype:trojan-activity; sid:100004425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot80.myvnc.com",nocase; classtype:trojan-activity; sid:100004426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"micalle.com.au",nocase; classtype:trojan-activity; sid:100004427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michaelphilip.com",nocase; classtype:trojan-activity; sid:100004428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michimal2.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microblading.mirliandias.com.br",nocase; classtype:trojan-activity; sid:100004430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microcomm-group.com",nocase; classtype:trojan-activity; sid:100004431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mikhailmotoringschool.com",nocase; classtype:trojan-activity; sid:100004432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mindfulbuildingandliving.com",nocase; classtype:trojan-activity; sid:100004433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mingguanwms.com",nocase; classtype:trojan-activity; sid:100004434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minuevavida.org",nocase; classtype:trojan-activity; sid:100004435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mirror.mypage.sk",nocase; classtype:trojan-activity; sid:100004436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mis.nbcc.ac.th",nocase; classtype:trojan-activity; sid:100004437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"misterson.com",nocase; classtype:trojan-activity; sid:100004438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mixr.at",nocase; classtype:trojan-activity; sid:100004439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mkontakt.az",nocase; classtype:trojan-activity; sid:100004440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mktf.mx",nocase; classtype:trojan-activity; sid:100004441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmogollon.com.mx",nocase; classtype:trojan-activity; sid:100004442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mncarteam.com",nocase; classtype:trojan-activity; sid:100004443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mobile.illumetechnology.com",nocase; classtype:trojan-activity; sid:100004444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modelhouseturkey.com",nocase; classtype:trojan-activity; sid:100004445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modernmanna.org",nocase; classtype:trojan-activity; sid:100004446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"monetization.business",nocase; classtype:trojan-activity; sid:100004447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moninediy.com",nocase; classtype:trojan-activity; sid:100004448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mopai.sg",nocase; classtype:trojan-activity; sid:100004449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"motorcomunicacion.com",nocase; classtype:trojan-activity; sid:100004450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"msacontabil.com.br",nocase; classtype:trojan-activity; sid:100004451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mtspsmjeli.sch.id",nocase; classtype:trojan-activity; sid:100004452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"muzimbiti.xigubo.co.mz",nocase; classtype:trojan-activity; sid:100004453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mxpiqw.am.files.1drv.com",nocase; classtype:trojan-activity; sid:100004454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mydatebook.in",nocase; classtype:trojan-activity; sid:100004455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mymlql.com",nocase; classtype:trojan-activity; sid:100004456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myritz.vettickal.com",nocase; classtype:trojan-activity; sid:100004457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myscape.in",nocase; classtype:trojan-activity; sid:100004458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysura.it",nocase; classtype:trojan-activity; sid:100004459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"namnyak.co.ke",nocase; classtype:trojan-activity; sid:100004460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nap.mgsservers.com",nocase; classtype:trojan-activity; sid:100004461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"navayurveda.in",nocase; classtype:trojan-activity; sid:100004462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nbs.vizzhost.com",nocase; classtype:trojan-activity; sid:100004463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nec-i.com",nocase; classtype:trojan-activity; sid:100004464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nelitrianggraeni.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nerve.untergrund.net",nocase; classtype:trojan-activity; sid:100004466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nettube.com.br",nocase; classtype:trojan-activity; sid:100004467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"networkwheels.co.za",nocase; classtype:trojan-activity; sid:100004468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neuromedic.com.br",nocase; classtype:trojan-activity; sid:100004469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neverseenshop.com.mx",nocase; classtype:trojan-activity; sid:100004470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newinfinitysynergy.com",nocase; classtype:trojan-activity; sid:100004471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"news.dbstrony.pl",nocase; classtype:trojan-activity; sid:100004472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtreedesign.co.uk",nocase; classtype:trojan-activity; sid:100004473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtrendeg.com",nocase; classtype:trojan-activity; sid:100004474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newvisionopticallab.com",nocase; classtype:trojan-activity; sid:100004475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newxing.com",nocase; classtype:trojan-activity; sid:100004476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nextdigitalday.ru",nocase; classtype:trojan-activity; sid:100004477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ngdaycare.co.za",nocase; classtype:trojan-activity; sid:100004478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nguyenkekhuyen.com",nocase; classtype:trojan-activity; sid:100004479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhorangtreem.com",nocase; classtype:trojan-activity; sid:100004480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nicolas.ug",nocase; classtype:trojan-activity; sid:100004481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nidhi.iexist.in",nocase; classtype:trojan-activity; sid:100004482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nikanpolimer.ir",nocase; classtype:trojan-activity; sid:100004483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilehouse.co.ug",nocase; classtype:trojan-activity; sid:100004484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilinkeji.com",nocase; classtype:trojan-activity; sid:100004485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nisacooks.com",nocase; classtype:trojan-activity; sid:100004486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"njtiledesigncenter.com",nocase; classtype:trojan-activity; sid:100004487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nobius.org",nocase; classtype:trojan-activity; sid:100004488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nocalnoodle.elin.co.za",nocase; classtype:trojan-activity; sid:100004489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nomadicbees.com",nocase; classtype:trojan-activity; sid:100004490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nonnarina.ax",nocase; classtype:trojan-activity; sid:100004491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"notamuzikaletleri.com",nocase; classtype:trojan-activity; sid:100004492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ns1.the-widyantos.com",nocase; classtype:trojan-activity; sid:100004493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsb.org.uk",nocase; classtype:trojan-activity; sid:100004494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsheldon.co.uk",nocase; classtype:trojan-activity; sid:100004495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nuthuassociates.com",nocase; classtype:trojan-activity; sid:100004496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nuwagi.com",nocase; classtype:trojan-activity; sid:100004497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyeh2o.com.au",nocase; classtype:trojan-activity; sid:100004498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oakleyandfriends.co.uk",nocase; classtype:trojan-activity; sid:100004499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"obseques-conseils.com",nocase; classtype:trojan-activity; sid:100004500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ocean.tecnasulstore.com.br",nocase; classtype:trojan-activity; sid:100004501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohe.ie",nocase; classtype:trojan-activity; sid:100004502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohsewgorgeous.co.uk",nocase; classtype:trojan-activity; sid:100004503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oknoplastik.sk",nocase; classtype:trojan-activity; sid:100004504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oleholeh.memangbeda.website",nocase; classtype:trojan-activity; sid:100004505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"olirecords.mixture.ltd",nocase; classtype:trojan-activity; sid:100004506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"olooom.com",nocase; classtype:trojan-activity; sid:100004507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaia.org",nocase; classtype:trojan-activity; sid:100004508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaromatic.com",nocase; classtype:trojan-activity; sid:100004509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omega.az",nocase; classtype:trojan-activity; sid:100004510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oms.pappai.com",nocase; classtype:trojan-activity; sid:100004511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omscoc.pappai.com",nocase; classtype:trojan-activity; sid:100004512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedigitalcard.granvizionnecorp.com",nocase; classtype:trojan-activity; sid:100004513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.listifyapp.co",nocase; classtype:trojan-activity; sid:100004514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"online.creedglobal.in",nocase; classtype:trojan-activity; sid:100004515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onlinestatis.bar",nocase; classtype:trojan-activity; sid:100004516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ont.proman.id",nocase; classtype:trojan-activity; sid:100004517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"open.warehousesaas.co.uk",nocase; classtype:trojan-activity; sid:100004518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opolis.io",nocase; classtype:trojan-activity; sid:100004519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opticaoptigral.cl",nocase; classtype:trojan-activity; sid:100004520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optimus.com.sg",nocase; classtype:trojan-activity; sid:100004521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optitechsa.co.za",nocase; classtype:trojan-activity; sid:100004522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"order.bizpeed.com",nocase; classtype:trojan-activity; sid:100004523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orientgatewayltd.com",nocase; classtype:trojan-activity; sid:100004524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orion445.com",nocase; classtype:trojan-activity; sid:100004525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orpod.ru",nocase; classtype:trojan-activity; sid:100004526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oserve.pk",nocase; classtype:trojan-activity; sid:100004527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ottimade.com",nocase; classtype:trojan-activity; sid:100004528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ourteam.searchkero.com",nocase; classtype:trojan-activity; sid:100004529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ozemag.com",nocase; classtype:trojan-activity; sid:100004530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p1.lingpao8.com",nocase; classtype:trojan-activity; sid:100004531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p3.zbjimg.com",nocase; classtype:trojan-activity; sid:100004532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p6.zbjimg.com",nocase; classtype:trojan-activity; sid:100004533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pablobrothel.com.ar",nocase; classtype:trojan-activity; sid:100004534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacificgroup.ws",nocase; classtype:trojan-activity; sid:100004535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacwebdesigns.com",nocase; classtype:trojan-activity; sid:100004536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pagos.krayem.com.mx",nocase; classtype:trojan-activity; sid:100004537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"palochusvet.szm.com",nocase; classtype:trojan-activity; sid:100004538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parallel.rockvideos.at",nocase; classtype:trojan-activity; sid:100004539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parejasfelices.mi-fs.com",nocase; classtype:trojan-activity; sid:100004540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parkhussion.com",nocase; classtype:trojan-activity; sid:100004541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastorpaulocosta.com",nocase; classtype:trojan-activity; sid:100004542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.51lg.com",nocase; classtype:trojan-activity; sid:100004543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.99ddd.com",nocase; classtype:trojan-activity; sid:100004544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch3.99ddd.com",nocase; classtype:trojan-activity; sid:100004545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paths.elin.co.za",nocase; classtype:trojan-activity; sid:100004546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paulmercier.biz",nocase; classtype:trojan-activity; sid:100004547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payerrealty.com",nocase; classtype:trojan-activity; sid:100004548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payments.atifsiddiqui.me",nocase; classtype:trojan-activity; sid:100004549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pcsoori.com",nocase; classtype:trojan-activity; sid:100004550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pd.oceaniarp.net",nocase; classtype:trojan-activity; sid:100004551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpus.onlineman7-jombang.sch.id",nocase; classtype:trojan-activity; sid:100004552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpustekim.untirta.ac.id",nocase; classtype:trojan-activity; sid:100004553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"petercollie.com",nocase; classtype:trojan-activity; sid:100004554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ph4s.ru",nocase; classtype:trojan-activity; sid:100004555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phasdesign.com",nocase; classtype:trojan-activity; sid:100004556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phenhuong.sanpham.online",nocase; classtype:trojan-activity; sid:100004557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phittc.com",nocase; classtype:trojan-activity; sid:100004558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photo360.kubooking.com",nocase; classtype:trojan-activity; sid:100004559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photographytipsclub.com",nocase; classtype:trojan-activity; sid:100004560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pink99.com",nocase; classtype:trojan-activity; sid:100004561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pizzabarletta.com.br",nocase; classtype:trojan-activity; sid:100004562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"plasfan.ind.br",nocase; classtype:trojan-activity; sid:100004563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pmglance.startwriteup.com",nocase; classtype:trojan-activity; sid:100004564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pokojewewladyslawowie.pl",nocase; classtype:trojan-activity; sid:100004565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pole.com.vc",nocase; classtype:trojan-activity; sid:100004566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pool.phxdir.com",nocase; classtype:trojan-activity; sid:100004567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pooltablemoversdenver.net",nocase; classtype:trojan-activity; sid:100004568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"posmicrosystems.com",nocase; classtype:trojan-activity; sid:100004569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"poulman.panagiotopoulos-tours.gr",nocase; classtype:trojan-activity; sid:100004570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ppdb.smk-ciptaskill.sch.id",nocase; classtype:trojan-activity; sid:100004571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pptvideotemplates.com",nocase; classtype:trojan-activity; sid:100004572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestigehomeautomation.net",nocase; classtype:trojan-activity; sid:100004573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prishaartcreations.com",nocase; classtype:trojan-activity; sid:100004574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"production.sparshims.com",nocase; classtype:trojan-activity; sid:100004575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"programaoperadoronline.com.br",nocase; classtype:trojan-activity; sid:100004576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"project.exquitec.com",nocase; classtype:trojan-activity; sid:100004577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promotoradescomplica.com.br",nocase; classtype:trojan-activity; sid:100004578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promoversdubai.com",nocase; classtype:trojan-activity; sid:100004579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq.elin.co.za",nocase; classtype:trojan-activity; sid:100004580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq2.elin.co.za",nocase; classtype:trojan-activity; sid:100004581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosoc.nl",nocase; classtype:trojan-activity; sid:100004582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosyarmakassar.com",nocase; classtype:trojan-activity; sid:100004583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"provence.elin.co.za",nocase; classtype:trojan-activity; sid:100004584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prueba.danielluza.com",nocase; classtype:trojan-activity; sid:100004585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ptpmeccatronica.eu",nocase; classtype:trojan-activity; sid:100004586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pujashoppe.in",nocase; classtype:trojan-activity; sid:100004587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punchdialogues.com",nocase; classtype:trojan-activity; sid:100004588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punjabdevelopersassociation.com.pk",nocase; classtype:trojan-activity; sid:100004589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"purefoe.top",nocase; classtype:trojan-activity; sid:100004590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pvcprinting.co.uk",nocase; classtype:trojan-activity; sid:100004591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qadir.tickfa.ir",nocase; classtype:trojan-activity; sid:100004592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qatarglobalconsulting.com",nocase; classtype:trojan-activity; sid:100004593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qmsled.com",nocase; classtype:trojan-activity; sid:100004594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quartier-midi.be",nocase; classtype:trojan-activity; sid:100004595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"querocar.com",nocase; classtype:trojan-activity; sid:100004596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rachmat-assuhaimi.my.id",nocase; classtype:trojan-activity; sid:100004597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rainbowisp.info",nocase; classtype:trojan-activity; sid:100004598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raodigitalmedia.com",nocase; classtype:trojan-activity; sid:100004599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rarlabarchiver.ac",nocase; classtype:trojan-activity; sid:100004600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rasadbar.ir",nocase; classtype:trojan-activity; sid:100004601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rashika.ascarvalho.co.za",nocase; classtype:trojan-activity; sid:100004602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ratemyfenancialadvisor.com",nocase; classtype:trojan-activity; sid:100004603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ravenproductionsltd.com",nocase; classtype:trojan-activity; sid:100004604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rc.ixiaoyang.cn",nocase; classtype:trojan-activity; sid:100004605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rcmesilva.charbelsales.com.br",nocase; classtype:trojan-activity; sid:100004606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"readymmade.com",nocase; classtype:trojan-activity; sid:100004607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redchillicrackers.com",nocase; classtype:trojan-activity; sid:100004608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reifenquick.de",nocase; classtype:trojan-activity; sid:100004609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"relaxindulge.co.nz",nocase; classtype:trojan-activity; sid:100004610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"renehavis.com.ua",nocase; classtype:trojan-activity; sid:100004611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"repatriacioncolombia.com",nocase; classtype:trojan-activity; sid:100004612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.uf1.cn",nocase; classtype:trojan-activity; sid:100004613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.digimitra.in",nocase; classtype:trojan-activity; sid:100004614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"resuco.net",nocase; classtype:trojan-activity; sid:100004615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rezkabum.ru",nocase; classtype:trojan-activity; sid:100004616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rhema.com.sg",nocase; classtype:trojan-activity; sid:100004617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richancyber.info",nocase; classtype:trojan-activity; sid:100004618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richmondminerals.co.zm",nocase; classtype:trojan-activity; sid:100004619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinaefoundation.org.za",nocase; classtype:trojan-activity; sid:100004620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinkaisystem-ht.com",nocase; classtype:trojan-activity; sid:100004621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"riverfox.co.za",nocase; classtype:trojan-activity; sid:100004622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkcable.co.in",nocase; classtype:trojan-activity; sid:100004623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkverify.securestudies.com",nocase; classtype:trojan-activity; sid:100004624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roadfurylifts.com",nocase; classtype:trojan-activity; sid:100004625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertmcardle.com",nocase; classtype:trojan-activity; sid:100004626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertsinclair.net",nocase; classtype:trojan-activity; sid:100004627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robinhood-sports.com",nocase; classtype:trojan-activity; sid:100004628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"romanianpoints.com",nocase; classtype:trojan-activity; sid:100004629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ronnietucker.co.uk",nocase; classtype:trojan-activity; sid:100004630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roomsvc.servegate.kr",nocase; classtype:trojan-activity; sid:100004631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshan.academy",nocase; classtype:trojan-activity; sid:100004632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshnijewellery.com",nocase; classtype:trojan-activity; sid:100004633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rs-toolkit.mikestclair.org",nocase; classtype:trojan-activity; sid:100004634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rsgym.net",nocase; classtype:trojan-activity; sid:100004635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubazar.pro",nocase; classtype:trojan-activity; sid:100004636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubycityvietnam.com",nocase; classtype:trojan-activity; sid:100004637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruch.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruisgood.ru",nocase; classtype:trojan-activity; sid:100004639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruwadalkuwait.com",nocase; classtype:trojan-activity; sid:100004640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rydchile.cl",nocase; classtype:trojan-activity; sid:100004641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rzminc.com",nocase; classtype:trojan-activity; sid:100004642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.51shijuan.com",nocase; classtype:trojan-activity; sid:100004643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.thechinesemuslim.com",nocase; classtype:trojan-activity; sid:100004644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sacredscentsonline.com",nocase; classtype:trojan-activity; sid:100004645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safcol-colors.com",nocase; classtype:trojan-activity; sid:100004646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safehubsecurity.ca",nocase; classtype:trojan-activity; sid:100004647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safety.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100004648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sahathaikasetpan.com",nocase; classtype:trojan-activity; sid:100004649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"saisoftwareinc.com",nocase; classtype:trojan-activity; sid:100004650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salecorner.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sandovalgraphics.com",nocase; classtype:trojan-activity; sid:100004652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"santyago.org",nocase; classtype:trojan-activity; sid:100004653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sarakem.cl",nocase; classtype:trojan-activity; sid:100004654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sasystemsuk.com",nocase; classtype:trojan-activity; sid:100004655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"savasaachi.systems",nocase; classtype:trojan-activity; sid:100004656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scarfaceindustries.com",nocase; classtype:trojan-activity; sid:100004657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scglobal.co.th",nocase; classtype:trojan-activity; sid:100004658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schalke04rss.de",nocase; classtype:trojan-activity; sid:100004659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scheff.com",nocase; classtype:trojan-activity; sid:100004660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schoolbustracker.softgig.co.ke",nocase; classtype:trojan-activity; sid:100004661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sec-doc-w.com",nocase; classtype:trojan-activity; sid:100004662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"secure-doc-reader.com",nocase; classtype:trojan-activity; sid:100004663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"segalsmetals.elin.co.za",nocase; classtype:trojan-activity; sid:100004664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sellmyphonela.com",nocase; classtype:trojan-activity; sid:100004665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"selltechtoday.com",nocase; classtype:trojan-activity; sid:100004666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"senbiaojita.com",nocase; classtype:trojan-activity; sid:100004667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sentierodelviandante.ml",nocase; classtype:trojan-activity; sid:100004668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serendibsourcing.com",nocase; classtype:trojan-activity; sid:100004669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd.myvnc.com",nocase; classtype:trojan-activity; sid:100004670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd80.myvnc.com",nocase; classtype:trojan-activity; sid:100004671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"seyranikenger.com.tr",nocase; classtype:trojan-activity; sid:100004672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sgessy.com.br",nocase; classtype:trojan-activity; sid:100004673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shaheentbfoundation.com",nocase; classtype:trojan-activity; sid:100004674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahikhana.cstdevs.com",nocase; classtype:trojan-activity; sid:100004675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharkrigs.com",nocase; classtype:trojan-activity; sid:100004676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharpelevators.in",nocase; classtype:trojan-activity; sid:100004677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shembefoundation.com",nocase; classtype:trojan-activity; sid:100004678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shivakunwar.com.np",nocase; classtype:trojan-activity; sid:100004679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shoblasaathitrust.org",nocase; classtype:trojan-activity; sid:100004680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shooka-co.com",nocase; classtype:trojan-activity; sid:100004681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shop.goldspot.agency",nocase; classtype:trojan-activity; sid:100004682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shopsofe.com",nocase; classtype:trojan-activity; sid:100004683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shrushtiinfotech.com",nocase; classtype:trojan-activity; sid:100004684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sibernetix.fr",nocase; classtype:trojan-activity; sid:100004685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siddharthpanditpautra.com",nocase; classtype:trojan-activity; sid:100004686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sige.brisainformatica.com.br",nocase; classtype:trojan-activity; sid:100004687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"signatureads.co.in",nocase; classtype:trojan-activity; sid:100004688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siili.net",nocase; classtype:trojan-activity; sid:100004689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simoneporzi.it",nocase; classtype:trojan-activity; sid:100004690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simplithy.co.uk",nocase; classtype:trojan-activity; sid:100004691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindicato1ucm.cl",nocase; classtype:trojan-activity; sid:100004692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindpol.tiejuris.com.br",nocase; classtype:trojan-activity; sid:100004693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sinergidwireka.com",nocase; classtype:trojan-activity; sid:100004694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sipahielektrik.com",nocase; classtype:trojan-activity; sid:100004695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siperb.in",nocase; classtype:trojan-activity; sid:100004696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sistelligent.com",nocase; classtype:trojan-activity; sid:100004697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skkksolo.beweiretail.com",nocase; classtype:trojan-activity; sid:100004698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyflyfares.com",nocase; classtype:trojan-activity; sid:100004699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyscan.com",nocase; classtype:trojan-activity; sid:100004700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarthouseforum.ru",nocase; classtype:trojan-activity; sid:100004701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarts.tj",nocase; classtype:trojan-activity; sid:100004702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smartzedu.com",nocase; classtype:trojan-activity; sid:100004703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokeandgrowrichtour.com",nocase; classtype:trojan-activity; sid:100004704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokesolutionindia.com",nocase; classtype:trojan-activity; sid:100004705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobethuacademy.com",nocase; classtype:trojan-activity; sid:100004706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.110route.com",nocase; classtype:trojan-activity; sid:100004707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.officelabo.net",nocase; classtype:trojan-activity; sid:100004708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sohs.conceptechs.info",nocase; classtype:trojan-activity; sid:100004709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solar.amazingtribe.lk",nocase; classtype:trojan-activity; sid:100004710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solo2.dbstrony.pl",nocase; classtype:trojan-activity; sid:100004711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somcorbera.cat",nocase; classtype:trojan-activity; sid:100004712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somir.com.mx",nocase; classtype:trojan-activity; sid:100004713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soralapps.com",nocase; classtype:trojan-activity; sid:100004714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sorteio.orgaostalita.com.br",nocase; classtype:trojan-activity; sid:100004715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sota-france.fr",nocase; classtype:trojan-activity; sid:100004716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sowingminerals.cl",nocase; classtype:trojan-activity; sid:100004717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"space.proactint.org",nocase; classtype:trojan-activity; sid:100004718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spaceframe.mobi.space-frame.co.za",nocase; classtype:trojan-activity; sid:100004719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"special-key.cf",nocase; classtype:trojan-activity; sid:100004720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spent.com.pl",nocase; classtype:trojan-activity; sid:100004721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spetsesyachtcharter.gr",nocase; classtype:trojan-activity; sid:100004722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spititourism.com",nocase; classtype:trojan-activity; sid:100004723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spittinfire.com",nocase; classtype:trojan-activity; sid:100004724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sports-net.de",nocase; classtype:trojan-activity; sid:100004725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"src1.minibai.com",nocase; classtype:trojan-activity; sid:100004726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sreenivasapaintingworks.com",nocase; classtype:trojan-activity; sid:100004727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sriglobalit.com",nocase; classtype:trojan-activity; sid:100004728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srvmanos.no-ip.info",nocase; classtype:trojan-activity; sid:100004729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ss.monita.co.id",nocase; classtype:trojan-activity; sid:100004730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"staging.apparelpunch.com",nocase; classtype:trojan-activity; sid:100004731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"starcountry.net",nocase; classtype:trojan-activity; sid:100004732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"static.3001.net",nocase; classtype:trojan-activity; sid:100004733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statsres.com",nocase; classtype:trojan-activity; sid:100004734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statssound.com",nocase; classtype:trojan-activity; sid:100004735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statsspot.com",nocase; classtype:trojan-activity; sid:100004736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stattilion.bar",nocase; classtype:trojan-activity; sid:100004737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiepancasetia.ac.id",nocase; classtype:trojan-activity; sid:100004738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stott-thompson.co.uk",nocase; classtype:trojan-activity; sid:100004739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stratexec.co.za",nocase; classtype:trojan-activity; sid:100004740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"streetdemo.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"suboldesign.com",nocase; classtype:trojan-activity; sid:100004742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sumerians.org",nocase; classtype:trojan-activity; sid:100004743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunbrero.com.au",nocase; classtype:trojan-activity; sid:100004744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunmarkholidays.com",nocase; classtype:trojan-activity; sid:100004745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supermercadostia.com",nocase; classtype:trojan-activity; sid:100004746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support-4-free.com",nocase; classtype:trojan-activity; sid:100004747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support.clz.kr",nocase; classtype:trojan-activity; sid:100004748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sw.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweaty.dk",nocase; classtype:trojan-activity; sid:100004750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweet-diet.com",nocase; classtype:trojan-activity; sid:100004751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swentsai.com",nocase; classtype:trojan-activity; sid:100004752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swiftlogisticseg.com",nocase; classtype:trojan-activity; sid:100004753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swwbia.com",nocase; classtype:trojan-activity; sid:100004754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"syedpro.dezinetimes.com",nocase; classtype:trojan-activity; sid:100004755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"syracusecoffee.com",nocase; classtype:trojan-activity; sid:100004756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sys.pbmadu.co.id",nocase; classtype:trojan-activity; sid:100004757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sytraders.co",nocase; classtype:trojan-activity; sid:100004758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.honker.info",nocase; classtype:trojan-activity; sid:100004759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.netcatkit.com",nocase; classtype:trojan-activity; sid:100004760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tacticohosting.com",nocase; classtype:trojan-activity; sid:100004761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tadoo.ca",nocase; classtype:trojan-activity; sid:100004762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tafsantoursandtravels.com",nocase; classtype:trojan-activity; sid:100004763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tallyinvoicecustomization.com",nocase; classtype:trojan-activity; sid:100004764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taltus.co.uk",nocase; classtype:trojan-activity; sid:100004765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tapalkoedacoffee.com",nocase; classtype:trojan-activity; sid:100004766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tarravalleyfoods.com.au",nocase; classtype:trojan-activity; sid:100004767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taurus.ug",nocase; classtype:trojan-activity; sid:100004768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taxicabsrilanka.com",nocase; classtype:trojan-activity; sid:100004769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taxpos.com",nocase; classtype:trojan-activity; sid:100004770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tc.snpsresidential.com",nocase; classtype:trojan-activity; sid:100004771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tcy.198424.com",nocase; classtype:trojan-activity; sid:100004772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tdsp.yngw518.com",nocase; classtype:trojan-activity; sid:100004773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"techgms.com",nocase; classtype:trojan-activity; sid:100004774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technogreen.crmmanivela.com",nocase; classtype:trojan-activity; sid:100004775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technohub.searchkero.com",nocase; classtype:trojan-activity; sid:100004776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tecnicaencolectores.com.mx",nocase; classtype:trojan-activity; sid:100004777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tecnologyschool.com",nocase; classtype:trojan-activity; sid:100004778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teduae.com",nocase; classtype:trojan-activity; sid:100004779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teleargentina.com",nocase; classtype:trojan-activity; sid:100004780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telescopelms.com",nocase; classtype:trojan-activity; sid:100004781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telmed.cl",nocase; classtype:trojan-activity; sid:100004782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"temptmag.com",nocase; classtype:trojan-activity; sid:100004783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tentandoserfitness.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.adventser.com",nocase; classtype:trojan-activity; sid:100004785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.letraele.es",nocase; classtype:trojan-activity; sid:100004786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.typoten.com",nocase; classtype:trojan-activity; sid:100004787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.wanepghana.org",nocase; classtype:trojan-activity; sid:100004788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.milenial.id",nocase; classtype:trojan-activity; sid:100004789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.tenplusone.my",nocase; classtype:trojan-activity; sid:100004790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.basis-web.com",nocase; classtype:trojan-activity; sid:100004791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.marrenconstruction.ie",nocase; classtype:trojan-activity; sid:100004792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.clickitsolutionsmw.com",nocase; classtype:trojan-activity; sid:100004793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.thinkingcorp.in",nocase; classtype:trojan-activity; sid:100004794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testnew.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teteaffiche.stephanebillon.com",nocase; classtype:trojan-activity; sid:100004796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tewoerd.eu",nocase; classtype:trojan-activity; sid:100004797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"textile.softberg.ro",nocase; classtype:trojan-activity; sid:100004798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"texturesbyvinita.com",nocase; classtype:trojan-activity; sid:100004799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tharringtonsponsorship.com",nocase; classtype:trojan-activity; sid:100004800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecleaningladiespdx.com",nocase; classtype:trojan-activity; sid:100004801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecreativecafe.co.uk",nocase; classtype:trojan-activity; sid:100004802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefuturelife.in",nocase; classtype:trojan-activity; sid:100004803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehighlightinterior.com",nocase; classtype:trojan-activity; sid:100004804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehouseofpragya.com",nocase; classtype:trojan-activity; sid:100004805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thekassia.co.uk",nocase; classtype:trojan-activity; sid:100004806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thelaunchpadteam.com",nocase; classtype:trojan-activity; sid:100004807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thesummitpc.net",nocase; classtype:trojan-activity; sid:100004808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theurbantutors.com",nocase; classtype:trojan-activity; sid:100004809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thosewebbs.com",nocase; classtype:trojan-activity; sid:100004810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tianangdep.com",nocase; classtype:trojan-activity; sid:100004811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickfood.tickme.lk",nocase; classtype:trojan-activity; sid:100004812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickjobs.tickme.lk",nocase; classtype:trojan-activity; sid:100004813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickmart.tickme.lk",nocase; classtype:trojan-activity; sid:100004814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"timegonebuy.com",nocase; classtype:trojan-activity; sid:100004815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tksb.net",nocase; classtype:trojan-activity; sid:100004816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tlcc.com.gt",nocase; classtype:trojan-activity; sid:100004817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"todoapp.cstdevs.com",nocase; classtype:trojan-activity; sid:100004818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonydong.com",nocase; classtype:trojan-activity; sid:100004819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonyzone.com",nocase; classtype:trojan-activity; sid:100004820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tooba.tenplusone.my",nocase; classtype:trojan-activity; sid:100004821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topcell9.com",nocase; classtype:trojan-activity; sid:100004822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topicsnepal.com",nocase; classtype:trojan-activity; sid:100004823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toplevel.com.br",nocase; classtype:trojan-activity; sid:100004824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"torresquinterocorp.com",nocase; classtype:trojan-activity; sid:100004825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"towme.services",nocase; classtype:trojan-activity; sid:100004826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toyotacollege.ac.th",nocase; classtype:trojan-activity; sid:100004827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpef.lsoftdemo.com",nocase; classtype:trojan-activity; sid:100004828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpke.hu",nocase; classtype:trojan-activity; sid:100004829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tradezone.ejuicysolutions.com",nocase; classtype:trojan-activity; sid:100004830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"translaterjemah.com",nocase; classtype:trojan-activity; sid:100004831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"travelwithmanta.co.za",nocase; classtype:trojan-activity; sid:100004832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trezors.io.mahlongwa.com",nocase; classtype:trojan-activity; sid:100004833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"triplonet.com.br",nocase; classtype:trojan-activity; sid:100004834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"troki.com.co",nocase; classtype:trojan-activity; sid:100004835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tropics.codeleek.net",nocase; classtype:trojan-activity; sid:100004836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trucks.softwarenecessities.com",nocase; classtype:trojan-activity; sid:100004837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trudelfavreau.com",nocase; classtype:trojan-activity; sid:100004838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsd.jxwan.com",nocase; classtype:trojan-activity; sid:100004839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tulli.info",nocase; classtype:trojan-activity; sid:100004840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tupperware.michaelroberge.ca",nocase; classtype:trojan-activity; sid:100004841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"turanggaresources.com",nocase; classtype:trojan-activity; sid:100004842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uat.indianfilmzone.com",nocase; classtype:trojan-activity; sid:100004843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ublretailerdemo.cstdevs.com",nocase; classtype:trojan-activity; sid:100004844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uc-56.ru",nocase; classtype:trojan-activity; sid:100004845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"udesk.searchkero.com",nocase; classtype:trojan-activity; sid:100004846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ugprs-ubih.org",nocase; classtype:trojan-activity; sid:100004847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ultimate-24.de",nocase; classtype:trojan-activity; sid:100004848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"umwelt-kirchhof.de",nocase; classtype:trojan-activity; sid:100004849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unicorpbrunei.com",nocase; classtype:trojan-activity; sid:100004850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uniengrisb.com",nocase; classtype:trojan-activity; sid:100004851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unisoftcc.com",nocase; classtype:trojan-activity; sid:100004852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unyazitelecom.com",nocase; classtype:trojan-activity; sid:100004853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"upcbpta.com",nocase; classtype:trojan-activity; sid:100004854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"urbane.dezinetimes.com",nocase; classtype:trojan-activity; sid:100004855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"useformoney.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"usmadetshirts.com",nocase; classtype:trojan-activity; sid:100004857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uss.ac.th",nocase; classtype:trojan-activity; sid:100004858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uzzepay.com.br",nocase; classtype:trojan-activity; sid:100004859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vbcargo.hu",nocase; classtype:trojan-activity; sid:100004860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vcah.co.uk",nocase; classtype:trojan-activity; sid:100004861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vegadelcasero.cl",nocase; classtype:trojan-activity; sid:100004862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vendas.lidiacarmeli.com.br",nocase; classtype:trojan-activity; sid:100004863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"verify.aicosoft.com",nocase; classtype:trojan-activity; sid:100004864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vfocus.net",nocase; classtype:trojan-activity; sid:100004865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vidmattic.com",nocase; classtype:trojan-activity; sid:100004866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vienen.gblix.srv.br",nocase; classtype:trojan-activity; sid:100004867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villamarand.com",nocase; classtype:trojan-activity; sid:100004868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villatera.com",nocase; classtype:trojan-activity; sid:100004869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"violinstop.com",nocase; classtype:trojan-activity; sid:100004870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viraltalking.com",nocase; classtype:trojan-activity; sid:100004871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visions.alnisamart.com",nocase; classtype:trojan-activity; sid:100004872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visualhome.cl",nocase; classtype:trojan-activity; sid:100004873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vitoriamodaintima.com.br",nocase; classtype:trojan-activity; sid:100004874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vivationdesign.com",nocase; classtype:trojan-activity; sid:100004875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viveirodoiscorregos.com.br",nocase; classtype:trojan-activity; sid:100004876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vksales.com",nocase; classtype:trojan-activity; sid:100004877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vladimirinternational.com",nocase; classtype:trojan-activity; sid:100004878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vokasi.ub.ac.id",nocase; classtype:trojan-activity; sid:100004879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vologroup.com.br",nocase; classtype:trojan-activity; sid:100004880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"voteyouramerica.dekitout.com",nocase; classtype:trojan-activity; sid:100004881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vstsample.com",nocase; classtype:trojan-activity; sid:100004882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vtube.fadlymotivator.com",nocase; classtype:trojan-activity; sid:100004883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vvsskmodinationalschool.com",nocase; classtype:trojan-activity; sid:100004884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepliberia.org",nocase; classtype:trojan-activity; sid:100004885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepniger.org",nocase; classtype:trojan-activity; sid:100004886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weareactum.com",nocase; classtype:trojan-activity; sid:100004887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.eng.ubu.ac.th",nocase; classtype:trojan-activity; sid:100004888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geetle.ga",nocase; classtype:trojan-activity; sid:100004889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geomegasoft.net",nocase; classtype:trojan-activity; sid:100004890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.newinnovationtechnology.com",nocase; classtype:trojan-activity; sid:100004891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.smarts-works.com",nocase; classtype:trojan-activity; sid:100004892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.thebeessolution.com",nocase; classtype:trojan-activity; sid:100004893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webgis.perumdasolo.com",nocase; classtype:trojan-activity; sid:100004894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga",nocase; classtype:trojan-activity; sid:100004895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webpresario.com",nocase; classtype:trojan-activity; sid:100004896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"website-work.com",nocase; classtype:trojan-activity; sid:100004897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weinsteincounseling.com",nocase; classtype:trojan-activity; sid:100004898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wexfashion.com",nocase; classtype:trojan-activity; sid:100004899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whcms.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteglovetailgate.com",nocase; classtype:trojan-activity; sid:100004901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteresponse.com",nocase; classtype:trojan-activity; sid:100004902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wi522012.ferozo.com",nocase; classtype:trojan-activity; sid:100004903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikalen.co.za",nocase; classtype:trojan-activity; sid:100004904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildnights.co.uk",nocase; classtype:trojan-activity; sid:100004905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildtrust.mediadevstaging.com",nocase; classtype:trojan-activity; sid:100004906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wimbamusica.com",nocase; classtype:trojan-activity; sid:100004907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"windcomtechnologies.com",nocase; classtype:trojan-activity; sid:100004908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wishesconcierge.com",nocase; classtype:trojan-activity; sid:100004909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woezon.agency",nocase; classtype:trojan-activity; sid:100004910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wolfgang-brodte.de",nocase; classtype:trojan-activity; sid:100004911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woodsytech.com",nocase; classtype:trojan-activity; sid:100004912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wordpress.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100004913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wozata.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wp.readhere.in",nocase; classtype:trojan-activity; sid:100004915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wpdemo.101clients.com.au",nocase; classtype:trojan-activity; sid:100004916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"writtendeer.com",nocase; classtype:trojan-activity; sid:100004917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ws5588.f3322.net",nocase; classtype:trojan-activity; sid:100004918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wyklej.pl",nocase; classtype:trojan-activity; sid:100004919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"x2vn.com",nocase; classtype:trojan-activity; sid:100004920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xia.beihaixue.com",nocase; classtype:trojan-activity; sid:100004921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xixaoclothing.com",nocase; classtype:trojan-activity; sid:100004922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xk.996is.com",nocase; classtype:trojan-activity; sid:100004923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--80akinnkiib6h.xn--90ais",nocase; classtype:trojan-activity; sid:100004924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--polimerbizmimarlk-rvc.com",nocase; classtype:trojan-activity; sid:100004925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ybom.urbanolab.com",nocase; classtype:trojan-activity; sid:100004926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yeichner.com",nocase; classtype:trojan-activity; sid:100004927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ylfpremium.com",nocase; classtype:trojan-activity; sid:100004928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yoast.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yourtopdog.com.au",nocase; classtype:trojan-activity; sid:100004930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"youtubetrainingacademy.com",nocase; classtype:trojan-activity; sid:100004931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yp.hnggzyjy.cn",nocase; classtype:trojan-activity; sid:100004932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yskadvisors.com",nocase; classtype:trojan-activity; sid:100004933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yummyyogaudaipur.com",nocase; classtype:trojan-activity; sid:100004934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yzkzixun.com",nocase; classtype:trojan-activity; sid:100004935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zakra.tecnasulstore.com.br",nocase; classtype:trojan-activity; sid:100004936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zytrox.tk",nocase; classtype:trojan-activity; sid:100004937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zz.690tx.com",nocase; classtype:trojan-activity; sid:100004938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amumufree.weebly.com",nocase; http_uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe",nocase; classtype:trojan-activity; sid:100004939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"analogx.com",nocase; http_uri; content:"/files/proxyi.exe",nocase; classtype:trojan-activity; sid:100004940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe",nocase; classtype:trojan-activity; sid:100004941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/densjons/bro/downloads/rew.exe",nocase; classtype:trojan-activity; sid:100004942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/dvdfv/anjj/downloads/jami.exe",nocase; classtype:trojan-activity; sid:100004943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/4.exe",nocase; classtype:trojan-activity; sid:100004944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/6.exe",nocase; classtype:trojan-activity; sid:100004945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr.exe",nocase; classtype:trojan-activity; sid:100004946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr3.exe",nocase; classtype:trojan-activity; sid:100004947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/instaler.exe",nocase; classtype:trojan-activity; sid:100004948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/installer.exe",nocase; classtype:trojan-activity; sid:100004949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatej.exe",nocase; classtype:trojan-activity; sid:100004950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatev.exe",nocase; classtype:trojan-activity; sid:100004951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/work.exe",nocase; classtype:trojan-activity; sid:100004952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/component.exe",nocase; classtype:trojan-activity; sid:100004953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe",nocase; classtype:trojan-activity; sid:100004954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/regsvc.exe",nocase; classtype:trojan-activity; sid:100004955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/skygaming/updates/downloads/update.exe",nocase; classtype:trojan-activity; sid:100004956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/001.txt",nocase; classtype:trojan-activity; sid:100004957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1488.txt",nocase; classtype:trojan-activity; sid:100004958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1_cr.txt",nocase; classtype:trojan-activity; sid:100004959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1cr.txt",nocase; classtype:trojan-activity; sid:100004960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1fc2d.txt",nocase; classtype:trojan-activity; sid:100004961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/26a5.txt",nocase; classtype:trojan-activity; sid:100004962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt",nocase; classtype:trojan-activity; sid:100004963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/abjects.txt",nocase; classtype:trojan-activity; sid:100004964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/attached.txt",nocase; classtype:trojan-activity; sid:100004965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/b7f2c.exe",nocase; classtype:trojan-activity; sid:100004966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/battletext.txt",nocase; classtype:trojan-activity; sid:100004967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe",nocase; classtype:trojan-activity; sid:100004968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe",nocase; classtype:trojan-activity; sid:100004969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build.txt",nocase; classtype:trojan-activity; sid:100004970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_makros.exe",nocase; classtype:trojan-activity; sid:100004971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_silent.txt",nocase; classtype:trojan-activity; sid:100004972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_sup.txt",nocase; classtype:trojan-activity; sid:100004973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe",nocase; classtype:trojan-activity; sid:100004974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt",nocase; classtype:trojan-activity; sid:100004975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcr.txt",nocase; classtype:trojan-activity; sid:100004976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildss.txt",nocase; classtype:trojan-activity; sid:100004977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientnik.txt",nocase; classtype:trojan-activity; sid:100004978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientrevers.txt",nocase; classtype:trojan-activity; sid:100004979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dcrat.exe",nocase; classtype:trojan-activity; sid:100004980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices.exe",nocase; classtype:trojan-activity; sid:100004981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices2.exe",nocase; classtype:trojan-activity; sid:100004982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe",nocase; classtype:trojan-activity; sid:100004983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hans.txt",nocase; classtype:trojan-activity; sid:100004984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hulu.txt",nocase; classtype:trojan-activity; sid:100004985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfive.txt",nocase; classtype:trojan-activity; sid:100004986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfour.txt",nocase; classtype:trojan-activity; sid:100004987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelone.txt",nocase; classtype:trojan-activity; sid:100004988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelthree.txt",nocase; classtype:trojan-activity; sid:100004989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/inteltwo.txt",nocase; classtype:trojan-activity; sid:100004990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe",nocase; classtype:trojan-activity; sid:100004991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/kleiman.exe",nocase; classtype:trojan-activity; sid:100004992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe",nocase; classtype:trojan-activity; sid:100004993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/notepadplus.txt",nocase; classtype:trojan-activity; sid:100004994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe",nocase; classtype:trojan-activity; sid:100004995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.exe",nocase; classtype:trojan-activity; sid:100004996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.txt",nocase; classtype:trojan-activity; sid:100004997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt",nocase; classtype:trojan-activity; sid:100004998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/putty.txt",nocase; classtype:trojan-activity; sid:100004999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/rockethcd.txt",nocase; classtype:trojan-activity; sid:100005000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/scvhost900.exe",nocase; classtype:trojan-activity; sid:100005001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/sessionwin.exe",nocase; classtype:trojan-activity; sid:100005002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/siliculose.txt",nocase; classtype:trojan-activity; sid:100005003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/statemobi.txt",nocase; classtype:trojan-activity; sid:100005004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers.exe",nocase; classtype:trojan-activity; sid:100005005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers2.exe",nocase; classtype:trojan-activity; sid:100005006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stgedo.exe",nocase; classtype:trojan-activity; sid:100005007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/svcperf.txt",nocase; classtype:trojan-activity; sid:100005008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe",nocase; classtype:trojan-activity; sid:100005009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurjok.txt",nocase; classtype:trojan-activity; sid:100005010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurusbabac.exe",nocase; classtype:trojan-activity; sid:100005011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/telekiller.exe",nocase; classtype:trojan-activity; sid:100005012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateanddr.txt",nocase; classtype:trojan-activity; sid:100005013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateandr.txt",nocase; classtype:trojan-activity; sid:100005014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/vhajeja.txt",nocase; classtype:trojan-activity; sid:100005015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/word.txt",nocase; classtype:trojan-activity; sid:100005016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/www.txt",nocase; classtype:trojan-activity; sid:100005017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/xlsd.txt",nocase; classtype:trojan-activity; sid:100005018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin",nocase; classtype:trojan-activity; sid:100005019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin",nocase; classtype:trojan-activity; sid:100005020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cd.textfiles.com",nocase; http_uri; content:"/hmatrix/data/hack1226.exe",nocase; classtype:trojan-activity; sid:100005021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq",nocase; classtype:trojan-activity; sid:100005022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/816070119281131570/816070273254162442/all.txt",nocase; classtype:trojan-activity; sid:100005023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso",nocase; classtype:trojan-activity; sid:100005024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chiptune.com",nocase; http_uri; content:"/razor/rzr-winner_intro.zip",nocase; classtype:trojan-activity; sid:100005025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz",nocase; classtype:trojan-activity; sid:100005026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar",nocase; classtype:trojan-activity; sid:100005027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codeload.github.com",nocase; http_uri; content:"/meteoradminz/hidden-tear/zip/master",nocase; classtype:trojan-activity; sid:100005028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colfincas.com",nocase; http_uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/",nocase; classtype:trojan-activity; sid:100005029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deepfreedom.org",nocase; http_uri; content:"/qz0h69.pdf",nocase; classtype:trojan-activity; sid:100005030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=11jnyjpzkjiie_rzc4xwa2feok3x__yvc",nocase; classtype:trojan-activity; sid:100005031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=151uxflny3vqh_lmghrkgjhhsqxi163sh",nocase; classtype:trojan-activity; sid:100005032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=15iwonkjkhyvri_okkc_llq56aasvnvb9",nocase; classtype:trojan-activity; sid:100005033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=16gqndqbduwuhy3qzxdn2nd9nufm_9ctq",nocase; classtype:trojan-activity; sid:100005034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1ak46tqftzejmq-og_ky2oupgpmkgujtm",nocase; classtype:trojan-activity; sid:100005035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1b6stzilakqykxaw1ct2w9hzccizwotff",nocase; classtype:trojan-activity; sid:100005036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1brsmnj6g0lxa44ixkypvg5tcxkvi5gjt",nocase; classtype:trojan-activity; sid:100005037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1by_s4vv8gdmmz8wl-lbpjbjy5adcrjk1",nocase; classtype:trojan-activity; sid:100005038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1dpsxfbptpyl-zegto9t29vvcku2rjm9u",nocase; classtype:trojan-activity; sid:100005039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1dwb7nww_ahtjfeed-afxl4hvm_xqkx-h",nocase; classtype:trojan-activity; sid:100005040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1e7t_hnuohxuziwcxihocdievcj5_dsgj",nocase; classtype:trojan-activity; sid:100005041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1erajjbz6gdxhsvvorlykzxyeoq-xu7wn",nocase; classtype:trojan-activity; sid:100005042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1ev7gkzwjgtv2vlbbisg1ragd7nf0-xog",nocase; classtype:trojan-activity; sid:100005043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1ey8zl85vszh-gdmubkoudacqs6zv2dup",nocase; classtype:trojan-activity; sid:100005044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1f5trx90ulgsd-m1zvdupuf_kfugoo9ye",nocase; classtype:trojan-activity; sid:100005045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1gq_jf503du9oip5bwzcoi6_kgolr3kx2",nocase; classtype:trojan-activity; sid:100005046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1hlaoow8ug5gjejeeihwetcxyfjodcdut",nocase; classtype:trojan-activity; sid:100005047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1imrv00kqbfz4ljzwq5qdau1to0zlmaqy",nocase; classtype:trojan-activity; sid:100005048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1j6pvg1rznjh9pkldcyjiogo8ysiyl8_y",nocase; classtype:trojan-activity; sid:100005049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1jlcqojhfhgifmirrsv0o5t-2rl-hblai",nocase; classtype:trojan-activity; sid:100005050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1jvvuxwek4wrjqs94bjm8_klnnngj7b5r",nocase; classtype:trojan-activity; sid:100005051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1k6sh5h-nptesem_jsnuxmhzntnvdlgxz",nocase; classtype:trojan-activity; sid:100005052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1lc8lpsmu5ndjweyusqrxblm0g84sdcc7",nocase; classtype:trojan-activity; sid:100005053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1lk6n-xrtv0dvdqljl26pzebxzp8tladk",nocase; classtype:trojan-activity; sid:100005054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1lkcqgpimry4yp8grinnhsotnawquozcz",nocase; classtype:trojan-activity; sid:100005055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1m34mp1cggxz-cz3a5ipjrgfog_qx8myx",nocase; classtype:trojan-activity; sid:100005056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1m6kdawqt1fwxea6epcae6t1qevfhl0-5",nocase; classtype:trojan-activity; sid:100005057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1m8w1y1-mxxa2pktrzkwfetwjxrlw1alo",nocase; classtype:trojan-activity; sid:100005058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1m9jxzqcbnb8j8uph1qfcas8b9pngcogj",nocase; classtype:trojan-activity; sid:100005059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1mdnlxs6vy5qk-u4dxz9movem4j3a3o-8",nocase; classtype:trojan-activity; sid:100005060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1o6omlk34dxy3cbai8rvkvrnp5g-ovsj-",nocase; classtype:trojan-activity; sid:100005061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1od6gtslxvylgyeujmrbvm9yhupmq_1lv",nocase; classtype:trojan-activity; sid:100005062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1ozpasp-mr-e-ui4lshy4qy4a2pl8pxsi",nocase; classtype:trojan-activity; sid:100005063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1pnmkgw-rlm9mjstqdxfcq0en07_x93ue",nocase; classtype:trojan-activity; sid:100005064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1q0edpjr7vgo_ytns7dgjcav6317juz9y",nocase; classtype:trojan-activity; sid:100005065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1q5gqeinogsri3i-ynlgvu88ajqnn9siq",nocase; classtype:trojan-activity; sid:100005066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1quyiobd7-d-vcddlhxiqbqrwxyg7ongo",nocase; classtype:trojan-activity; sid:100005067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1qyzpbxbnmnbp5opdk5rmeplmbga9c_q9",nocase; classtype:trojan-activity; sid:100005068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1rrtyvouwizor2icbcoywdid4w9rwngxi",nocase; classtype:trojan-activity; sid:100005069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1sao6yxf-a0t6wdgdr36srwlju57vigx_",nocase; classtype:trojan-activity; sid:100005070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1sbg8kdmxp5futgje5jcfvh-ieq28holg",nocase; classtype:trojan-activity; sid:100005071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1seb4h5c8z5jaf2_ulvhdv7mzqzmntp0k",nocase; classtype:trojan-activity; sid:100005072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1skuwjvkgsmicbr1o48gnalcksfytwtdp",nocase; classtype:trojan-activity; sid:100005073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1st5mtgqyofsskuhlomfihfmz_qx-i32o",nocase; classtype:trojan-activity; sid:100005074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1umz5zjobot9__v2jxdutyborb2az90hz",nocase; classtype:trojan-activity; sid:100005075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1we-h5qtxj9czhkhzvzg0qqpxufgu_v__",nocase; classtype:trojan-activity; sid:100005076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1wmi0gpfe9ebcgai4w6iw6pninxo6ke-m",nocase; classtype:trojan-activity; sid:100005077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1wurpipyf0s__fqtn1ov619nx7v1-tcy3",nocase; classtype:trojan-activity; sid:100005078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1wwkqbfluu4qusqz26ewulr48zh9vzq-w",nocase; classtype:trojan-activity; sid:100005079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1xbvceq1wmfjad59zyxwtykzy3xwy9iqb",nocase; classtype:trojan-activity; sid:100005080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1xqcnagjbut3pdajnpsx0nonhla3nqes-",nocase; classtype:trojan-activity; sid:100005081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1xsj8d2ysnoluawhk3g4tadaoyp8ktmab",nocase; classtype:trojan-activity; sid:100005082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1xtflvdimom8odrygcmip7j4aesrjtgsm",nocase; classtype:trojan-activity; sid:100005083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1yyuejm8cerrq2tctsibww4uetepcmh4i",nocase; classtype:trojan-activity; sid:100005084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com.it-barcelona.com",nocase; http_uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe",nocase; classtype:trojan-activity; sid:100005085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm",nocase; classtype:trojan-activity; sid:100005086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1",nocase; classtype:trojan-activity; sid:100005087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch",nocase; classtype:trojan-activity; sid:100005088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox",nocase; classtype:trojan-activity; sid:100005089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig",nocase; classtype:trojan-activity; sid:100005090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn",nocase; classtype:trojan-activity; sid:100005091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben",nocase; classtype:trojan-activity; sid:100005092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi",nocase; classtype:trojan-activity; sid:100005093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je",nocase; classtype:trojan-activity; sid:100005094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev",nocase; classtype:trojan-activity; sid:100005095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr",nocase; classtype:trojan-activity; sid:100005096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y",nocase; classtype:trojan-activity; sid:100005097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd",nocase; classtype:trojan-activity; sid:100005098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw",nocase; classtype:trojan-activity; sid:100005099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej",nocase; classtype:trojan-activity; sid:100005100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn",nocase; classtype:trojan-activity; sid:100005101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw",nocase; classtype:trojan-activity; sid:100005102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76",nocase; classtype:trojan-activity; sid:100005103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55",nocase; classtype:trojan-activity; sid:100005104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t",nocase; classtype:trojan-activity; sid:100005105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e",nocase; classtype:trojan-activity; sid:100005106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi",nocase; classtype:trojan-activity; sid:100005107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv",nocase; classtype:trojan-activity; sid:100005108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr",nocase; classtype:trojan-activity; sid:100005109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0",nocase; classtype:trojan-activity; sid:100005110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/1zilg/",nocase; classtype:trojan-activity; sid:100005111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/qcgfmfvh/",nocase; classtype:trojan-activity; sid:100005112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-mudhra.com",nocase; http_uri; content:"/downloads/emclick.zip",nocase; classtype:trojan-activity; sid:100005113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe",nocase; classtype:trojan-activity; sid:100005114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe",nocase; classtype:trojan-activity; sid:100005115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/",nocase; classtype:trojan-activity; sid:100005116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/",nocase; classtype:trojan-activity; sid:100005117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/x/",nocase; classtype:trojan-activity; sid:100005118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/",nocase; classtype:trojan-activity; sid:100005119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//",nocase; classtype:trojan-activity; sid:100005120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///",nocase; classtype:trojan-activity; sid:100005121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////",nocase; classtype:trojan-activity; sid:100005122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"file.elecfans.com",nocase; http_uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe",nocase; classtype:trojan-activity; sid:100005123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls",nocase; classtype:trojan-activity; sid:100005124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx",nocase; classtype:trojan-activity; sid:100005125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gist.githubusercontent.com",nocase; http_uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe",nocase; classtype:trojan-activity; sid:100005126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hqdecig.com",nocase; http_uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/",nocase; classtype:trojan-activity; sid:100005127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsecaravans.co.uk",nocase; http_uri; content:"/wp-admin/suy/",nocase; classtype:trojan-activity; sid:100005128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ia801802.us.archive.org",nocase; http_uri; content:"/19/items/startup_20210219/startup.txt",nocase; classtype:trojan-activity; sid:100005129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ie-best.net",nocase; http_uri; content:"/online-timer-kvhxz/ilxl/",nocase; classtype:trojan-activity; sid:100005130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100005131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100005132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jcedu.org",nocase; http_uri; content:"/ebook/cs17.exe",nocase; classtype:trojan-activity; sid:100005133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1",nocase; classtype:trojan-activity; sid:100005134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2",nocase; classtype:trojan-activity; sid:100005135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3",nocase; classtype:trojan-activity; sid:100005136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"justlficante.mediafire.com",nocase; http_uri; content:"/file/jl01o54yy09qrzg/fac215.tgz/file",nocase; classtype:trojan-activity; sid:100005137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karmakoincodes.weebly.com",nocase; http_uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe",nocase; classtype:trojan-activity; sid:100005138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kotakwarna.co.id",nocase; http_uri; content:"/dg/etrac/nf4emwz/",nocase; classtype:trojan-activity; sid:100005139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ksh.hu",nocase; http_uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe",nocase; classtype:trojan-activity; sid:100005140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kuaizip.com",nocase; http_uri; content:"/down/affiliate/kuaizip_setup_10029.exe",nocase; classtype:trojan-activity; sid:100005141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linuxforensicsbook.com.s3.amazonaws.com",nocase; http_uri; content:"/linuxforensicscode.zip",nocase; classtype:trojan-activity; sid:100005142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minpic.de",nocase; http_uri; content:"/k/big5/1giof6/",nocase; classtype:trojan-activity; sid:100005143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"morrobaydrugandgift.com",nocase; http_uri; content:"/wp-contentbak/t9m/",nocase; classtype:trojan-activity; sid:100005144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"my.cloudme.com",nocase; http_uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe",nocase; classtype:trojan-activity; sid:100005145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/aacenc.exe",nocase; classtype:trojan-activity; sid:100005146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/doxillionsetup.exe",nocase; classtype:trojan-activity; sid:100005147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newyarlfm.weebly.com",nocase; http_uri; content:"/uploads/4/1/6/6/4166984/keygen.exe",nocase; classtype:trojan-activity; sid:100005148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhipcauytevietnhat.com",nocase; http_uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/",nocase; classtype:trojan-activity; sid:100005149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"note.youdao.com",nocase; http_uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a",nocase; classtype:trojan-activity; sid:100005150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oldschoolvalue.s3.amazonaws.com",nocase; http_uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe",nocase; classtype:trojan-activity; sid:100005151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq",nocase; classtype:trojan-activity; sid:100005152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq",nocase; classtype:trojan-activity; sid:100005153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa",nocase; classtype:trojan-activity; sid:100005154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq",nocase; classtype:trojan-activity; sid:100005155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe",nocase; classtype:trojan-activity; sid:100005156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg",nocase; classtype:trojan-activity; sid:100005157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0",nocase; classtype:trojan-activity; sid:100005158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g",nocase; classtype:trojan-activity; sid:100005159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140",nocase; classtype:trojan-activity; sid:100005160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130",nocase; classtype:trojan-activity; sid:100005161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135",nocase; classtype:trojan-activity; sid:100005162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732",nocase; classtype:trojan-activity; sid:100005163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4",nocase; classtype:trojan-activity; sid:100005164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100005165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100005166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0",nocase; classtype:trojan-activity; sid:100005167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100005168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100005169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100005170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100005171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc",nocase; classtype:trojan-activity; sid:100005172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq",nocase; classtype:trojan-activity; sid:100005173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko",nocase; classtype:trojan-activity; sid:100005174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw",nocase; classtype:trojan-activity; sid:100005175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4",nocase; classtype:trojan-activity; sid:100005176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4",nocase; classtype:trojan-activity; sid:100005177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma",nocase; classtype:trojan-activity; sid:100005178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48",nocase; classtype:trojan-activity; sid:100005179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg",nocase; classtype:trojan-activity; sid:100005180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw",nocase; classtype:trojan-activity; sid:100005181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq",nocase; classtype:trojan-activity; sid:100005182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100005183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100005184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100005185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100005186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4",nocase; classtype:trojan-activity; sid:100005187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100005188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100005189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw",nocase; classtype:trojan-activity; sid:100005190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0",nocase; classtype:trojan-activity; sid:100005191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk",nocase; classtype:trojan-activity; sid:100005192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk",nocase; classtype:trojan-activity; sid:100005193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a",nocase; classtype:trojan-activity; sid:100005194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4",nocase; classtype:trojan-activity; sid:100005195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo",nocase; classtype:trojan-activity; sid:100005196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100005197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100005198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc",nocase; classtype:trojan-activity; sid:100005199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc",nocase; classtype:trojan-activity; sid:100005200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100005201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100005202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100005203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100005204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100005205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100005206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve",nocase; classtype:trojan-activity; sid:100005207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w",nocase; classtype:trojan-activity; sid:100005208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100005209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100005210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg",nocase; classtype:trojan-activity; sid:100005211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60",nocase; classtype:trojan-activity; sid:100005212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg",nocase; classtype:trojan-activity; sid:100005213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4",nocase; classtype:trojan-activity; sid:100005214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c",nocase; classtype:trojan-activity; sid:100005215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0",nocase; classtype:trojan-activity; sid:100005216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100005217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs",nocase; classtype:trojan-activity; sid:100005218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0",nocase; classtype:trojan-activity; sid:100005219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd",nocase; classtype:trojan-activity; sid:100005220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc",nocase; classtype:trojan-activity; sid:100005221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100005222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po",nocase; classtype:trojan-activity; sid:100005223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe",nocase; classtype:trojan-activity; sid:100005224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk",nocase; classtype:trojan-activity; sid:100005225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100005226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100005227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu",nocase; classtype:trojan-activity; sid:100005228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k",nocase; classtype:trojan-activity; sid:100005229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo",nocase; classtype:trojan-activity; sid:100005230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk",nocase; classtype:trojan-activity; sid:100005231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei",nocase; classtype:trojan-activity; sid:100005232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte",nocase; classtype:trojan-activity; sid:100005233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk",nocase; classtype:trojan-activity; sid:100005234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei",nocase; classtype:trojan-activity; sid:100005235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte",nocase; classtype:trojan-activity; sid:100005236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga",nocase; classtype:trojan-activity; sid:100005237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly",nocase; classtype:trojan-activity; sid:100005238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs",nocase; classtype:trojan-activity; sid:100005239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs",nocase; classtype:trojan-activity; sid:100005240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0",nocase; classtype:trojan-activity; sid:100005241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620",nocase; classtype:trojan-activity; sid:100005242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo",nocase; classtype:trojan-activity; sid:100005243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e",nocase; classtype:trojan-activity; sid:100005244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100005245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100005246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw",nocase; classtype:trojan-activity; sid:100005247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw",nocase; classtype:trojan-activity; sid:100005248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4",nocase; classtype:trojan-activity; sid:100005249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w",nocase; classtype:trojan-activity; sid:100005250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100005251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8",nocase; classtype:trojan-activity; sid:100005252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100005253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw",nocase; classtype:trojan-activity; sid:100005254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8",nocase; classtype:trojan-activity; sid:100005255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100005256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100005257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100005258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100005259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq",nocase; classtype:trojan-activity; sid:100005260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o",nocase; classtype:trojan-activity; sid:100005261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc",nocase; classtype:trojan-activity; sid:100005262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0",nocase; classtype:trojan-activity; sid:100005263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100005264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100005265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100005266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100005267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo",nocase; classtype:trojan-activity; sid:100005268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou",nocase; classtype:trojan-activity; sid:100005269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo",nocase; classtype:trojan-activity; sid:100005270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou",nocase; classtype:trojan-activity; sid:100005271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100005272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100005273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100005274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100005275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk",nocase; classtype:trojan-activity; sid:100005276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100005277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100005278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge",nocase; classtype:trojan-activity; sid:100005279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs",nocase; classtype:trojan-activity; sid:100005280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100005281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100005282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100005283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100005284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0",nocase; classtype:trojan-activity; sid:100005285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100005286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100005287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik",nocase; classtype:trojan-activity; sid:100005288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq",nocase; classtype:trojan-activity; sid:100005289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy",nocase; classtype:trojan-activity; sid:100005290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100005291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100005292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8",nocase; classtype:trojan-activity; sid:100005293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c",nocase; classtype:trojan-activity; sid:100005294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y",nocase; classtype:trojan-activity; sid:100005295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100005296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100005297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100005298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100005299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y",nocase; classtype:trojan-activity; sid:100005300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo",nocase; classtype:trojan-activity; sid:100005301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4",nocase; classtype:trojan-activity; sid:100005302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm",nocase; classtype:trojan-activity; sid:100005303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu",nocase; classtype:trojan-activity; sid:100005304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100005305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc",nocase; classtype:trojan-activity; sid:100005306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y",nocase; classtype:trojan-activity; sid:100005307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8",nocase; classtype:trojan-activity; sid:100005308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0",nocase; classtype:trojan-activity; sid:100005309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc",nocase; classtype:trojan-activity; sid:100005310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs",nocase; classtype:trojan-activity; sid:100005311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts",nocase; classtype:trojan-activity; sid:100005312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc",nocase; classtype:trojan-activity; sid:100005313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg",nocase; classtype:trojan-activity; sid:100005314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y",nocase; classtype:trojan-activity; sid:100005315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday",nocase; classtype:trojan-activity; sid:100005316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0",nocase; classtype:trojan-activity; sid:100005317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas",nocase; classtype:trojan-activity; sid:100005318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve",nocase; classtype:trojan-activity; sid:100005319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy",nocase; classtype:trojan-activity; sid:100005320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14",nocase; classtype:trojan-activity; sid:100005321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i",nocase; classtype:trojan-activity; sid:100005322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa",nocase; classtype:trojan-activity; sid:100005323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu",nocase; classtype:trojan-activity; sid:100005324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c",nocase; classtype:trojan-activity; sid:100005325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q",nocase; classtype:trojan-activity; sid:100005326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm",nocase; classtype:trojan-activity; sid:100005327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4",nocase; classtype:trojan-activity; sid:100005328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho",nocase; classtype:trojan-activity; sid:100005329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18",nocase; classtype:trojan-activity; sid:100005330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q",nocase; classtype:trojan-activity; sid:100005331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm",nocase; classtype:trojan-activity; sid:100005332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na",nocase; classtype:trojan-activity; sid:100005333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk",nocase; classtype:trojan-activity; sid:100005334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe",nocase; classtype:trojan-activity; sid:100005335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi",nocase; classtype:trojan-activity; sid:100005336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc",nocase; classtype:trojan-activity; sid:100005337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc",nocase; classtype:trojan-activity; sid:100005338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100005339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100005340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100005341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100005342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100005343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100005344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100005345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100005346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100005347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100005348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100005349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100005350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4",nocase; classtype:trojan-activity; sid:100005351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu",nocase; classtype:trojan-activity; sid:100005352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi",nocase; classtype:trojan-activity; sid:100005353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8",nocase; classtype:trojan-activity; sid:100005354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8",nocase; classtype:trojan-activity; sid:100005355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100005356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100005357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8",nocase; classtype:trojan-activity; sid:100005358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100005359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100005360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100005361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100005362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g",nocase; classtype:trojan-activity; sid:100005363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum",nocase; classtype:trojan-activity; sid:100005364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa",nocase; classtype:trojan-activity; sid:100005365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi",nocase; classtype:trojan-activity; sid:100005366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy",nocase; classtype:trojan-activity; sid:100005367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o",nocase; classtype:trojan-activity; sid:100005368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa",nocase; classtype:trojan-activity; sid:100005369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100005370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100005371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc",nocase; classtype:trojan-activity; sid:100005372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk",nocase; classtype:trojan-activity; sid:100005373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea",nocase; classtype:trojan-activity; sid:100005374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100005375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100005376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100005377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100005378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100005379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100005380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo",nocase; classtype:trojan-activity; sid:100005381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva",nocase; classtype:trojan-activity; sid:100005382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc",nocase; classtype:trojan-activity; sid:100005383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles",nocase; classtype:trojan-activity; sid:100005384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg",nocase; classtype:trojan-activity; sid:100005385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100005386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100005387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100005388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw",nocase; classtype:trojan-activity; sid:100005389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8",nocase; classtype:trojan-activity; sid:100005390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq",nocase; classtype:trojan-activity; sid:100005391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug",nocase; classtype:trojan-activity; sid:100005392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua",nocase; classtype:trojan-activity; sid:100005393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe",nocase; classtype:trojan-activity; sid:100005394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa",nocase; classtype:trojan-activity; sid:100005395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe",nocase; classtype:trojan-activity; sid:100005396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4",nocase; classtype:trojan-activity; sid:100005397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa",nocase; classtype:trojan-activity; sid:100005398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w",nocase; classtype:trojan-activity; sid:100005399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo",nocase; classtype:trojan-activity; sid:100005400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4",nocase; classtype:trojan-activity; sid:100005401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa",nocase; classtype:trojan-activity; sid:100005402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w",nocase; classtype:trojan-activity; sid:100005403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo",nocase; classtype:trojan-activity; sid:100005404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi",nocase; classtype:trojan-activity; sid:100005405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e",nocase; classtype:trojan-activity; sid:100005406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100005407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100005408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk",nocase; classtype:trojan-activity; sid:100005409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4",nocase; classtype:trojan-activity; sid:100005410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo",nocase; classtype:trojan-activity; sid:100005411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji",nocase; classtype:trojan-activity; sid:100005412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100005413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100005414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg",nocase; classtype:trojan-activity; sid:100005415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70",nocase; classtype:trojan-activity; sid:100005416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc",nocase; classtype:trojan-activity; sid:100005417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100005418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100005419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100005420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100005421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw",nocase; classtype:trojan-activity; sid:100005422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq",nocase; classtype:trojan-activity; sid:100005423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm",nocase; classtype:trojan-activity; sid:100005424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100005425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100005426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8",nocase; classtype:trojan-activity; sid:100005427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100005428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100005429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!296&authkey=adsdrrjllbu1nwa",nocase; classtype:trojan-activity; sid:100005430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!297&authkey=am7nspchat4aqtw",nocase; classtype:trojan-activity; sid:100005431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21296&authkey=adsdrrjllbu1nwa",nocase; classtype:trojan-activity; sid:100005432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu",nocase; classtype:trojan-activity; sid:100005433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i",nocase; classtype:trojan-activity; sid:100005434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam",nocase; classtype:trojan-activity; sid:100005435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble",nocase; classtype:trojan-activity; sid:100005436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60",nocase; classtype:trojan-activity; sid:100005437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k",nocase; classtype:trojan-activity; sid:100005438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8",nocase; classtype:trojan-activity; sid:100005439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg",nocase; classtype:trojan-activity; sid:100005440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte",nocase; classtype:trojan-activity; sid:100005441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34",nocase; classtype:trojan-activity; sid:100005442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w",nocase; classtype:trojan-activity; sid:100005443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta",nocase; classtype:trojan-activity; sid:100005444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em",nocase; classtype:trojan-activity; sid:100005445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!210&authkey=agpl0pgvft8faaa",nocase; classtype:trojan-activity; sid:100005446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c",nocase; classtype:trojan-activity; sid:100005447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa",nocase; classtype:trojan-activity; sid:100005448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c",nocase; classtype:trojan-activity; sid:100005449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100005450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100005451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100005452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100005453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm",nocase; classtype:trojan-activity; sid:100005454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq",nocase; classtype:trojan-activity; sid:100005455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k",nocase; classtype:trojan-activity; sid:100005456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100005457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100005458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100005459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100005460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100005461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100005462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs",nocase; classtype:trojan-activity; sid:100005463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli",nocase; classtype:trojan-activity; sid:100005464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18",nocase; classtype:trojan-activity; sid:100005465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli",nocase; classtype:trojan-activity; sid:100005466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c",nocase; classtype:trojan-activity; sid:100005467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0",nocase; classtype:trojan-activity; sid:100005468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq",nocase; classtype:trojan-activity; sid:100005469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=80dabacd46496407&resid=80dabacd46496407%21124&authkey=abnj7t59iwijpdy",nocase; classtype:trojan-activity; sid:100005470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda",nocase; classtype:trojan-activity; sid:100005471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm",nocase; classtype:trojan-activity; sid:100005472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk",nocase; classtype:trojan-activity; sid:100005473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4",nocase; classtype:trojan-activity; sid:100005474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c",nocase; classtype:trojan-activity; sid:100005475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100005476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100005477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4",nocase; classtype:trojan-activity; sid:100005478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84",nocase; classtype:trojan-activity; sid:100005479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk",nocase; classtype:trojan-activity; sid:100005480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk",nocase; classtype:trojan-activity; sid:100005481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae",nocase; classtype:trojan-activity; sid:100005482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0",nocase; classtype:trojan-activity; sid:100005483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8",nocase; classtype:trojan-activity; sid:100005484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s",nocase; classtype:trojan-activity; sid:100005485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my",nocase; classtype:trojan-activity; sid:100005486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc",nocase; classtype:trojan-activity; sid:100005487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby",nocase; classtype:trojan-activity; sid:100005488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo",nocase; classtype:trojan-activity; sid:100005489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti",nocase; classtype:trojan-activity; sid:100005490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe",nocase; classtype:trojan-activity; sid:100005491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari",nocase; classtype:trojan-activity; sid:100005492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4",nocase; classtype:trojan-activity; sid:100005493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia",nocase; classtype:trojan-activity; sid:100005494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok",nocase; classtype:trojan-activity; sid:100005495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe",nocase; classtype:trojan-activity; sid:100005496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari",nocase; classtype:trojan-activity; sid:100005497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4",nocase; classtype:trojan-activity; sid:100005498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m",nocase; classtype:trojan-activity; sid:100005499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia",nocase; classtype:trojan-activity; sid:100005500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok",nocase; classtype:trojan-activity; sid:100005501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm",nocase; classtype:trojan-activity; sid:100005502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m",nocase; classtype:trojan-activity; sid:100005503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w",nocase; classtype:trojan-activity; sid:100005504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100005505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100005506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k",nocase; classtype:trojan-activity; sid:100005507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli",nocase; classtype:trojan-activity; sid:100005508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm",nocase; classtype:trojan-activity; sid:100005509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue",nocase; classtype:trojan-activity; sid:100005510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma",nocase; classtype:trojan-activity; sid:100005511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg",nocase; classtype:trojan-activity; sid:100005512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq",nocase; classtype:trojan-activity; sid:100005513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs",nocase; classtype:trojan-activity; sid:100005514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho",nocase; classtype:trojan-activity; sid:100005515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc",nocase; classtype:trojan-activity; sid:100005516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w",nocase; classtype:trojan-activity; sid:100005517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm",nocase; classtype:trojan-activity; sid:100005518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0",nocase; classtype:trojan-activity; sid:100005519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy",nocase; classtype:trojan-activity; sid:100005520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm",nocase; classtype:trojan-activity; sid:100005521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi",nocase; classtype:trojan-activity; sid:100005522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi",nocase; classtype:trojan-activity; sid:100005523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8",nocase; classtype:trojan-activity; sid:100005524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100005525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100005526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o",nocase; classtype:trojan-activity; sid:100005527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4",nocase; classtype:trojan-activity; sid:100005528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi",nocase; classtype:trojan-activity; sid:100005529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100005530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100005531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo",nocase; classtype:trojan-activity; sid:100005532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq",nocase; classtype:trojan-activity; sid:100005533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi",nocase; classtype:trojan-activity; sid:100005534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs",nocase; classtype:trojan-activity; sid:100005535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw",nocase; classtype:trojan-activity; sid:100005536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o",nocase; classtype:trojan-activity; sid:100005537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc",nocase; classtype:trojan-activity; sid:100005538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs",nocase; classtype:trojan-activity; sid:100005539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100005540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100005541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi",nocase; classtype:trojan-activity; sid:100005542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc",nocase; classtype:trojan-activity; sid:100005543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy",nocase; classtype:trojan-activity; sid:100005544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc",nocase; classtype:trojan-activity; sid:100005545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey",nocase; classtype:trojan-activity; sid:100005546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg",nocase; classtype:trojan-activity; sid:100005547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui",nocase; classtype:trojan-activity; sid:100005548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi",nocase; classtype:trojan-activity; sid:100005549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk",nocase; classtype:trojan-activity; sid:100005550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw",nocase; classtype:trojan-activity; sid:100005551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100005552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e",nocase; classtype:trojan-activity; sid:100005553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100005554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100005555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu",nocase; classtype:trojan-activity; sid:100005556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu",nocase; classtype:trojan-activity; sid:100005557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u",nocase; classtype:trojan-activity; sid:100005558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm",nocase; classtype:trojan-activity; sid:100005559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy",nocase; classtype:trojan-activity; sid:100005560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc",nocase; classtype:trojan-activity; sid:100005561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy",nocase; classtype:trojan-activity; sid:100005562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy",nocase; classtype:trojan-activity; sid:100005563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84",nocase; classtype:trojan-activity; sid:100005564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo",nocase; classtype:trojan-activity; sid:100005565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw",nocase; classtype:trojan-activity; sid:100005566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww",nocase; classtype:trojan-activity; sid:100005567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy",nocase; classtype:trojan-activity; sid:100005568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w",nocase; classtype:trojan-activity; sid:100005569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq",nocase; classtype:trojan-activity; sid:100005570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100005571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100005572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg",nocase; classtype:trojan-activity; sid:100005573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg",nocase; classtype:trojan-activity; sid:100005574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100005575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100005576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m",nocase; classtype:trojan-activity; sid:100005577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8",nocase; classtype:trojan-activity; sid:100005578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1045&authkey=aetgoeo_eku-6ba",nocase; classtype:trojan-activity; sid:100005579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211045&authkey=aetgoeo_eku-6ba",nocase; classtype:trojan-activity; sid:100005580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100005581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100005582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq",nocase; classtype:trojan-activity; sid:100005583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm",nocase; classtype:trojan-activity; sid:100005584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai",nocase; classtype:trojan-activity; sid:100005585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk",nocase; classtype:trojan-activity; sid:100005586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100005587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100005588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100005589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100005590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100005591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100005592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100005593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100005594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100005595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100005596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100005597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100005598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100005599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100005600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100005601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100005602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100005603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100005604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100005605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100005606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8",nocase; classtype:trojan-activity; sid:100005607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc",nocase; classtype:trojan-activity; sid:100005608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc",nocase; classtype:trojan-activity; sid:100005609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw",nocase; classtype:trojan-activity; sid:100005610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21122&authkey=ajqq2okqxfq8iuo",nocase; classtype:trojan-activity; sid:100005611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs",nocase; classtype:trojan-activity; sid:100005612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m",nocase; classtype:trojan-activity; sid:100005613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga",nocase; classtype:trojan-activity; sid:100005614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg",nocase; classtype:trojan-activity; sid:100005615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100005616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100005617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw",nocase; classtype:trojan-activity; sid:100005618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100005619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100005620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100005621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100005622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100005623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100005624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100005625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100005626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100005627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100005628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0",nocase; classtype:trojan-activity; sid:100005629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100005630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100005631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100005632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100005633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy",nocase; classtype:trojan-activity; sid:100005634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774!124&authkey=afq42wqejwvcv8o",nocase; classtype:trojan-activity; sid:100005635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774%21124&authkey=afq42wqejwvcv8o",nocase; classtype:trojan-activity; sid:100005636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na",nocase; classtype:trojan-activity; sid:100005637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8",nocase; classtype:trojan-activity; sid:100005638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o",nocase; classtype:trojan-activity; sid:100005639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0",nocase; classtype:trojan-activity; sid:100005640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o",nocase; classtype:trojan-activity; sid:100005641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0",nocase; classtype:trojan-activity; sid:100005642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw",nocase; classtype:trojan-activity; sid:100005643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe",nocase; classtype:trojan-activity; sid:100005644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq",nocase; classtype:trojan-activity; sid:100005645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4",nocase; classtype:trojan-activity; sid:100005646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq",nocase; classtype:trojan-activity; sid:100005647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100005648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100005649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100005650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100005651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100005652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100005653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo",nocase; classtype:trojan-activity; sid:100005654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo",nocase; classtype:trojan-activity; sid:100005655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw",nocase; classtype:trojan-activity; sid:100005656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0",nocase; classtype:trojan-activity; sid:100005657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4",nocase; classtype:trojan-activity; sid:100005658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs",nocase; classtype:trojan-activity; sid:100005659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0",nocase; classtype:trojan-activity; sid:100005660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q",nocase; classtype:trojan-activity; sid:100005661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100005662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100005663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc",nocase; classtype:trojan-activity; sid:100005664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc",nocase; classtype:trojan-activity; sid:100005665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0",nocase; classtype:trojan-activity; sid:100005666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c",nocase; classtype:trojan-activity; sid:100005667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4a3bd996f92bf71&resid=e4a3bd996f92bf71%211944&authkey=ao3lztaialsza88",nocase; classtype:trojan-activity; sid:100005668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg",nocase; classtype:trojan-activity; sid:100005669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100005670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100005671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq",nocase; classtype:trojan-activity; sid:100005672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom",nocase; classtype:trojan-activity; sid:100005673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da",nocase; classtype:trojan-activity; sid:100005674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100005675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100005676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0",nocase; classtype:trojan-activity; sid:100005677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100005678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100005679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai",nocase; classtype:trojan-activity; sid:100005680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc",nocase; classtype:trojan-activity; sid:100005681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8",nocase; classtype:trojan-activity; sid:100005682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns",nocase; classtype:trojan-activity; sid:100005683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8",nocase; classtype:trojan-activity; sid:100005684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4",nocase; classtype:trojan-activity; sid:100005685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100005686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100005687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100005688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100005689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100005690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100005691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0",nocase; classtype:trojan-activity; sid:100005692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw",nocase; classtype:trojan-activity; sid:100005693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e",nocase; classtype:trojan-activity; sid:100005694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu",nocase; classtype:trojan-activity; sid:100005695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq",nocase; classtype:trojan-activity; sid:100005696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k",nocase; classtype:trojan-activity; sid:100005697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie",nocase; classtype:trojan-activity; sid:100005698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c",nocase; classtype:trojan-activity; sid:100005699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g",nocase; classtype:trojan-activity; sid:100005700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta",nocase; classtype:trojan-activity; sid:100005701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100005702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao",nocase; classtype:trojan-activity; sid:100005703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk",nocase; classtype:trojan-activity; sid:100005704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100005705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk",nocase; classtype:trojan-activity; sid:100005706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw",nocase; classtype:trojan-activity; sid:100005707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty",nocase; classtype:trojan-activity; sid:100005708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22",nocase; classtype:trojan-activity; sid:100005709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100005710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100005711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100005712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100005713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f8d2350982acb14f&resid=f8d2350982acb14f%21140&authkey=ajo86idqg2jvzfq",nocase; classtype:trojan-activity; sid:100005714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc",nocase; classtype:trojan-activity; sid:100005715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu",nocase; classtype:trojan-activity; sid:100005716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw",nocase; classtype:trojan-activity; sid:100005717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!196&authkey=amm2av5ubkbhoru",nocase; classtype:trojan-activity; sid:100005718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!197&authkey=apnt4trskzjga_k",nocase; classtype:trojan-activity; sid:100005719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21196&authkey=amm2av5ubkbhoru",nocase; classtype:trojan-activity; sid:100005720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21197&authkey=apnt4trskzjga_k",nocase; classtype:trojan-activity; sid:100005721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100005722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100005723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100005724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100005725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100005726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100005727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg",nocase; classtype:trojan-activity; sid:100005728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100005729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm",nocase; classtype:trojan-activity; sid:100005730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100005731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/yqvsvlvq",nocase; classtype:trojan-activity; sid:100005732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pierreconsulting.info",nocase; http_uri; content:"/wp-admin/llc/mwcacs65xienqdp/",nocase; classtype:trojan-activity; sid:100005733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pioneiraagronegocio.com.br",nocase; http_uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/",nocase; classtype:trojan-activity; sid:100005734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skoda22.jpg",nocase; classtype:trojan-activity; sid:100005735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg",nocase; classtype:trojan-activity; sid:100005736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qjbutterflyevents.co.za",nocase; http_uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/",nocase; classtype:trojan-activity; sid:100005737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/maersk-bl+draft-copy-shipping-documents.ace",nocase; classtype:trojan-activity; sid:100005738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace",nocase; classtype:trojan-activity; sid:100005739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/purchasing+ordersigned+contractinv-30067121.ace",nocase; classtype:trojan-activity; sid:100005740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll",nocase; classtype:trojan-activity; sid:100005741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe",nocase; classtype:trojan-activity; sid:100005742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe",nocase; classtype:trojan-activity; sid:100005743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe",nocase; classtype:trojan-activity; sid:100005744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe",nocase; classtype:trojan-activity; sid:100005745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar",nocase; classtype:trojan-activity; sid:100005746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/myqseeaccount/one/main/one.htm",nocase; classtype:trojan-activity; sid:100005747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp",nocase; classtype:trojan-activity; sid:100005748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe",nocase; classtype:trojan-activity; sid:100005749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe",nocase; classtype:trojan-activity; sid:100005750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/tennc/webshell/master/other/small_shell.txt",nocase; classtype:trojan-activity; sid:100005751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.yeshen.com",nocase; http_uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe",nocase; classtype:trojan-activity; sid:100005752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sendspace.com",nocase; http_uri; content:"/pro/dl/q05z91",nocase; classtype:trojan-activity; sid:100005753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sites.google.com",nocase; http_uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0",nocase; classtype:trojan-activity; sid:100005754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt",nocase; classtype:trojan-activity; sid:100005755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt",nocase; classtype:trojan-activity; sid:100005756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt",nocase; classtype:trojan-activity; sid:100005757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt",nocase; classtype:trojan-activity; sid:100005758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt",nocase; classtype:trojan-activity; sid:100005759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt",nocase; classtype:trojan-activity; sid:100005760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt",nocase; classtype:trojan-activity; sid:100005761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg",nocase; classtype:trojan-activity; sid:100005762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt",nocase; classtype:trojan-activity; sid:100005763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt",nocase; classtype:trojan-activity; sid:100005764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technologydistilled.com",nocase; http_uri; content:"/a-nurse-ss8d9/z/",nocase; classtype:trojan-activity; sid:100005765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"truemerit.io",nocase; http_uri; content:"/databases/merit.php",nocase; classtype:trojan-activity; sid:100005766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsrv4.ws",nocase; http_uri; content:"/23.exe",nocase; classtype:trojan-activity; sid:100005767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"users.skynet.be",nocase; http_uri; content:"/crisanar/defis/jek_crackme1.7.zip",nocase; classtype:trojan-activity; sid:100005768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/amowvegfrt9ja/",nocase; classtype:trojan-activity; sid:100005769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/",nocase; classtype:trojan-activity; sid:100005770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100005771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100005772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe",nocase; classtype:trojan-activity; sid:100005773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb%5efr_ouverture.exe",nocase; classtype:trojan-activity; sid:100005774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb^fr_ouverture.exe",nocase; classtype:trojan-activity; sid:100005775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe",nocase; classtype:trojan-activity; sid:100005776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/151_155/tidex_-_short_stuff.exe",nocase; classtype:trojan-activity; sid:100005777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikileaks.org",nocase; http_uri; content:"/syria-files/attach/222/222051_instruction.zip",nocase; classtype:trojan-activity; sid:100005778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.46.55",nocase; classtype:trojan-activity; sid:100003207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.48.162",nocase; classtype:trojan-activity; sid:100003208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.231.95.247",nocase; classtype:trojan-activity; sid:100003209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.232.102.163",nocase; classtype:trojan-activity; sid:100003210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.232.46.169",nocase; classtype:trojan-activity; sid:100003211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.233.159.21",nocase; classtype:trojan-activity; sid:100003212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.233.78.236",nocase; classtype:trojan-activity; sid:100003213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.234.247.41",nocase; classtype:trojan-activity; sid:100003214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.234.85.184",nocase; classtype:trojan-activity; sid:100003215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.23.163",nocase; classtype:trojan-activity; sid:100003216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.67.162",nocase; classtype:trojan-activity; sid:100003217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.82.112",nocase; classtype:trojan-activity; sid:100003218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.87.100",nocase; classtype:trojan-activity; sid:100003219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.90.32",nocase; classtype:trojan-activity; sid:100003220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.95.254",nocase; classtype:trojan-activity; sid:100003221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.148.201",nocase; classtype:trojan-activity; sid:100003222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.237.142.157",nocase; classtype:trojan-activity; sid:100003223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.237.24.151",nocase; classtype:trojan-activity; sid:100003224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.237.252.159",nocase; classtype:trojan-activity; sid:100003225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.237.60.73",nocase; classtype:trojan-activity; sid:100003226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.238.228.0",nocase; classtype:trojan-activity; sid:100003227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.155.147",nocase; classtype:trojan-activity; sid:100003228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.202.121",nocase; classtype:trojan-activity; sid:100003229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.21.27",nocase; classtype:trojan-activity; sid:100003230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.218.137",nocase; classtype:trojan-activity; sid:100003231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.98.70",nocase; classtype:trojan-activity; sid:100003232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.242.200.90",nocase; classtype:trojan-activity; sid:100003233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.56.15.227",nocase; classtype:trojan-activity; sid:100003234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.61.99.155",nocase; classtype:trojan-activity; sid:100003235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.84.37.198",nocase; classtype:trojan-activity; sid:100003236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.87.29.162",nocase; classtype:trojan-activity; sid:100003237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.230.156.44",nocase; classtype:trojan-activity; sid:100003238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.241.106.183",nocase; classtype:trojan-activity; sid:100003239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.252.8.94",nocase; classtype:trojan-activity; sid:100003240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.137",nocase; classtype:trojan-activity; sid:100003241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.139",nocase; classtype:trojan-activity; sid:100003242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.242",nocase; classtype:trojan-activity; sid:100003243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.203.192",nocase; classtype:trojan-activity; sid:100003244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.135.134.228",nocase; classtype:trojan-activity; sid:100003245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.182",nocase; classtype:trojan-activity; sid:100003246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.204",nocase; classtype:trojan-activity; sid:100003247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.244",nocase; classtype:trojan-activity; sid:100003248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.66",nocase; classtype:trojan-activity; sid:100003249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.141.84.184",nocase; classtype:trojan-activity; sid:100003250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.142",nocase; classtype:trojan-activity; sid:100003251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.65",nocase; classtype:trojan-activity; sid:100003252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.47",nocase; classtype:trojan-activity; sid:100003253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.94",nocase; classtype:trojan-activity; sid:100003254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.165.215.19",nocase; classtype:trojan-activity; sid:100003255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.116",nocase; classtype:trojan-activity; sid:100003256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.164",nocase; classtype:trojan-activity; sid:100003257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.22",nocase; classtype:trojan-activity; sid:100003258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.248",nocase; classtype:trojan-activity; sid:100003259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.110.99",nocase; classtype:trojan-activity; sid:100003260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.119",nocase; classtype:trojan-activity; sid:100003261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.154",nocase; classtype:trojan-activity; sid:100003262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.16",nocase; classtype:trojan-activity; sid:100003263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.202",nocase; classtype:trojan-activity; sid:100003264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.84",nocase; classtype:trojan-activity; sid:100003265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.178.101.22",nocase; classtype:trojan-activity; sid:100003266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.179.171.252",nocase; classtype:trojan-activity; sid:100003267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.22.209.58",nocase; classtype:trojan-activity; sid:100003268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.23.22.186",nocase; classtype:trojan-activity; sid:100003269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.231.210.27",nocase; classtype:trojan-activity; sid:100003270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.27.253.137",nocase; classtype:trojan-activity; sid:100003271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.33.112.19",nocase; classtype:trojan-activity; sid:100003272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.51.104.59",nocase; classtype:trojan-activity; sid:100003273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.81.235.31",nocase; classtype:trojan-activity; sid:100003274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.9.148.37",nocase; classtype:trojan-activity; sid:100003275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.151.155.218",nocase; classtype:trojan-activity; sid:100003276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.161.185.15",nocase; classtype:trojan-activity; sid:100003277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.172.75.231",nocase; classtype:trojan-activity; sid:100003278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.175.184.121",nocase; classtype:trojan-activity; sid:100003279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.182.173.246",nocase; classtype:trojan-activity; sid:100003280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.20.63.218",nocase; classtype:trojan-activity; sid:100003281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.21.153.231",nocase; classtype:trojan-activity; sid:100003282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.214.27.4",nocase; classtype:trojan-activity; sid:100003283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.24.130.254",nocase; classtype:trojan-activity; sid:100003284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.243.179.115",nocase; classtype:trojan-activity; sid:100003285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.249.33.79",nocase; classtype:trojan-activity; sid:100003286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.25.242.211",nocase; classtype:trojan-activity; sid:100003287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.118.86",nocase; classtype:trojan-activity; sid:100003288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.86.128",nocase; classtype:trojan-activity; sid:100003289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.97.76.242",nocase; classtype:trojan-activity; sid:100003290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.145.152.26",nocase; classtype:trojan-activity; sid:100003291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.151.23.172",nocase; classtype:trojan-activity; sid:100003292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.157.97.71",nocase; classtype:trojan-activity; sid:100003293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.16.131.51",nocase; classtype:trojan-activity; sid:100003294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.197.0.119",nocase; classtype:trojan-activity; sid:100003295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.21.202.98",nocase; classtype:trojan-activity; sid:100003296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.46.231.38",nocase; classtype:trojan-activity; sid:100003297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.162.113",nocase; classtype:trojan-activity; sid:100003298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.87.36",nocase; classtype:trojan-activity; sid:100003299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.143.32.36",nocase; classtype:trojan-activity; sid:100003300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.143.43.93",nocase; classtype:trojan-activity; sid:100003301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.158.201.200",nocase; classtype:trojan-activity; sid:100003302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.20.121",nocase; classtype:trojan-activity; sid:100003303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.21.3",nocase; classtype:trojan-activity; sid:100003304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.174.182.99",nocase; classtype:trojan-activity; sid:100003305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.170.49",nocase; classtype:trojan-activity; sid:100003306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.178.183",nocase; classtype:trojan-activity; sid:100003307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.179.129",nocase; classtype:trojan-activity; sid:100003308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.68.221.252",nocase; classtype:trojan-activity; sid:100003309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.68.249.121",nocase; classtype:trojan-activity; sid:100003310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.70.15.16",nocase; classtype:trojan-activity; sid:100003311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.70.95.181",nocase; classtype:trojan-activity; sid:100003312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.146.202.18",nocase; classtype:trojan-activity; sid:100003313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.181.135.114",nocase; classtype:trojan-activity; sid:100003314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.2.70.50",nocase; classtype:trojan-activity; sid:100003315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.42.37.74",nocase; classtype:trojan-activity; sid:100003316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.53.146.179",nocase; classtype:trojan-activity; sid:100003317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.8.10.62",nocase; classtype:trojan-activity; sid:100003318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.102",nocase; classtype:trojan-activity; sid:100003319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.121.91.255",nocase; classtype:trojan-activity; sid:100003320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.252.47.29",nocase; classtype:trojan-activity; sid:100003321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"51.171.146.13",nocase; classtype:trojan-activity; sid:100003322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"51.222.56.159",nocase; classtype:trojan-activity; sid:100003323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.114.136",nocase; classtype:trojan-activity; sid:100003324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.180.122",nocase; classtype:trojan-activity; sid:100003325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.114.246.26",nocase; classtype:trojan-activity; sid:100003326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.108.164",nocase; classtype:trojan-activity; sid:100003327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.162.92",nocase; classtype:trojan-activity; sid:100003328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.174.4",nocase; classtype:trojan-activity; sid:100003329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.125.191.4",nocase; classtype:trojan-activity; sid:100003330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.126.247.118",nocase; classtype:trojan-activity; sid:100003331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.141.122.109",nocase; classtype:trojan-activity; sid:100003332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.166.120",nocase; classtype:trojan-activity; sid:100003333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.200.124",nocase; classtype:trojan-activity; sid:100003334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.143.142.142",nocase; classtype:trojan-activity; sid:100003335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.143.189.75",nocase; classtype:trojan-activity; sid:100003336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.18.103.109",nocase; classtype:trojan-activity; sid:100003337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.19.249.50",nocase; classtype:trojan-activity; sid:100003338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.218.67.253",nocase; classtype:trojan-activity; sid:100003339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.22.212.107",nocase; classtype:trojan-activity; sid:100003340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.226.129.29",nocase; classtype:trojan-activity; sid:100003341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.23.245.24",nocase; classtype:trojan-activity; sid:100003342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.230.89.42",nocase; classtype:trojan-activity; sid:100003343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.238.42.192",nocase; classtype:trojan-activity; sid:100003344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.240.147.97",nocase; classtype:trojan-activity; sid:100003345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.57.237",nocase; classtype:trojan-activity; sid:100003346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.78.55",nocase; classtype:trojan-activity; sid:100003347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.243.126.133",nocase; classtype:trojan-activity; sid:100003348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.112.254",nocase; classtype:trojan-activity; sid:100003349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.117.238",nocase; classtype:trojan-activity; sid:100003350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.142.5",nocase; classtype:trojan-activity; sid:100003351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.143.240",nocase; classtype:trojan-activity; sid:100003352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.144.229",nocase; classtype:trojan-activity; sid:100003353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.147.196",nocase; classtype:trojan-activity; sid:100003354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.151.33",nocase; classtype:trojan-activity; sid:100003355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.153.224",nocase; classtype:trojan-activity; sid:100003356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.74.240",nocase; classtype:trojan-activity; sid:100003357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.77.38",nocase; classtype:trojan-activity; sid:100003358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.12.80",nocase; classtype:trojan-activity; sid:100003359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.14.53",nocase; classtype:trojan-activity; sid:100003360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.16.173",nocase; classtype:trojan-activity; sid:100003361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.19.127",nocase; classtype:trojan-activity; sid:100003362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.72.88",nocase; classtype:trojan-activity; sid:100003363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.74.243",nocase; classtype:trojan-activity; sid:100003364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.74.245",nocase; classtype:trojan-activity; sid:100003365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.75.213",nocase; classtype:trojan-activity; sid:100003366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.77.88",nocase; classtype:trojan-activity; sid:100003367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.80.25",nocase; classtype:trojan-activity; sid:100003368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.82.35",nocase; classtype:trojan-activity; sid:100003369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.87.171",nocase; classtype:trojan-activity; sid:100003370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.89.158",nocase; classtype:trojan-activity; sid:100003371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.252.176.71",nocase; classtype:trojan-activity; sid:100003372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.255.133.161",nocase; classtype:trojan-activity; sid:100003373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.255.140.150",nocase; classtype:trojan-activity; sid:100003374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.48.154.143",nocase; classtype:trojan-activity; sid:100003375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.50.221.148",nocase; classtype:trojan-activity; sid:100003376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.153",nocase; classtype:trojan-activity; sid:100003377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.39",nocase; classtype:trojan-activity; sid:100003378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.76.151.189",nocase; classtype:trojan-activity; sid:100003379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.76.151.51",nocase; classtype:trojan-activity; sid:100003380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.97.206.33",nocase; classtype:trojan-activity; sid:100003381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.0.211.161",nocase; classtype:trojan-activity; sid:100003382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.102.168.189",nocase; classtype:trojan-activity; sid:100003383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.127.11.50",nocase; classtype:trojan-activity; sid:100003384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.202.3",nocase; classtype:trojan-activity; sid:100003385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.214.4",nocase; classtype:trojan-activity; sid:100003386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.246.125",nocase; classtype:trojan-activity; sid:100003387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.29.133.229",nocase; classtype:trojan-activity; sid:100003388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.45.235.176",nocase; classtype:trojan-activity; sid:100003389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.58.104.244",nocase; classtype:trojan-activity; sid:100003390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.58.117.226",nocase; classtype:trojan-activity; sid:100003391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.7.124.148",nocase; classtype:trojan-activity; sid:100003392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.8.35.22",nocase; classtype:trojan-activity; sid:100003393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.180.232",nocase; classtype:trojan-activity; sid:100003394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.217.35",nocase; classtype:trojan-activity; sid:100003395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.94.180.230",nocase; classtype:trojan-activity; sid:100003396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.96.37.181",nocase; classtype:trojan-activity; sid:100003397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.96.37.192",nocase; classtype:trojan-activity; sid:100003398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.96.39.222",nocase; classtype:trojan-activity; sid:100003399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.193.255",nocase; classtype:trojan-activity; sid:100003400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.13.61.12",nocase; classtype:trojan-activity; sid:100003401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.14.48.221",nocase; classtype:trojan-activity; sid:100003402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.16.247.78",nocase; classtype:trojan-activity; sid:100003403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.162.122.36",nocase; classtype:trojan-activity; sid:100003404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.164.130.220",nocase; classtype:trojan-activity; sid:100003405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.176.249.56",nocase; classtype:trojan-activity; sid:100003406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.184.149.169",nocase; classtype:trojan-activity; sid:100003407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.20.217.142",nocase; classtype:trojan-activity; sid:100003408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.208.135.42",nocase; classtype:trojan-activity; sid:100003409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.122.57",nocase; classtype:trojan-activity; sid:100003410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.186.185",nocase; classtype:trojan-activity; sid:100003411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.216.23",nocase; classtype:trojan-activity; sid:100003412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.233.94",nocase; classtype:trojan-activity; sid:100003413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.33.5",nocase; classtype:trojan-activity; sid:100003414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.19.63",nocase; classtype:trojan-activity; sid:100003415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.6.112",nocase; classtype:trojan-activity; sid:100003416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.100.83",nocase; classtype:trojan-activity; sid:100003417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.111.39",nocase; classtype:trojan-activity; sid:100003418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.162.152",nocase; classtype:trojan-activity; sid:100003419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.202.218",nocase; classtype:trojan-activity; sid:100003420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.206.246",nocase; classtype:trojan-activity; sid:100003421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.218.31",nocase; classtype:trojan-activity; sid:100003422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.220.167",nocase; classtype:trojan-activity; sid:100003423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.23.84",nocase; classtype:trojan-activity; sid:100003424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.254.178",nocase; classtype:trojan-activity; sid:100003425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.162.59",nocase; classtype:trojan-activity; sid:100003426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.58.188",nocase; classtype:trojan-activity; sid:100003427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.83.55",nocase; classtype:trojan-activity; sid:100003428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.214.217.96",nocase; classtype:trojan-activity; sid:100003429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.214.32.17",nocase; classtype:trojan-activity; sid:100003430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.214.73.6",nocase; classtype:trojan-activity; sid:100003431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.214.93.166",nocase; classtype:trojan-activity; sid:100003432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.165.64",nocase; classtype:trojan-activity; sid:100003433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.195.111",nocase; classtype:trojan-activity; sid:100003434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.207.11",nocase; classtype:trojan-activity; sid:100003435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.4.239",nocase; classtype:trojan-activity; sid:100003436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.177.196",nocase; classtype:trojan-activity; sid:100003437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.86.208",nocase; classtype:trojan-activity; sid:100003438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.223.84.102",nocase; classtype:trojan-activity; sid:100003439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.25.109.240",nocase; classtype:trojan-activity; sid:100003440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.25.115.48",nocase; classtype:trojan-activity; sid:100003441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.25.76.224",nocase; classtype:trojan-activity; sid:100003442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.15.104",nocase; classtype:trojan-activity; sid:100003443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.4.72",nocase; classtype:trojan-activity; sid:100003444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.42.72",nocase; classtype:trojan-activity; sid:100003445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.51.127",nocase; classtype:trojan-activity; sid:100003446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.26.17.221",nocase; classtype:trojan-activity; sid:100003447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.10.121",nocase; classtype:trojan-activity; sid:100003448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.8.43",nocase; classtype:trojan-activity; sid:100003449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.99.254",nocase; classtype:trojan-activity; sid:100003450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.102.243.124",nocase; classtype:trojan-activity; sid:100003451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.130.195.121",nocase; classtype:trojan-activity; sid:100003452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.162.169.210",nocase; classtype:trojan-activity; sid:100003453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.162.55.42",nocase; classtype:trojan-activity; sid:100003454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.163.142.96",nocase; classtype:trojan-activity; sid:100003455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.164.96.98",nocase; classtype:trojan-activity; sid:100003456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.171.60",nocase; classtype:trojan-activity; sid:100003457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.194",nocase; classtype:trojan-activity; sid:100003458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.230",nocase; classtype:trojan-activity; sid:100003459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.192.73.253",nocase; classtype:trojan-activity; sid:100003460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.213.118.28",nocase; classtype:trojan-activity; sid:100003461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.247.224.66",nocase; classtype:trojan-activity; sid:100003462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.253.94.230",nocase; classtype:trojan-activity; sid:100003463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.124.125",nocase; classtype:trojan-activity; sid:100003464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.151.60",nocase; classtype:trojan-activity; sid:100003465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.47.220.169",nocase; classtype:trojan-activity; sid:100003466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.103.144",nocase; classtype:trojan-activity; sid:100003467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.103.217",nocase; classtype:trojan-activity; sid:100003468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.109.9",nocase; classtype:trojan-activity; sid:100003469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.11.87",nocase; classtype:trojan-activity; sid:100003470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.159.231",nocase; classtype:trojan-activity; sid:100003471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.167.66",nocase; classtype:trojan-activity; sid:100003472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.195.226",nocase; classtype:trojan-activity; sid:100003473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.210.53",nocase; classtype:trojan-activity; sid:100003474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.211.61",nocase; classtype:trojan-activity; sid:100003475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.212.191",nocase; classtype:trojan-activity; sid:100003476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.214.11",nocase; classtype:trojan-activity; sid:100003477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.234.193",nocase; classtype:trojan-activity; sid:100003478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.237.212",nocase; classtype:trojan-activity; sid:100003479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.242.56",nocase; classtype:trojan-activity; sid:100003480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.30.172",nocase; classtype:trojan-activity; sid:100003481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.4.214",nocase; classtype:trojan-activity; sid:100003482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.42.174",nocase; classtype:trojan-activity; sid:100003483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.48.40",nocase; classtype:trojan-activity; sid:100003484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.76.72",nocase; classtype:trojan-activity; sid:100003485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.9.166",nocase; classtype:trojan-activity; sid:100003486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.9.62",nocase; classtype:trojan-activity; sid:100003487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.98.22",nocase; classtype:trojan-activity; sid:100003488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.99.161",nocase; classtype:trojan-activity; sid:100003489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.102.137",nocase; classtype:trojan-activity; sid:100003490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.117.115",nocase; classtype:trojan-activity; sid:100003491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.119.161",nocase; classtype:trojan-activity; sid:100003492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.122.161",nocase; classtype:trojan-activity; sid:100003493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.123.162",nocase; classtype:trojan-activity; sid:100003494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.192.49",nocase; classtype:trojan-activity; sid:100003495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.201.162",nocase; classtype:trojan-activity; sid:100003496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.103.56",nocase; classtype:trojan-activity; sid:100003497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.168.35",nocase; classtype:trojan-activity; sid:100003498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.232.45",nocase; classtype:trojan-activity; sid:100003499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.40.202",nocase; classtype:trojan-activity; sid:100003500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.58.20",nocase; classtype:trojan-activity; sid:100003501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.64.104",nocase; classtype:trojan-activity; sid:100003502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.180.67",nocase; classtype:trojan-activity; sid:100003503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.181.7",nocase; classtype:trojan-activity; sid:100003504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.57.96.116",nocase; classtype:trojan-activity; sid:100003505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.170.60",nocase; classtype:trojan-activity; sid:100003506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.73.220",nocase; classtype:trojan-activity; sid:100003507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.61.218.23",nocase; classtype:trojan-activity; sid:100003508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.65.172.121",nocase; classtype:trojan-activity; sid:100003509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.0.22",nocase; classtype:trojan-activity; sid:100003510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.104.46",nocase; classtype:trojan-activity; sid:100003511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.110.59",nocase; classtype:trojan-activity; sid:100003512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.195",nocase; classtype:trojan-activity; sid:100003513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.86",nocase; classtype:trojan-activity; sid:100003514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.255.60",nocase; classtype:trojan-activity; sid:100003515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.45.130",nocase; classtype:trojan-activity; sid:100003516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.98.144.75",nocase; classtype:trojan-activity; sid:100003517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.1.98.131",nocase; classtype:trojan-activity; sid:100003518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.117.124.114",nocase; classtype:trojan-activity; sid:100003519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.141.73.58",nocase; classtype:trojan-activity; sid:100003520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.131.205",nocase; classtype:trojan-activity; sid:100003521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.143.46",nocase; classtype:trojan-activity; sid:100003522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.155.61",nocase; classtype:trojan-activity; sid:100003523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.227.31",nocase; classtype:trojan-activity; sid:100003524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.31.126.33",nocase; classtype:trojan-activity; sid:100003525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.149.66",nocase; classtype:trojan-activity; sid:100003526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.222.98",nocase; classtype:trojan-activity; sid:100003527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.43.207.148",nocase; classtype:trojan-activity; sid:100003528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.90.165.236",nocase; classtype:trojan-activity; sid:100003529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"63.245.122.93",nocase; classtype:trojan-activity; sid:100003530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"64.233.154.99",nocase; classtype:trojan-activity; sid:100003531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.125.128.196",nocase; classtype:trojan-activity; sid:100003532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.21.58.252",nocase; classtype:trojan-activity; sid:100003533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.26.155.131",nocase; classtype:trojan-activity; sid:100003534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.35.61.255",nocase; classtype:trojan-activity; sid:100003535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.153.233.87",nocase; classtype:trojan-activity; sid:100003536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.229.214.115",nocase; classtype:trojan-activity; sid:100003537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.57.55.210",nocase; classtype:trojan-activity; sid:100003538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.74.7.197",nocase; classtype:trojan-activity; sid:100003539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.91.21.31",nocase; classtype:trojan-activity; sid:100003540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.196",nocase; classtype:trojan-activity; sid:100003541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.213",nocase; classtype:trojan-activity; sid:100003542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.245.151.203",nocase; classtype:trojan-activity; sid:100003543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.3.169.223",nocase; classtype:trojan-activity; sid:100003544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.8.138.101",nocase; classtype:trojan-activity; sid:100003545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.81.98.111",nocase; classtype:trojan-activity; sid:100003546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.83.49.234",nocase; classtype:trojan-activity; sid:100003547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.84.138.165",nocase; classtype:trojan-activity; sid:100003548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.151.244.128",nocase; classtype:trojan-activity; sid:100003549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.174.182.226",nocase; classtype:trojan-activity; sid:100003550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.175.107.153",nocase; classtype:trojan-activity; sid:100003551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.183.25.71",nocase; classtype:trojan-activity; sid:100003552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.188.144.143",nocase; classtype:trojan-activity; sid:100003553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.204.88.29",nocase; classtype:trojan-activity; sid:100003554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.106.84",nocase; classtype:trojan-activity; sid:100003555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.119.241",nocase; classtype:trojan-activity; sid:100003556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.78.33.33",nocase; classtype:trojan-activity; sid:100003557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68468438438.xyz",nocase; classtype:trojan-activity; sid:100003558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.115.37.205",nocase; classtype:trojan-activity; sid:100003559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.120.237.255",nocase; classtype:trojan-activity; sid:100003560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.123.245.151",nocase; classtype:trojan-activity; sid:100003561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.124.231.110",nocase; classtype:trojan-activity; sid:100003562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.127.214.47",nocase; classtype:trojan-activity; sid:100003563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.146.232.34",nocase; classtype:trojan-activity; sid:100003564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.165.173.49",nocase; classtype:trojan-activity; sid:100003565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.196.158.227",nocase; classtype:trojan-activity; sid:100003566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.222.157.166",nocase; classtype:trojan-activity; sid:100003567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.229.0.133",nocase; classtype:trojan-activity; sid:100003568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.63.73.234",nocase; classtype:trojan-activity; sid:100003569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.115.194",nocase; classtype:trojan-activity; sid:100003570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.227.186",nocase; classtype:trojan-activity; sid:100003571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.76.240.206",nocase; classtype:trojan-activity; sid:100003572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.115.31.30",nocase; classtype:trojan-activity; sid:100003573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.118.240.88",nocase; classtype:trojan-activity; sid:100003574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.167.10.180",nocase; classtype:trojan-activity; sid:100003575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.236.190.250",nocase; classtype:trojan-activity; sid:100003576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.25.5.105",nocase; classtype:trojan-activity; sid:100003577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.93.129.118",nocase; classtype:trojan-activity; sid:100003578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.127.148.69",nocase; classtype:trojan-activity; sid:100003579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.146.190.91",nocase; classtype:trojan-activity; sid:100003580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.167.164.113",nocase; classtype:trojan-activity; sid:100003581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.204.63.239",nocase; classtype:trojan-activity; sid:100003582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.29.48.164",nocase; classtype:trojan-activity; sid:100003583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.34.191.213",nocase; classtype:trojan-activity; sid:100003584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.40.234.166",nocase; classtype:trojan-activity; sid:100003585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.106.142",nocase; classtype:trojan-activity; sid:100003586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.2.122",nocase; classtype:trojan-activity; sid:100003587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.235.106",nocase; classtype:trojan-activity; sid:100003588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.47.133.58",nocase; classtype:trojan-activity; sid:100003589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.71.60.69",nocase; classtype:trojan-activity; sid:100003590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.85.106.211",nocase; classtype:trojan-activity; sid:100003591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.17.22.30",nocase; classtype:trojan-activity; sid:100003592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.186.139.38",nocase; classtype:trojan-activity; sid:100003593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.180.98",nocase; classtype:trojan-activity; sid:100003594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.200.62",nocase; classtype:trojan-activity; sid:100003595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.214.69.226",nocase; classtype:trojan-activity; sid:100003596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.230.118",nocase; classtype:trojan-activity; sid:100003597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.35.40",nocase; classtype:trojan-activity; sid:100003598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.31.40.122",nocase; classtype:trojan-activity; sid:100003599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.204.216.103",nocase; classtype:trojan-activity; sid:100003600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.101.1.159",nocase; classtype:trojan-activity; sid:100003601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.108.224.112",nocase; classtype:trojan-activity; sid:100003602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.116.216.141",nocase; classtype:trojan-activity; sid:100003603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.194.117.165",nocase; classtype:trojan-activity; sid:100003604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.195.115.176",nocase; classtype:trojan-activity; sid:100003605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.199.84.77",nocase; classtype:trojan-activity; sid:100003606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.64.139.223",nocase; classtype:trojan-activity; sid:100003607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.75.165.81",nocase; classtype:trojan-activity; sid:100003608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.127.141.52",nocase; classtype:trojan-activity; sid:100003609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.83.102.27",nocase; classtype:trojan-activity; sid:100003610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.99.213.61",nocase; classtype:trojan-activity; sid:100003611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.108.199.153",nocase; classtype:trojan-activity; sid:100003612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.170.11.82",nocase; classtype:trojan-activity; sid:100003613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.178.22.145",nocase; classtype:trojan-activity; sid:100003614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.250.199.133",nocase; classtype:trojan-activity; sid:100003615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.254.129.227",nocase; classtype:trojan-activity; sid:100003616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.84.134.33",nocase; classtype:trojan-activity; sid:100003617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.95.12.137",nocase; classtype:trojan-activity; sid:100003618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.237.25.210",nocase; classtype:trojan-activity; sid:100003619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.50.153",nocase; classtype:trojan-activity; sid:100003620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.52.220",nocase; classtype:trojan-activity; sid:100003621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.79.191.32",nocase; classtype:trojan-activity; sid:100003622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.89.203.238",nocase; classtype:trojan-activity; sid:100003623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.94.89.20",nocase; classtype:trojan-activity; sid:100003624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.186.155.18",nocase; classtype:trojan-activity; sid:100003625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.141.144",nocase; classtype:trojan-activity; sid:100003626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.240.125",nocase; classtype:trojan-activity; sid:100003627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.41.200",nocase; classtype:trojan-activity; sid:100003628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.168.64",nocase; classtype:trojan-activity; sid:100003629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.188.141",nocase; classtype:trojan-activity; sid:100003630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.104.157",nocase; classtype:trojan-activity; sid:100003631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.176.163",nocase; classtype:trojan-activity; sid:100003632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.23.172.81",nocase; classtype:trojan-activity; sid:100003633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.8.225.77",nocase; classtype:trojan-activity; sid:100003634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.11.195.121",nocase; classtype:trojan-activity; sid:100003635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.13.49.221",nocase; classtype:trojan-activity; sid:100003636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.130.253.13",nocase; classtype:trojan-activity; sid:100003637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.147.123.48",nocase; classtype:trojan-activity; sid:100003638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.170.31.56",nocase; classtype:trojan-activity; sid:100003639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.175.42.244",nocase; classtype:trojan-activity; sid:100003640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.21.84.63",nocase; classtype:trojan-activity; sid:100003641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.7.170.58",nocase; classtype:trojan-activity; sid:100003642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.79.58.94",nocase; classtype:trojan-activity; sid:100003643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.8.70.162",nocase; classtype:trojan-activity; sid:100003644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.9.88.185",nocase; classtype:trojan-activity; sid:100003645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.107.89.207",nocase; classtype:trojan-activity; sid:100003646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.19.101.218",nocase; classtype:trojan-activity; sid:100003647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.211.181.77",nocase; classtype:trojan-activity; sid:100003648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.217.12.7",nocase; classtype:trojan-activity; sid:100003649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.67.32.66",nocase; classtype:trojan-activity; sid:100003650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.99.128.61",nocase; classtype:trojan-activity; sid:100003651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.136.146.213",nocase; classtype:trojan-activity; sid:100003652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.165.44.109",nocase; classtype:trojan-activity; sid:100003653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.191.40.58",nocase; classtype:trojan-activity; sid:100003654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.111.60",nocase; classtype:trojan-activity; sid:100003655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.141.184",nocase; classtype:trojan-activity; sid:100003656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.215.199.29",nocase; classtype:trojan-activity; sid:100003657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.187.113",nocase; classtype:trojan-activity; sid:100003658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.195.216",nocase; classtype:trojan-activity; sid:100003659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.237.128.200",nocase; classtype:trojan-activity; sid:100003660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.246.225.203",nocase; classtype:trojan-activity; sid:100003661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.92.36.96",nocase; classtype:trojan-activity; sid:100003662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.103.108.72",nocase; classtype:trojan-activity; sid:100003663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.135.196.130",nocase; classtype:trojan-activity; sid:100003664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.212.178",nocase; classtype:trojan-activity; sid:100003665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.85.112",nocase; classtype:trojan-activity; sid:100003666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.207.61.194",nocase; classtype:trojan-activity; sid:100003667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.209.250.155",nocase; classtype:trojan-activity; sid:100003668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.211.156.38",nocase; classtype:trojan-activity; sid:100003669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.110.252",nocase; classtype:trojan-activity; sid:100003670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.53.77",nocase; classtype:trojan-activity; sid:100003671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.138.72",nocase; classtype:trojan-activity; sid:100003672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.139.92",nocase; classtype:trojan-activity; sid:100003673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.154.214",nocase; classtype:trojan-activity; sid:100003674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.187.109",nocase; classtype:trojan-activity; sid:100003675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.100.54",nocase; classtype:trojan-activity; sid:100003676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.108.172",nocase; classtype:trojan-activity; sid:100003677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.131.158",nocase; classtype:trojan-activity; sid:100003678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.19.42",nocase; classtype:trojan-activity; sid:100003679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.197.254",nocase; classtype:trojan-activity; sid:100003680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.215.149",nocase; classtype:trojan-activity; sid:100003681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.232.68",nocase; classtype:trojan-activity; sid:100003682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.234.195",nocase; classtype:trojan-activity; sid:100003683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.246.96",nocase; classtype:trojan-activity; sid:100003684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.28.57",nocase; classtype:trojan-activity; sid:100003685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.4.57",nocase; classtype:trojan-activity; sid:100003686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.55.84",nocase; classtype:trojan-activity; sid:100003687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.73.245",nocase; classtype:trojan-activity; sid:100003688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.9.62",nocase; classtype:trojan-activity; sid:100003689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.98.51",nocase; classtype:trojan-activity; sid:100003690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.165.237.163",nocase; classtype:trojan-activity; sid:100003691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.147.99",nocase; classtype:trojan-activity; sid:100003692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.218.42",nocase; classtype:trojan-activity; sid:100003693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.242.253.154",nocase; classtype:trojan-activity; sid:100003694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.252.9.37",nocase; classtype:trojan-activity; sid:100003695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.208",nocase; classtype:trojan-activity; sid:100003696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.213",nocase; classtype:trojan-activity; sid:100003697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.212.219.127",nocase; classtype:trojan-activity; sid:100003698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.50.118",nocase; classtype:trojan-activity; sid:100003699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.95.204",nocase; classtype:trojan-activity; sid:100003700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.238.24.35",nocase; classtype:trojan-activity; sid:100003701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.247.83.74",nocase; classtype:trojan-activity; sid:100003702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.254.39.129",nocase; classtype:trojan-activity; sid:100003703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.33.111.227",nocase; classtype:trojan-activity; sid:100003704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.40.127.242",nocase; classtype:trojan-activity; sid:100003705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.42.20.217",nocase; classtype:trojan-activity; sid:100003706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com",nocase; classtype:trojan-activity; sid:100003707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.11.216",nocase; classtype:trojan-activity; sid:100003708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.123.251",nocase; classtype:trojan-activity; sid:100003709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.135.187",nocase; classtype:trojan-activity; sid:100003710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.208.25",nocase; classtype:trojan-activity; sid:100003711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.224.141",nocase; classtype:trojan-activity; sid:100003712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.241.2",nocase; classtype:trojan-activity; sid:100003713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.214.149.236",nocase; classtype:trojan-activity; sid:100003714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.64.181.50",nocase; classtype:trojan-activity; sid:100003715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.74.215.180",nocase; classtype:trojan-activity; sid:100003716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.130.227",nocase; classtype:trojan-activity; sid:100003717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.195.129",nocase; classtype:trojan-activity; sid:100003718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"86.35.43.220",nocase; classtype:trojan-activity; sid:100003719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.61.89.40",nocase; classtype:trojan-activity; sid:100003720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87du.vip",nocase; classtype:trojan-activity; sid:100003721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.119.171.253",nocase; classtype:trojan-activity; sid:100003722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.208.71",nocase; classtype:trojan-activity; sid:100003723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.219.179",nocase; classtype:trojan-activity; sid:100003724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.225.222.128",nocase; classtype:trojan-activity; sid:100003725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.247.96.19",nocase; classtype:trojan-activity; sid:100003726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.136.231",nocase; classtype:trojan-activity; sid:100003727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.51.139",nocase; classtype:trojan-activity; sid:100003728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.249.244.180",nocase; classtype:trojan-activity; sid:100003729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.204.12",nocase; classtype:trojan-activity; sid:100003730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.226.26",nocase; classtype:trojan-activity; sid:100003731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.254.90",nocase; classtype:trojan-activity; sid:100003732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.122.183.130",nocase; classtype:trojan-activity; sid:100003733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.29.213.33",nocase; classtype:trojan-activity; sid:100003734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.35.62.96",nocase; classtype:trojan-activity; sid:100003735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.85.166",nocase; classtype:trojan-activity; sid:100003736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.87.5",nocase; classtype:trojan-activity; sid:100003737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.46.237.89",nocase; classtype:trojan-activity; sid:100003738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8poieq.bn.files.1drv.com",nocase; classtype:trojan-activity; sid:100003739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"90.152.144.139",nocase; classtype:trojan-activity; sid:100003740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"90.63.176.144",nocase; classtype:trojan-activity; sid:100003741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.177.139.132",nocase; classtype:trojan-activity; sid:100003742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.187.103.32",nocase; classtype:trojan-activity; sid:100003743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.212.150.241",nocase; classtype:trojan-activity; sid:100003744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.217.104.185",nocase; classtype:trojan-activity; sid:100003745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.233.112.188",nocase; classtype:trojan-activity; sid:100003746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.234.60.94",nocase; classtype:trojan-activity; sid:100003747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.239.168.83",nocase; classtype:trojan-activity; sid:100003748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.244.169.139",nocase; classtype:trojan-activity; sid:100003749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.92.16.244",nocase; classtype:trojan-activity; sid:100003750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.98.4.181",nocase; classtype:trojan-activity; sid:100003751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.113.93.34",nocase; classtype:trojan-activity; sid:100003752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.114.191.82",nocase; classtype:trojan-activity; sid:100003753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.241.78.114",nocase; classtype:trojan-activity; sid:100003754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.27.246.202",nocase; classtype:trojan-activity; sid:100003755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.54.237.237",nocase; classtype:trojan-activity; sid:100003756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.83.62.139",nocase; classtype:trojan-activity; sid:100003757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.85.18.138",nocase; classtype:trojan-activity; sid:100003758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.171.157.73",nocase; classtype:trojan-activity; sid:100003759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.21.224.154",nocase; classtype:trojan-activity; sid:100003760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.115.176",nocase; classtype:trojan-activity; sid:100003761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.137.16",nocase; classtype:trojan-activity; sid:100003762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.182.249",nocase; classtype:trojan-activity; sid:100003763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.206.56",nocase; classtype:trojan-activity; sid:100003764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.57.43.233",nocase; classtype:trojan-activity; sid:100003765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.73.99.102",nocase; classtype:trojan-activity; sid:100003766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.136.69.199",nocase; classtype:trojan-activity; sid:100003767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.143.53.34",nocase; classtype:trojan-activity; sid:100003768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.17.170",nocase; classtype:trojan-activity; sid:100003769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.82.190",nocase; classtype:trojan-activity; sid:100003770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.200.16.22",nocase; classtype:trojan-activity; sid:100003771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.224.83.208",nocase; classtype:trojan-activity; sid:100003772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.53.120.109",nocase; classtype:trojan-activity; sid:100003773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.132.129.250",nocase; classtype:trojan-activity; sid:100003774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.153.241.63",nocase; classtype:trojan-activity; sid:100003775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.154.20.231",nocase; classtype:trojan-activity; sid:100003776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.158.19.130",nocase; classtype:trojan-activity; sid:100003777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.113.227",nocase; classtype:trojan-activity; sid:100003778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.113.52",nocase; classtype:trojan-activity; sid:100003779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.201.34",nocase; classtype:trojan-activity; sid:100003780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.181.155.112",nocase; classtype:trojan-activity; sid:100003781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.146.134",nocase; classtype:trojan-activity; sid:100003782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.6.114",nocase; classtype:trojan-activity; sid:100003783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.66.196.63",nocase; classtype:trojan-activity; sid:100003784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.9.120.40",nocase; classtype:trojan-activity; sid:100003785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.239.73.246",nocase; classtype:trojan-activity; sid:100003786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.47.147.169",nocase; classtype:trojan-activity; sid:100003787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.68.140.254",nocase; classtype:trojan-activity; sid:100003788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.96.199.75",nocase; classtype:trojan-activity; sid:100003789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.210.218",nocase; classtype:trojan-activity; sid:100003790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.239.142",nocase; classtype:trojan-activity; sid:100003791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.113.239.207",nocase; classtype:trojan-activity; sid:100003792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.116.72.119",nocase; classtype:trojan-activity; sid:100003793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.128.147.115",nocase; classtype:trojan-activity; sid:100003794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.178.242.44",nocase; classtype:trojan-activity; sid:100003795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.249.236.11",nocase; classtype:trojan-activity; sid:100003796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.28.200.139",nocase; classtype:trojan-activity; sid:100003797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.30.24.54",nocase; classtype:trojan-activity; sid:100003798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.150.245.203",nocase; classtype:trojan-activity; sid:100003799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.33.195.164",nocase; classtype:trojan-activity; sid:100003800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abcd.bg",nocase; classtype:trojan-activity; sid:100003801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abclicks.in",nocase; classtype:trojan-activity; sid:100003802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abissnet.net",nocase; classtype:trojan-activity; sid:100003803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aboveandbelow.com.au",nocase; classtype:trojan-activity; sid:100003804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absoftechworld.com",nocase; classtype:trojan-activity; sid:100003805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absupplies.co.uk",nocase; classtype:trojan-activity; sid:100003806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abyssos.eu",nocase; classtype:trojan-activity; sid:100003807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"academyshademani.com",nocase; classtype:trojan-activity; sid:100003808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acbick.com",nocase; classtype:trojan-activity; sid:100003809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"accounts.thesmarttechhub.com",nocase; classtype:trojan-activity; sid:100003810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aceeprc.com.aceeprc.com",nocase; classtype:trojan-activity; sid:100003811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acellr.co.uk",nocase; classtype:trojan-activity; sid:100003812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aciabogados.com",nocase; classtype:trojan-activity; sid:100003813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acteon.com.ar",nocase; classtype:trojan-activity; sid:100003814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"activateyourdiscount.com",nocase; classtype:trojan-activity; sid:100003815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"activecost.com.au",nocase; classtype:trojan-activity; sid:100003816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adamorinmusic.com",nocase; classtype:trojan-activity; sid:100003817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"addahealingmusic.com",nocase; classtype:trojan-activity; sid:100003818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.com",nocase; classtype:trojan-activity; sid:100003819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.memengers.com",nocase; classtype:trojan-activity; sid:100003820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.erapor.smk-alasror.net",nocase; classtype:trojan-activity; sid:100003821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.gentbcn.org",nocase; classtype:trojan-activity; sid:100003822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.grandoceanvilla.com",nocase; classtype:trojan-activity; sid:100003823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adventureexplorer.in",nocase; classtype:trojan-activity; sid:100003824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aeropilates.cl",nocase; classtype:trojan-activity; sid:100003825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afrimedspecialist.com",nocase; classtype:trojan-activity; sid:100003826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agemn.co.za",nocase; classtype:trojan-activity; sid:100003827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciadigitalwdys.com",nocase; classtype:trojan-activity; sid:100003828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciatabletshouse.com.br",nocase; classtype:trojan-activity; sid:100003829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenda.gmelloinformatica.com.br",nocase; classtype:trojan-activity; sid:100003830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agentt.ac.ug",nocase; classtype:trojan-activity; sid:100003831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agile8studio.com",nocase; classtype:trojan-activity; sid:100003832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agmcarpetcare.co.uk",nocase; classtype:trojan-activity; sid:100003833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiqtest.com",nocase; classtype:trojan-activity; sid:100003834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajpharmaholding.com",nocase; classtype:trojan-activity; sid:100003835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajstudiollc.com",nocase; classtype:trojan-activity; sid:100003836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"akauk09.top",nocase; classtype:trojan-activity; sid:100003837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"akivj07.top",nocase; classtype:trojan-activity; sid:100003838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"akpgi08.top",nocase; classtype:trojan-activity; sid:100003839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"al-wahd.com",nocase; classtype:trojan-activity; sid:100003840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alasdemariposas.org",nocase; classtype:trojan-activity; sid:100003841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alemelektronik.com",nocase; classtype:trojan-activity; sid:100003842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alena1971.es",nocase; classtype:trojan-activity; sid:100003843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alexdubai.com.aldiabsteel.com",nocase; classtype:trojan-activity; sid:100003844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"algreenstdykelveskbg.dns.army",nocase; classtype:trojan-activity; sid:100003845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alka.institute",nocase; classtype:trojan-activity; sid:100003846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"allforcreative.com.au",nocase; classtype:trojan-activity; sid:100003847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alltheway.travel",nocase; classtype:trojan-activity; sid:100003848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alpaylar.com.tr",nocase; classtype:trojan-activity; sid:100003849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"am-concepts.ca",nocase; classtype:trojan-activity; sid:100003850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amamontajes.com",nocase; classtype:trojan-activity; sid:100003851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarresdeamorymaestroshechiceros.com",nocase; classtype:trojan-activity; sid:100003852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarteargentina.com.ar",nocase; classtype:trojan-activity; sid:100003853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amenyan.zouri.jp",nocase; classtype:trojan-activity; sid:100003854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amos524.org",nocase; classtype:trojan-activity; sid:100003855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ams.alvinasschools.org.ng",nocase; classtype:trojan-activity; sid:100003856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anantam.net.in",nocase; classtype:trojan-activity; sid:100003857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreelapeyre.com",nocase; classtype:trojan-activity; sid:100003858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andremaraisbeleggings.co.za",nocase; classtype:trojan-activity; sid:100003859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ac.ug",nocase; classtype:trojan-activity; sid:100003860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ug",nocase; classtype:trojan-activity; sid:100003861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreshconcejal.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelazgheibld.com",nocase; classtype:trojan-activity; sid:100003863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelsdetour.com",nocase; classtype:trojan-activity; sid:100003864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angloteste.bigprime.com.br",nocase; classtype:trojan-activity; sid:100003865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anhung1102.vn",nocase; classtype:trojan-activity; sid:100003866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anysbergbiltong.co.za",nocase; classtype:trojan-activity; sid:100003867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apartamentoscitta.com",nocase; classtype:trojan-activity; sid:100003868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api-ms.cobainaja.id",nocase; classtype:trojan-activity; sid:100003869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.cstdevs.com",nocase; classtype:trojan-activity; sid:100003870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.quocbao.biz",nocase; classtype:trojan-activity; sid:100003871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.sampy.io",nocase; classtype:trojan-activity; sid:100003872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aplicativoparasindicato.com.br",nocase; classtype:trojan-activity; sid:100003873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apoolcondo.com",nocase; classtype:trojan-activity; sid:100003874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.adsensearticle.com",nocase; classtype:trojan-activity; sid:100003875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.explicitsurveys.co.uk",nocase; classtype:trojan-activity; sid:100003876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.prerana.info",nocase; classtype:trojan-activity; sid:100003877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apps.saintsoporte.com",nocase; classtype:trojan-activity; sid:100003878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aqv.news",nocase; classtype:trojan-activity; sid:100003879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"areyoulivingwell.com",nocase; classtype:trojan-activity; sid:100003880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"artedibujoyarquitectura.com",nocase; classtype:trojan-activity; sid:100003881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ask-regard.call-save.biz",nocase; classtype:trojan-activity; sid:100003882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atfile.com",nocase; classtype:trojan-activity; sid:100003883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"athenacapsg.com",nocase; classtype:trojan-activity; sid:100003884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atlasconcreteworks.com",nocase; classtype:trojan-activity; sid:100003885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atnetech.com",nocase; classtype:trojan-activity; sid:100003886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"attach.66rpg.com",nocase; classtype:trojan-activity; sid:100003887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atteuqpotentialunlimited.com",nocase; classtype:trojan-activity; sid:100003888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"augustair.com",nocase; classtype:trojan-activity; sid:100003889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aulist.com",nocase; classtype:trojan-activity; sid:100003890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"automaticrefreshments.com",nocase; classtype:trojan-activity; sid:100003891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"avadhanagames.com",nocase; classtype:trojan-activity; sid:100003892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayamallah.com",nocase; classtype:trojan-activity; sid:100003893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azmeasurement.com",nocase; classtype:trojan-activity; sid:100003894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azraktours.com",nocase; classtype:trojan-activity; sid:100003895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"b2b.toptanakaryakit.com.tr",nocase; classtype:trojan-activity; sid:100003896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"backgrounds.pk",nocase; classtype:trojan-activity; sid:100003897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"badeggdesign.com",nocase; classtype:trojan-activity; sid:100003898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"balealgodon.mx",nocase; classtype:trojan-activity; sid:100003899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangkok-orchids.com",nocase; classtype:trojan-activity; sid:100003900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"barcionstw.eastus.cloudapp.azure.com",nocase; classtype:trojan-activity; sid:100003901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bary.sz4h.com",nocase; classtype:trojan-activity; sid:100003902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bash.givemexyz.in",nocase; classtype:trojan-activity; sid:100003903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"basma.com.kw",nocase; classtype:trojan-activity; sid:100003904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk",nocase; classtype:trojan-activity; sid:100003905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bavhome.com",nocase; classtype:trojan-activity; sid:100003906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bbia.co.uk",nocase; classtype:trojan-activity; sid:100003907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcmt.elin.co.za",nocase; classtype:trojan-activity; sid:100003908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcrg.co.za",nocase; classtype:trojan-activity; sid:100003909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bearcatpumps.com.cn",nocase; classtype:trojan-activity; sid:100003910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beautincollagen.rs",nocase; classtype:trojan-activity; sid:100003911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bekape.co.id",nocase; classtype:trojan-activity; sid:100003912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bespokeweddings.ie",nocase; classtype:trojan-activity; sid:100003913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bestcarenepal.com",nocase; classtype:trojan-activity; sid:100003914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betone.co.kr",nocase; classtype:trojan-activity; sid:100003915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betycopaints.com",nocase; classtype:trojan-activity; sid:100003916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beveragesmiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bhavaniengineering.com",nocase; classtype:trojan-activity; sid:100003918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bigbag.wootraining.certificacion.cl",nocase; classtype:trojan-activity; sid:100003919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilbosaquet.ug",nocase; classtype:trojan-activity; sid:100003920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilhen.co.za",nocase; classtype:trojan-activity; sid:100003921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"billing.rahitechnosoft.com",nocase; classtype:trojan-activity; sid:100003922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"binoy.stalphonsamissionva.org",nocase; classtype:trojan-activity; sid:100003923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birdi.elin.co.za",nocase; classtype:trojan-activity; sid:100003924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birminghamlink.org",nocase; classtype:trojan-activity; sid:100003925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.callensaxen.com",nocase; classtype:trojan-activity; sid:100003926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.oyinblogs.com",nocase; classtype:trojan-activity; sid:100003927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.takbelit.com",nocase; classtype:trojan-activity; sid:100003928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bmlifestyle.co.uk",nocase; classtype:trojan-activity; sid:100003929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bnrnews.id",nocase; classtype:trojan-activity; sid:100003930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bodenstein.co.za",nocase; classtype:trojan-activity; sid:100003931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"booksearch.com",nocase; classtype:trojan-activity; sid:100003932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bounces.mi-fs.com",nocase; classtype:trojan-activity; sid:100003933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bpo.correct.go.th",nocase; classtype:trojan-activity; sid:100003934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bradleyinstitute.co.za",nocase; classtype:trojan-activity; sid:100003935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brandtrust.com.pk",nocase; classtype:trojan-activity; sid:100003936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brendanquine.com",nocase; classtype:trojan-activity; sid:100003937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brideofmessiah.com",nocase; classtype:trojan-activity; sid:100003938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bridesofmaldives.com",nocase; classtype:trojan-activity; sid:100003939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightmega.com",nocase; classtype:trojan-activity; sid:100003940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightonrooms.co.uk",nocase; classtype:trojan-activity; sid:100003941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightstarshop.com",nocase; classtype:trojan-activity; sid:100003942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"browardinsurancemiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bt2.elin.co.za",nocase; classtype:trojan-activity; sid:100003944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"btdapi.robotake.com",nocase; classtype:trojan-activity; sid:100003945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buigiaphat.com.vn",nocase; classtype:trojan-activity; sid:100003946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bullseyemedia.in",nocase; classtype:trojan-activity; sid:100003947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"busandvanrentalmalaysia.com",nocase; classtype:trojan-activity; sid:100003948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buscascolegios.diit.cl",nocase; classtype:trojan-activity; sid:100003949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business.softberg.ro",nocase; classtype:trojan-activity; sid:100003950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buyingmusiconline.com",nocase; classtype:trojan-activity; sid:100003951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bwsr.eu",nocase; classtype:trojan-activity; sid:100003952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c.oooooooooo.ga",nocase; classtype:trojan-activity; sid:100003953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c0140529.ferozo.com",nocase; classtype:trojan-activity; sid:100003954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"caballo.com.au",nocase; classtype:trojan-activity; sid:100003955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"calgaryautorepairservice.com",nocase; classtype:trojan-activity; sid:100003956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"callbury.in",nocase; classtype:trojan-activity; sid:100003957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"camminachetipassa.it",nocase; classtype:trojan-activity; sid:100003958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"campusvirtual.cepsanjuanbosco.net.pe",nocase; classtype:trojan-activity; sid:100003959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cancer.educandome.co",nocase; classtype:trojan-activity; sid:100003960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalgroup-kw.com",nocase; classtype:trojan-activity; sid:100003961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalnewsagency.com",nocase; classtype:trojan-activity; sid:100003962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capoeiraventrelivre.com",nocase; classtype:trojan-activity; sid:100003963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cashyinvestment.org",nocase; classtype:trojan-activity; sid:100003964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchpoolshetlands.co.uk",nocase; classtype:trojan-activity; sid:100003965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cazyacustomfurniture.com",nocase; classtype:trojan-activity; sid:100003966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ccauthority.net",nocase; classtype:trojan-activity; sid:100003967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdaonline.com.ar",nocase; classtype:trojan-activity; sid:100003968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cec.asso.ac-amiens.fr",nocase; classtype:trojan-activity; sid:100003969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cecra.cl",nocase; classtype:trojan-activity; sid:100003970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cellas.sk",nocase; classtype:trojan-activity; sid:100003971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cendekiabinaaksara.com",nocase; classtype:trojan-activity; sid:100003972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cespol-bote.com.mx",nocase; classtype:trojan-activity; sid:100003973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cfs5.tistory.com",nocase; classtype:trojan-activity; sid:100003974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ch.rmu.ac.th",nocase; classtype:trojan-activity; sid:100003975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"changematterscounselling.com",nocase; classtype:trojan-activity; sid:100003976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chardhamdodham.com",nocase; classtype:trojan-activity; sid:100003977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chezalice.co.za",nocase; classtype:trojan-activity; sid:100003978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"childselect.com",nocase; classtype:trojan-activity; sid:100003979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile.myvnc.com",nocase; classtype:trojan-activity; sid:100003980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile80.myvnc.com",nocase; classtype:trojan-activity; sid:100003981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cible-energy.com",nocase; classtype:trojan-activity; sid:100003982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cifeer.net",nocase; classtype:trojan-activity; sid:100003983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citycapproperty.ru",nocase; classtype:trojan-activity; sid:100003984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cityglobalgospel.com",nocase; classtype:trojan-activity; sid:100003985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"civi.istmejia.com",nocase; classtype:trojan-activity; sid:100003986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cleanbydesignllc.com",nocase; classtype:trojan-activity; sid:100003987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloud.fc.co.mz",nocase; classtype:trojan-activity; sid:100003988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codsambal.com",nocase; classtype:trojan-activity; sid:100003989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colinde.pricesne.com",nocase; classtype:trojan-activity; sid:100003990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colorpak.pl",nocase; classtype:trojan-activity; sid:100003991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"competancy.indigoconsult.net",nocase; classtype:trojan-activity; sid:100003992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"config.cqhbkjzx.com",nocase; classtype:trojan-activity; sid:100003993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"constructoralyon.com",nocase; classtype:trojan-activity; sid:100003994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"consulateins.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"contributeindustry.com",nocase; classtype:trojan-activity; sid:100003996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"controleautomacao.com.br",nocase; classtype:trojan-activity; sid:100003997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"copelandscapes.com",nocase; classtype:trojan-activity; sid:100003998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"coulsongraphics.com",nocase; classtype:trojan-activity; sid:100003999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"covid19.cyberschool.or.id",nocase; classtype:trojan-activity; sid:100004000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cr-sq.com",nocase; classtype:trojan-activity; sid:100004001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"craftnesia.id",nocase; classtype:trojan-activity; sid:100004002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"creationskateboards.com",nocase; classtype:trojan-activity; sid:100004003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crecerco.com",nocase; classtype:trojan-activity; sid:100004004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crittersbythebay.com",nocase; classtype:trojan-activity; sid:100004005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crm.notariavieitoyvelamazan.com",nocase; classtype:trojan-activity; sid:100004006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crscorretordeimoveis.com.br",nocase; classtype:trojan-activity; sid:100004007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cse-engineer.com",nocase; classtype:trojan-activity; sid:100004008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"csnserver.com",nocase; classtype:trojan-activity; sid:100004009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubescargoexpress.com",nocase; classtype:trojan-activity; sid:100004010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubrebocasenpuebla.com.mx",nocase; classtype:trojan-activity; sid:100004011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"curasoles.co.za",nocase; classtype:trojan-activity; sid:100004012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"currantmedia.com",nocase; classtype:trojan-activity; sid:100004013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cwa.mx",nocase; classtype:trojan-activity; sid:100004014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyber.searchkero.com",nocase; classtype:trojan-activity; sid:100004015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyclomove.com",nocase; classtype:trojan-activity; sid:100004016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cynkon.kairoscs.net",nocase; classtype:trojan-activity; sid:100004017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czas.dbstrony.pl",nocase; classtype:trojan-activity; sid:100004018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czsl.91756.cn",nocase; classtype:trojan-activity; sid:100004019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d.powerofwish.com",nocase; classtype:trojan-activity; sid:100004020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d9.99ddd.com",nocase; classtype:trojan-activity; sid:100004021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"da.alibuf.com",nocase; classtype:trojan-activity; sid:100004022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"damagedessentialtelecommunications.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100004023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dandyair.com",nocase; classtype:trojan-activity; sid:100004024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dartoonpictures.com",nocase; classtype:trojan-activity; sid:100004025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.cdevelop.org",nocase; classtype:trojan-activity; sid:100004026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.over-blog-kiwi.com",nocase; classtype:trojan-activity; sid:100004027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datapolish.com",nocase; classtype:trojan-activity; sid:100004028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dating.khokhas.co.za",nocase; classtype:trojan-activity; sid:100004029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datsom.vn",nocase; classtype:trojan-activity; sid:100004030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"daunhotq10.com",nocase; classtype:trojan-activity; sid:100004031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davethompson.me.uk",nocase; classtype:trojan-activity; sid:100004032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davidmcguinness.info",nocase; classtype:trojan-activity; sid:100004033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dayspringdaisies.com",nocase; classtype:trojan-activity; sid:100004034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dd.qiyuea.cn",nocase; classtype:trojan-activity; sid:100004035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"de.gsearch.com.de",nocase; classtype:trojan-activity; sid:100004036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"decifrar.com.br",nocase; classtype:trojan-activity; sid:100004037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deigratia2.elin.co.za",nocase; classtype:trojan-activity; sid:100004038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dekovizyon.com",nocase; classtype:trojan-activity; sid:100004039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo-cliente.mindcreative.com.br",nocase; classtype:trojan-activity; sid:100004040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo6.hiites.com",nocase; classtype:trojan-activity; sid:100004041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dent-estet.com",nocase; classtype:trojan-activity; sid:100004042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dental.xiaoxiao.media",nocase; classtype:trojan-activity; sid:100004043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dentalalliance.se",nocase; classtype:trojan-activity; sid:100004044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"designerliving.co.za",nocase; classtype:trojan-activity; sid:100004045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"desiringhands.com",nocase; classtype:trojan-activity; sid:100004046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"despertaresi.com.br",nocase; classtype:trojan-activity; sid:100004047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"destinymc.co.za",nocase; classtype:trojan-activity; sid:100004048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"detorre.es",nocase; classtype:trojan-activity; sid:100004049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev-interestingtech.pantheonsite.io",nocase; classtype:trojan-activity; sid:100004050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.sebpo.net",nocase; classtype:trojan-activity; sid:100004051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dezcom.com",nocase; classtype:trojan-activity; sid:100004052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfcf.91756.cn",nocase; classtype:trojan-activity; sid:100004053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"diamantenegro.mi-fs.com",nocase; classtype:trojan-activity; sid:100004054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dienmayminhhung.com",nocase; classtype:trojan-activity; sid:100004055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digilib.dianhusada.ac.id",nocase; classtype:trojan-activity; sid:100004056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"djking.f3322.net",nocase; classtype:trojan-activity; sid:100004057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl-link.link",nocase; classtype:trojan-activity; sid:100004058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.1003b.56a.com",nocase; classtype:trojan-activity; sid:100004059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.198424.com",nocase; classtype:trojan-activity; sid:100004060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.installcdn-aws.com",nocase; classtype:trojan-activity; sid:100004061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.packetstormsecurity.net",nocase; classtype:trojan-activity; sid:100004062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.rina-roleplay.com",nocase; classtype:trojan-activity; sid:100004063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.zkytech.com",nocase; classtype:trojan-activity; sid:100004064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dns.cyberium.cc",nocase; classtype:trojan-activity; sid:100004065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dockerupdate.anondns.net",nocase; classtype:trojan-activity; sid:100004066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docman.orientalservices.in",nocase; classtype:trojan-activity; sid:100004067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dodsonimaging.com",nocase; classtype:trojan-activity; sid:100004068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dokan.blueberrytec.com",nocase; classtype:trojan-activity; sid:100004069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom-chel74.ru",nocase; classtype:trojan-activity; sid:100004070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom.daf.free.fr",nocase; classtype:trojan-activity; sid:100004071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doncedyhall.com",nocase; classtype:trojan-activity; sid:100004072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donghobinhminh.com",nocase; classtype:trojan-activity; sid:100004073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dongphuctop.com",nocase; classtype:trojan-activity; sid:100004074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donwnloasecury.ath.cx",nocase; classtype:trojan-activity; sid:100004075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosame.com",nocase; classtype:trojan-activity; sid:100004076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosman.pl",nocase; classtype:trojan-activity; sid:100004077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dovberger.com",nocase; classtype:trojan-activity; sid:100004078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.flash-plays.com",nocase; classtype:trojan-activity; sid:100004079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.pcclear.com",nocase; classtype:trojan-activity; sid:100004080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.webbora.com",nocase; classtype:trojan-activity; sid:100004081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down1.arpun.com",nocase; classtype:trojan-activity; sid:100004082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.caihong.com",nocase; classtype:trojan-activity; sid:100004083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.doumaibiji.cn",nocase; classtype:trojan-activity; sid:100004084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.exrnybuf.cn",nocase; classtype:trojan-activity; sid:100004085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.kaobeitu.com",nocase; classtype:trojan-activity; sid:100004086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.pdf00.cn",nocase; classtype:trojan-activity; sid:100004087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.rising.com.cn",nocase; classtype:trojan-activity; sid:100004088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.skycn.com",nocase; classtype:trojan-activity; sid:100004089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.zjsyawqj.cn",nocase; classtype:trojan-activity; sid:100004090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"downloads.jxtsteel.cn",nocase; classtype:trojan-activity; sid:100004091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dragonsknot.com",nocase; classtype:trojan-activity; sid:100004092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drbaby.com.sa",nocase; classtype:trojan-activity; sid:100004093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drohnen.ensenanzainteligente.com",nocase; classtype:trojan-activity; sid:100004094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drools-moved.46999.n3.nabble.com",nocase; classtype:trojan-activity; sid:100004095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drsha.innovativesolutions.mobi",nocase; classtype:trojan-activity; sid:100004096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsenterprize.co.za",nocase; classtype:trojan-activity; sid:100004097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsspainting.com",nocase; classtype:trojan-activity; sid:100004098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"du-wizards.com",nocase; classtype:trojan-activity; sid:100004099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duckrambo.com",nocase; classtype:trojan-activity; sid:100004100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duque.guantanameratravel.com",nocase; classtype:trojan-activity; sid:100004101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dutapp.wisolve.co.za",nocase; classtype:trojan-activity; sid:100004102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duvalcharter.dekitout.com",nocase; classtype:trojan-activity; sid:100004103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dx.qqyewu.com",nocase; classtype:trojan-activity; sid:100004104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dzinestudio87.co.uk",nocase; classtype:trojan-activity; sid:100004105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-commerce.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100004106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e.sldov.ru",nocase; classtype:trojan-activity; sid:100004107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ebruyatkin.com",nocase; classtype:trojan-activity; sid:100004108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"econews.treegle.org",nocase; classtype:trojan-activity; sid:100004109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"efficientegroup.com",nocase; classtype:trojan-activity; sid:100004110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"en.baoend.com",nocase; classtype:trojan-activity; sid:100004111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enc-tech.com",nocase; classtype:trojan-activity; sid:100004112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"endurotanzania.co.tz",nocase; classtype:trojan-activity; sid:100004113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ennovate.elin.co.za",nocase; classtype:trojan-activity; sid:100004114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enriquecendocomconsorcio.com.br",nocase; classtype:trojan-activity; sid:100004115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"envios.petpienso.cl",nocase; classtype:trojan-activity; sid:100004116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"equimination.ee",nocase; classtype:trojan-activity; sid:100004117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"escola.probommar.org.br",nocase; classtype:trojan-activity; sid:100004118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"esnconsultants.com",nocase; classtype:trojan-activity; sid:100004119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"essentia.org.br",nocase; classtype:trojan-activity; sid:100004120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eubanks7.com",nocase; classtype:trojan-activity; sid:100004121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evidencemarketing.ca",nocase; classtype:trojan-activity; sid:100004122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exilum.com",nocase; classtype:trojan-activity; sid:100004123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exitoalfaomega.co",nocase; classtype:trojan-activity; sid:100004124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"extrovertoffers.com",nocase; classtype:trojan-activity; sid:100004125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"familydentist.site",nocase; classtype:trojan-activity; sid:100004126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"farmaciasdrogaminas.com.br",nocase; classtype:trojan-activity; sid:100004127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fate3.xyz",nocase; classtype:trojan-activity; sid:100004128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"faveraprojects.com",nocase; classtype:trojan-activity; sid:100004129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fc.co.mz",nocase; classtype:trojan-activity; sid:100004130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"felicienne.nl",nocase; classtype:trojan-activity; sid:100004131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fi.bonitastores.com",nocase; classtype:trojan-activity; sid:100004132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.martellexpress.us",nocase; classtype:trojan-activity; sid:100004133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"final.makkahkmcc.com",nocase; classtype:trojan-activity; sid:100004134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fineartgallerym.com",nocase; classtype:trojan-activity; sid:100004135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fixauto.illumetechnology.com",nocase; classtype:trojan-activity; sid:100004136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fkd.derpcity.ru",nocase; classtype:trojan-activity; sid:100004137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flintspin.com",nocase; classtype:trojan-activity; sid:100004138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flyingbuddhadesign.com",nocase; classtype:trojan-activity; sid:100004139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fmjplastering.co.uk",nocase; classtype:trojan-activity; sid:100004140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fms.buladde.or.ug",nocase; classtype:trojan-activity; sid:100004141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foothills.com.br",nocase; classtype:trojan-activity; sid:100004142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"footweardirect.elin.co.za",nocase; classtype:trojan-activity; sid:100004143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"forum.mdb.nu",nocase; classtype:trojan-activity; sid:100004144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fotoobjetivo.com",nocase; classtype:trojan-activity; sid:100004145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foxeps.com.br",nocase; classtype:trojan-activity; sid:100004146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freecnetdownload.com",nocase; classtype:trojan-activity; sid:100004147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freedombookshop.tickme.lk",nocase; classtype:trojan-activity; sid:100004148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freisites.com.br",nocase; classtype:trojan-activity; sid:100004149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ftp.n3twork30cm.ml",nocase; classtype:trojan-activity; sid:100004150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fullelectronica.com.ar",nocase; classtype:trojan-activity; sid:100004151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"funletters.net",nocase; classtype:trojan-activity; sid:100004152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fusionfiresolutions.com",nocase; classtype:trojan-activity; sid:100004153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gametwogame.com",nocase; classtype:trojan-activity; sid:100004154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garciadogshow.com",nocase; classtype:trojan-activity; sid:100004155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow.myvnc.com",nocase; classtype:trojan-activity; sid:100004156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow4.myvnc.com",nocase; classtype:trojan-activity; sid:100004157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gbbulls.co.uk",nocase; classtype:trojan-activity; sid:100004158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gcpc.co.id.chronoscurtain.com",nocase; classtype:trojan-activity; sid:100004159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"generaldeviales.com",nocase; classtype:trojan-activity; sid:100004160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfmodd1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100004161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfold1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100004162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghettohub.co.za",nocase; classtype:trojan-activity; sid:100004163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghislain.dartois.pagesperso-orange.fr",nocase; classtype:trojan-activity; sid:100004164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giadungg7.com",nocase; classtype:trojan-activity; sid:100004165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giddos.ga",nocase; classtype:trojan-activity; sid:100004166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"girotexuniformes.com",nocase; classtype:trojan-activity; sid:100004167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giteletropical.com",nocase; classtype:trojan-activity; sid:100004168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"globaltask.ar",nocase; classtype:trojan-activity; sid:100004169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"glowinmedia.co.ke",nocase; classtype:trojan-activity; sid:100004170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmtransformationacademy.com",nocase; classtype:trojan-activity; sid:100004171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmvadmission.org",nocase; classtype:trojan-activity; sid:100004172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnimelf.net",nocase; classtype:trojan-activity; sid:100004173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnscrew.ro",nocase; classtype:trojan-activity; sid:100004174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gold.investforex.id",nocase; classtype:trojan-activity; sid:100004175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcake.co.id",nocase; classtype:trojan-activity; sid:100004176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com",nocase; classtype:trojan-activity; sid:100004177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com.au",nocase; classtype:trojan-activity; sid:100004178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcupmortgage.com",nocase; classtype:trojan-activity; sid:100004179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"golden-memories-funerals.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldmen.in",nocase; classtype:trojan-activity; sid:100004181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gracejukes.com",nocase; classtype:trojan-activity; sid:100004182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"grupoinmare.com",nocase; classtype:trojan-activity; sid:100004183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gruposelt.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gs.monerorx.com",nocase; classtype:trojan-activity; sid:100004185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gulfac-house.com",nocase; classtype:trojan-activity; sid:100004186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gvpcdpgc.edu.in",nocase; classtype:trojan-activity; sid:100004187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"habbotips.free.fr",nocase; classtype:trojan-activity; sid:100004188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hagebakken.no",nocase; classtype:trojan-activity; sid:100004189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"harshraval.in",nocase; classtype:trojan-activity; sid:100004190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hd11315.com",nocase; classtype:trojan-activity; sid:100004191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hdkamera2003.hu",nocase; classtype:trojan-activity; sid:100004192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hdrest.fastlinktz.com",nocase; classtype:trojan-activity; sid:100004193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hds.sz4h.com",nocase; classtype:trojan-activity; sid:100004194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"healthy20.net",nocase; classtype:trojan-activity; sid:100004195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"heavymaq.cl",nocase; classtype:trojan-activity; sid:100004196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com",nocase; classtype:trojan-activity; sid:100004197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hellogorgeous.com.au",nocase; classtype:trojan-activity; sid:100004198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"help.hizuko.com",nocase; classtype:trojan-activity; sid:100004199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"herchinfitout.com.sg",nocase; classtype:trojan-activity; sid:100004200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hhaward.org",nocase; classtype:trojan-activity; sid:100004201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandroadcoc.com",nocase; classtype:trojan-activity; sid:100004202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandslasvegas.atakdev.com",nocase; classtype:trojan-activity; sid:100004203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hindi.factsriver.com",nocase; classtype:trojan-activity; sid:100004204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hiptool.net",nocase; classtype:trojan-activity; sid:100004205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitpe.com",nocase; classtype:trojan-activity; sid:100004206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitstation.nl",nocase; classtype:trojan-activity; sid:100004207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hmpmall.co.kr",nocase; classtype:trojan-activity; sid:100004208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoagietesting10.com",nocase; classtype:trojan-activity; sid:100004209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoayeuthuong-my.sharepoint.com",nocase; classtype:trojan-activity; sid:100004210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"homefindersolutions.com",nocase; classtype:trojan-activity; sid:100004211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hongluosi.com",nocase; classtype:trojan-activity; sid:100004212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hookedupboatclub.com",nocase; classtype:trojan-activity; sid:100004213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostzaa.com",nocase; classtype:trojan-activity; sid:100004214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"houstonshutters.site",nocase; classtype:trojan-activity; sid:100004215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hr2019.vrcom7.com",nocase; classtype:trojan-activity; sid:100004216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hseda.com",nocase; classtype:trojan-activity; sid:100004217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsmwebapp.com",nocase; classtype:trojan-activity; sid:100004218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"htownbars.com",nocase; classtype:trojan-activity; sid:100004219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hubtech.co.za",nocase; classtype:trojan-activity; sid:100004220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hunggiang.vn",nocase; classtype:trojan-activity; sid:100004221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"husamiyahschool.com",nocase; classtype:trojan-activity; sid:100004222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iam313.com",nocase; classtype:trojan-activity; sid:100004223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"icon.shatangmu.cn",nocase; classtype:trojan-activity; sid:100004224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idea-secure-login.com",nocase; classtype:trojan-activity; sid:100004225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idilsoft.com",nocase; classtype:trojan-activity; sid:100004226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idj.no",nocase; classtype:trojan-activity; sid:100004227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idvindia.com",nocase; classtype:trojan-activity; sid:100004228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iesanjosemonitos.edu.co",nocase; classtype:trojan-activity; sid:100004229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ikexpert.com",nocase; classtype:trojan-activity; sid:100004230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ilrafrica.com",nocase; classtype:trojan-activity; sid:100004231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"imbueautoworx.co.za",nocase; classtype:trojan-activity; sid:100004232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incodimsa.com",nocase; classtype:trojan-activity; sid:100004233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incrediblepixels.com",nocase; classtype:trojan-activity; sid:100004234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incredicole.com",nocase; classtype:trojan-activity; sid:100004235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infair.vn",nocase; classtype:trojan-activity; sid:100004236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infovator.com",nocase; classtype:trojan-activity; sid:100004237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"innatosbrand.com",nocase; classtype:trojan-activity; sid:100004238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inodesthetotaldesigners.com",nocase; classtype:trojan-activity; sid:100004239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inovations.searchkero.com",nocase; classtype:trojan-activity; sid:100004240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inrajahmundry.co.in",nocase; classtype:trojan-activity; sid:100004241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"insignificantfinecore.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100004242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"instantindialoan.com",nocase; classtype:trojan-activity; sid:100004243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intellectsmart.in",nocase; classtype:trojan-activity; sid:100004244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intersel-idf.org",nocase; classtype:trojan-activity; sid:100004245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intuitiveideas.com.my",nocase; classtype:trojan-activity; sid:100004246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inversiones.arrayanfinanciero.cl",nocase; classtype:trojan-activity; sid:100004247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"invest.xpcorporative.com.br",nocase; classtype:trojan-activity; sid:100004248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"investinae.com",nocase; classtype:trojan-activity; sid:100004249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ipmes.ma",nocase; classtype:trojan-activity; sid:100004250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iremart.es",nocase; classtype:trojan-activity; sid:100004251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iris101.co.uk",nocase; classtype:trojan-activity; sid:100004252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isaac.mikhailmotoringschool.com",nocase; classtype:trojan-activity; sid:100004253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iscamenabe.com",nocase; classtype:trojan-activity; sid:100004254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ismf.com.ng",nocase; classtype:trojan-activity; sid:100004255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iso-dubai.net",nocase; classtype:trojan-activity; sid:100004256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"israrulhaq.me",nocase; classtype:trojan-activity; sid:100004257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isrorg.com",nocase; classtype:trojan-activity; sid:100004258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isso.ps",nocase; classtype:trojan-activity; sid:100004259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"it123.ru",nocase; classtype:trojan-activity; sid:100004260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itc-demo.softgig.co.ke",nocase; classtype:trojan-activity; sid:100004261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itconsultus.com.co",nocase; classtype:trojan-activity; sid:100004262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamiekaylive.com",nocase; classtype:trojan-activity; sid:100004263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamshed.pk",nocase; classtype:trojan-activity; sid:100004264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jansen-heesch.nl",nocase; classtype:trojan-activity; sid:100004265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jathra.co.uk",nocase; classtype:trojan-activity; sid:100004266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jay.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100004267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jebs.net.au",nocase; classtype:trojan-activity; sid:100004268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jeffdahlke.com",nocase; classtype:trojan-activity; sid:100004269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jhayesconsulting.com",nocase; classtype:trojan-activity; sid:100004270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jiaoyuzixun.cn",nocase; classtype:trojan-activity; sid:100004271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jing-da.com.tw",nocase; classtype:trojan-activity; sid:100004272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jmcomputacion.com.ar",nocase; classtype:trojan-activity; sid:100004273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jmtc.91756.cn",nocase; classtype:trojan-activity; sid:100004274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jnanbharati.com",nocase; classtype:trojan-activity; sid:100004275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jobs.thebeessolution.com",nocase; classtype:trojan-activity; sid:100004276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"joelbonissilver.com",nocase; classtype:trojan-activity; sid:100004277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"join.cl8movement.co.za",nocase; classtype:trojan-activity; sid:100004278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josegene.com",nocase; classtype:trojan-activity; sid:100004279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josuarochoa.com",nocase; classtype:trojan-activity; sid:100004280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jpwoodfordco.com",nocase; classtype:trojan-activity; sid:100004281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jumpmanualjacobhiller.com",nocase; classtype:trojan-activity; sid:100004282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jupiter.toxsl.in",nocase; classtype:trojan-activity; sid:100004283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"justinscott.com.au",nocase; classtype:trojan-activity; sid:100004284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalawatihomes.com",nocase; classtype:trojan-activity; sid:100004285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalpataru-elitus-mulund.thakkers.in",nocase; classtype:trojan-activity; sid:100004286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karer.by",nocase; classtype:trojan-activity; sid:100004287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"katanvetov.co.il",nocase; classtype:trojan-activity; sid:100004288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kensingtondriving.com",nocase; classtype:trojan-activity; sid:100004289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kevinjewelry.com.co",nocase; classtype:trojan-activity; sid:100004290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"keywatch.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kingssa.co.za",nocase; classtype:trojan-activity; sid:100004292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kjcpromo.com",nocase; classtype:trojan-activity; sid:100004293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kleinendeli.co.za",nocase; classtype:trojan-activity; sid:100004294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"korrectconceptservices.com",nocase; classtype:trojan-activity; sid:100004295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ktb.sch.id",nocase; classtype:trojan-activity; sid:100004296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kubatoglubaklava.com.tr",nocase; classtype:trojan-activity; sid:100004297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kumaralok.in",nocase; classtype:trojan-activity; sid:100004298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kwanfromhongkong.com",nocase; classtype:trojan-activity; sid:100004299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kz.sldov.ru",nocase; classtype:trojan-activity; sid:100004300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lacasadelosalebrijes.com",nocase; classtype:trojan-activity; sid:100004301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ladylabonde.com",nocase; classtype:trojan-activity; sid:100004302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lameguard.ru",nocase; classtype:trojan-activity; sid:100004303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laodongnhat.vn",nocase; classtype:trojan-activity; sid:100004304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laravel.pointersoftwares.com.br",nocase; classtype:trojan-activity; sid:100004305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lasermobilesounds.co.uk",nocase; classtype:trojan-activity; sid:100004306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lauratomismith.com",nocase; classtype:trojan-activity; sid:100004307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lautarosanmiguel.com",nocase; classtype:trojan-activity; sid:100004308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawforall.edu.lk",nocase; classtype:trojan-activity; sid:100004309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lceventos.net",nocase; classtype:trojan-activity; sid:100004310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ld.mediaget.com",nocase; classtype:trojan-activity; sid:100004311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ldgcorp.com",nocase; classtype:trojan-activity; sid:100004312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"learning.real-academy.net",nocase; classtype:trojan-activity; sid:100004313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leasiacherise.com",nocase; classtype:trojan-activity; sid:100004314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leczkregoslup.acelero.pl",nocase; classtype:trojan-activity; sid:100004315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"legend.nu",nocase; classtype:trojan-activity; sid:100004316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leluibuffet.com.br",nocase; classtype:trojan-activity; sid:100004317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lestesteux.ca",nocase; classtype:trojan-activity; sid:100004318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"libantravel.pl",nocase; classtype:trojan-activity; sid:100004319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.arihantmbainstitute.ac.in",nocase; classtype:trojan-activity; sid:100004320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.uib.ac.id",nocase; classtype:trojan-activity; sid:100004321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lidoraggiodisole.it",nocase; classtype:trojan-activity; sid:100004322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lifebeam.elin.co.za",nocase; classtype:trojan-activity; sid:100004323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lindnerelektroanlagen.de",nocase; classtype:trojan-activity; sid:100004324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linkintec.cn",nocase; classtype:trojan-activity; sid:100004325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"livetrack.in",nocase; classtype:trojan-activity; sid:100004326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lloydsindian.co.uk",nocase; classtype:trojan-activity; sid:100004327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lm.stagingarea.co.za",nocase; classtype:trojan-activity; sid:100004328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmaancha.co.il",nocase; classtype:trojan-activity; sid:100004329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.cstdevs.com",nocase; classtype:trojan-activity; sid:100004330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.login2.in",nocase; classtype:trojan-activity; sid:100004331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmvirtualbookkeeping.com",nocase; classtype:trojan-activity; sid:100004332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lnt-rejuve-360.thakkers.in",nocase; classtype:trojan-activity; sid:100004333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"location-voitures.ma",nocase; classtype:trojan-activity; sid:100004334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"login.trezor.com.stockfootagesindia.com",nocase; classtype:trojan-activity; sid:100004335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"logotypfabriken.se",nocase; classtype:trojan-activity; sid:100004336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotix.de",nocase; classtype:trojan-activity; sid:100004337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotusanddragonfly.com",nocase; classtype:trojan-activity; sid:100004338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.definerisco.com",nocase; classtype:trojan-activity; sid:100004339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.difusodesign.com",nocase; classtype:trojan-activity; sid:100004340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ltc.typoten.com",nocase; classtype:trojan-activity; sid:100004341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luckybrownie.com",nocase; classtype:trojan-activity; sid:100004342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luminouspneuma.com",nocase; classtype:trojan-activity; sid:100004343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luxomodels.com",nocase; classtype:trojan-activity; sid:100004344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m-technics.kz",nocase; classtype:trojan-activity; sid:100004345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m.estudiomoros.com.ar",nocase; classtype:trojan-activity; sid:100004346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"madicon.co.za",nocase; classtype:trojan-activity; sid:100004347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"magianegramagiablancayamarres.com",nocase; classtype:trojan-activity; sid:100004348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.bs-eiendomme.co.za",nocase; classtype:trojan-activity; sid:100004349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.golimoapp.com",nocase; classtype:trojan-activity; sid:100004350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.jeffsono.org",nocase; classtype:trojan-activity; sid:100004351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maksi.feb.unib.ac.id",nocase; classtype:trojan-activity; sid:100004352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malaya.tv",nocase; classtype:trojan-activity; sid:100004353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malwarecoding.github.io",nocase; classtype:trojan-activity; sid:100004354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managed.oss-cn-beijing.aliyuncs.com",nocase; classtype:trojan-activity; sid:100004355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managemysalon.in",nocase; classtype:trojan-activity; sid:100004356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manantialesdelnorte.uy",nocase; classtype:trojan-activity; sid:100004357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manhtien.net",nocase; classtype:trojan-activity; sid:100004358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marcapinyo.ru",nocase; classtype:trojan-activity; sid:100004359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mario-sunjic.com",nocase; classtype:trojan-activity; sid:100004360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariobrown.net",nocase; classtype:trojan-activity; sid:100004361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariotessarollo.com",nocase; classtype:trojan-activity; sid:100004362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketinfosales.com",nocase; classtype:trojan-activity; sid:100004363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketing.enexusgroup.com.au",nocase; classtype:trojan-activity; sid:100004364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marksidfgs.ug",nocase; classtype:trojan-activity; sid:100004365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"masjidhabeebiyarazviya.mysunni.com",nocase; classtype:trojan-activity; sid:100004366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"materialescantu.com",nocase; classtype:trojan-activity; sid:100004367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"matruchhaya.co.in",nocase; classtype:trojan-activity; sid:100004368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mattysplayground.com",nocase; classtype:trojan-activity; sid:100004369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxiquim.cl",nocase; classtype:trojan-activity; sid:100004370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxtox.com.pk",nocase; classtype:trojan-activity; sid:100004371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbgrm.com",nocase; classtype:trojan-activity; sid:100004372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbsolutions.ge",nocase; classtype:trojan-activity; sid:100004373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mdasa.elin.co.za",nocase; classtype:trojan-activity; sid:100004374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medevlb.org",nocase; classtype:trojan-activity; sid:100004375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"media-server.skyinternet.com.pk",nocase; classtype:trojan-activity; sid:100004376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mediamaster.co.za",nocase; classtype:trojan-activity; sid:100004377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medianews.ge",nocase; classtype:trojan-activity; sid:100004378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medistaffconsulting.com",nocase; classtype:trojan-activity; sid:100004379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meditreat.itwebservice.in",nocase; classtype:trojan-activity; sid:100004380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meeweb.com",nocase; classtype:trojan-activity; sid:100004381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megamart.afnan-amc.com",nocase; classtype:trojan-activity; sid:100004382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merbay.ru",nocase; classtype:trojan-activity; sid:100004383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merkathink.com",nocase; classtype:trojan-activity; sid:100004384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mertlog.com",nocase; classtype:trojan-activity; sid:100004385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"metalin-cr.com",nocase; classtype:trojan-activity; sid:100004386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mettaanand.org",nocase; classtype:trojan-activity; sid:100004387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meuoculosnanet.com.br",nocase; classtype:trojan-activity; sid:100004388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mfevr.com",nocase; classtype:trojan-activity; sid:100004389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot.myvnc.com",nocase; classtype:trojan-activity; sid:100004390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot80.myvnc.com",nocase; classtype:trojan-activity; sid:100004391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"micalle.com.au",nocase; classtype:trojan-activity; sid:100004392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michaelphilip.com",nocase; classtype:trojan-activity; sid:100004393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michimal2.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microblading.mirliandias.com.br",nocase; classtype:trojan-activity; sid:100004395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microcomm-group.com",nocase; classtype:trojan-activity; sid:100004396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mikhailmotoringschool.com",nocase; classtype:trojan-activity; sid:100004397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mindfulbuildingandliving.com",nocase; classtype:trojan-activity; sid:100004398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mingguanwms.com",nocase; classtype:trojan-activity; sid:100004399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minuevavida.org",nocase; classtype:trojan-activity; sid:100004400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mirror.mypage.sk",nocase; classtype:trojan-activity; sid:100004401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mis.nbcc.ac.th",nocase; classtype:trojan-activity; sid:100004402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"misterson.com",nocase; classtype:trojan-activity; sid:100004403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mixr.at",nocase; classtype:trojan-activity; sid:100004404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mkontakt.az",nocase; classtype:trojan-activity; sid:100004405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mktf.mx",nocase; classtype:trojan-activity; sid:100004406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmogollon.com.mx",nocase; classtype:trojan-activity; sid:100004407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mncarteam.com",nocase; classtype:trojan-activity; sid:100004408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mobile.illumetechnology.com",nocase; classtype:trojan-activity; sid:100004409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modelhouseturkey.com",nocase; classtype:trojan-activity; sid:100004410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modernmanna.org",nocase; classtype:trojan-activity; sid:100004411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"monetization.business",nocase; classtype:trojan-activity; sid:100004412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moninediy.com",nocase; classtype:trojan-activity; sid:100004413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mopai.sg",nocase; classtype:trojan-activity; sid:100004414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"motorcomunicacion.com",nocase; classtype:trojan-activity; sid:100004415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"msacontabil.com.br",nocase; classtype:trojan-activity; sid:100004416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mtspsmjeli.sch.id",nocase; classtype:trojan-activity; sid:100004417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"muzimbiti.xigubo.co.mz",nocase; classtype:trojan-activity; sid:100004418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mxpiqw.am.files.1drv.com",nocase; classtype:trojan-activity; sid:100004419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mydatebook.in",nocase; classtype:trojan-activity; sid:100004420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mymlql.com",nocase; classtype:trojan-activity; sid:100004421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myritz.vettickal.com",nocase; classtype:trojan-activity; sid:100004422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myscape.in",nocase; classtype:trojan-activity; sid:100004423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysura.it",nocase; classtype:trojan-activity; sid:100004424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"namnyak.co.ke",nocase; classtype:trojan-activity; sid:100004425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nap.mgsservers.com",nocase; classtype:trojan-activity; sid:100004426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"navayurveda.in",nocase; classtype:trojan-activity; sid:100004427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nbs.vizzhost.com",nocase; classtype:trojan-activity; sid:100004428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nec-i.com",nocase; classtype:trojan-activity; sid:100004429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nelitrianggraeni.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nerve.untergrund.net",nocase; classtype:trojan-activity; sid:100004431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nettube.com.br",nocase; classtype:trojan-activity; sid:100004432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"networkwheels.co.za",nocase; classtype:trojan-activity; sid:100004433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neuromedic.com.br",nocase; classtype:trojan-activity; sid:100004434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neverseenshop.com.mx",nocase; classtype:trojan-activity; sid:100004435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newinfinitysynergy.com",nocase; classtype:trojan-activity; sid:100004436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"news.dbstrony.pl",nocase; classtype:trojan-activity; sid:100004437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtreedesign.co.uk",nocase; classtype:trojan-activity; sid:100004438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtrendeg.com",nocase; classtype:trojan-activity; sid:100004439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newvisionopticallab.com",nocase; classtype:trojan-activity; sid:100004440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newxing.com",nocase; classtype:trojan-activity; sid:100004441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nextdigitalday.ru",nocase; classtype:trojan-activity; sid:100004442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ngdaycare.co.za",nocase; classtype:trojan-activity; sid:100004443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nguyenkekhuyen.com",nocase; classtype:trojan-activity; sid:100004444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhorangtreem.com",nocase; classtype:trojan-activity; sid:100004445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nicolas.ug",nocase; classtype:trojan-activity; sid:100004446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nidhi.iexist.in",nocase; classtype:trojan-activity; sid:100004447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nikanpolimer.ir",nocase; classtype:trojan-activity; sid:100004448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilehouse.co.ug",nocase; classtype:trojan-activity; sid:100004449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilinkeji.com",nocase; classtype:trojan-activity; sid:100004450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"njtiledesigncenter.com",nocase; classtype:trojan-activity; sid:100004451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nobius.org",nocase; classtype:trojan-activity; sid:100004452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nocalnoodle.elin.co.za",nocase; classtype:trojan-activity; sid:100004453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nomadicbees.com",nocase; classtype:trojan-activity; sid:100004454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nonnarina.ax",nocase; classtype:trojan-activity; sid:100004455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"notamuzikaletleri.com",nocase; classtype:trojan-activity; sid:100004456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ns1.the-widyantos.com",nocase; classtype:trojan-activity; sid:100004457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsb.org.uk",nocase; classtype:trojan-activity; sid:100004458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsheldon.co.uk",nocase; classtype:trojan-activity; sid:100004459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nuthuassociates.com",nocase; classtype:trojan-activity; sid:100004460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nuwagi.com",nocase; classtype:trojan-activity; sid:100004461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyeh2o.com.au",nocase; classtype:trojan-activity; sid:100004462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oakleyandfriends.co.uk",nocase; classtype:trojan-activity; sid:100004463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"obseques-conseils.com",nocase; classtype:trojan-activity; sid:100004464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohe.ie",nocase; classtype:trojan-activity; sid:100004465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohsewgorgeous.co.uk",nocase; classtype:trojan-activity; sid:100004466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oknoplastik.sk",nocase; classtype:trojan-activity; sid:100004467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oleholeh.memangbeda.website",nocase; classtype:trojan-activity; sid:100004468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"olirecords.mixture.ltd",nocase; classtype:trojan-activity; sid:100004469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"olooom.com",nocase; classtype:trojan-activity; sid:100004470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaia.org",nocase; classtype:trojan-activity; sid:100004471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaromatic.com",nocase; classtype:trojan-activity; sid:100004472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omega.az",nocase; classtype:trojan-activity; sid:100004473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oms.pappai.com",nocase; classtype:trojan-activity; sid:100004474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omscoc.pappai.com",nocase; classtype:trojan-activity; sid:100004475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedigitalcard.granvizionnecorp.com",nocase; classtype:trojan-activity; sid:100004476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.listifyapp.co",nocase; classtype:trojan-activity; sid:100004477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"online.creedglobal.in",nocase; classtype:trojan-activity; sid:100004478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onlinestatis.bar",nocase; classtype:trojan-activity; sid:100004479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ont.proman.id",nocase; classtype:trojan-activity; sid:100004480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"open.warehousesaas.co.uk",nocase; classtype:trojan-activity; sid:100004481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opolis.io",nocase; classtype:trojan-activity; sid:100004482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opticaoptigral.cl",nocase; classtype:trojan-activity; sid:100004483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optimus.com.sg",nocase; classtype:trojan-activity; sid:100004484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optitechsa.co.za",nocase; classtype:trojan-activity; sid:100004485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"order.bizpeed.com",nocase; classtype:trojan-activity; sid:100004486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orientgatewayltd.com",nocase; classtype:trojan-activity; sid:100004487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orion445.com",nocase; classtype:trojan-activity; sid:100004488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orpod.ru",nocase; classtype:trojan-activity; sid:100004489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oserve.pk",nocase; classtype:trojan-activity; sid:100004490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ottimade.com",nocase; classtype:trojan-activity; sid:100004491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ourteam.searchkero.com",nocase; classtype:trojan-activity; sid:100004492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ozemag.com",nocase; classtype:trojan-activity; sid:100004493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p1.lingpao8.com",nocase; classtype:trojan-activity; sid:100004494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p3.zbjimg.com",nocase; classtype:trojan-activity; sid:100004495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p6.zbjimg.com",nocase; classtype:trojan-activity; sid:100004496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pablobrothel.com.ar",nocase; classtype:trojan-activity; sid:100004497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacificgroup.ws",nocase; classtype:trojan-activity; sid:100004498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacwebdesigns.com",nocase; classtype:trojan-activity; sid:100004499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pagos.krayem.com.mx",nocase; classtype:trojan-activity; sid:100004500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"palochusvet.szm.com",nocase; classtype:trojan-activity; sid:100004501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parallel.rockvideos.at",nocase; classtype:trojan-activity; sid:100004502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parejasfelices.mi-fs.com",nocase; classtype:trojan-activity; sid:100004503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parkhussion.com",nocase; classtype:trojan-activity; sid:100004504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastorpaulocosta.com",nocase; classtype:trojan-activity; sid:100004505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.51lg.com",nocase; classtype:trojan-activity; sid:100004506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.99ddd.com",nocase; classtype:trojan-activity; sid:100004507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch3.99ddd.com",nocase; classtype:trojan-activity; sid:100004508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paths.elin.co.za",nocase; classtype:trojan-activity; sid:100004509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paulmercier.biz",nocase; classtype:trojan-activity; sid:100004510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payerrealty.com",nocase; classtype:trojan-activity; sid:100004511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payments.atifsiddiqui.me",nocase; classtype:trojan-activity; sid:100004512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pcsoori.com",nocase; classtype:trojan-activity; sid:100004513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pd.oceaniarp.net",nocase; classtype:trojan-activity; sid:100004514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpustekim.untirta.ac.id",nocase; classtype:trojan-activity; sid:100004515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"petercollie.com",nocase; classtype:trojan-activity; sid:100004516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ph4s.ru",nocase; classtype:trojan-activity; sid:100004517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phasdesign.com",nocase; classtype:trojan-activity; sid:100004518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phenhuong.sanpham.online",nocase; classtype:trojan-activity; sid:100004519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phittc.com",nocase; classtype:trojan-activity; sid:100004520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photo360.kubooking.com",nocase; classtype:trojan-activity; sid:100004521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photographytipsclub.com",nocase; classtype:trojan-activity; sid:100004522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pink99.com",nocase; classtype:trojan-activity; sid:100004523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pizzabarletta.com.br",nocase; classtype:trojan-activity; sid:100004524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"plasfan.ind.br",nocase; classtype:trojan-activity; sid:100004525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pmglance.startwriteup.com",nocase; classtype:trojan-activity; sid:100004526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pokojewewladyslawowie.pl",nocase; classtype:trojan-activity; sid:100004527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pole.com.vc",nocase; classtype:trojan-activity; sid:100004528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pool.phxdir.com",nocase; classtype:trojan-activity; sid:100004529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pooltablemoversdenver.net",nocase; classtype:trojan-activity; sid:100004530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"posmicrosystems.com",nocase; classtype:trojan-activity; sid:100004531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"poulman.panagiotopoulos-tours.gr",nocase; classtype:trojan-activity; sid:100004532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ppdb.smk-ciptaskill.sch.id",nocase; classtype:trojan-activity; sid:100004533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pptvideotemplates.com",nocase; classtype:trojan-activity; sid:100004534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestasicash.com.ar",nocase; classtype:trojan-activity; sid:100004535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestigehomeautomation.net",nocase; classtype:trojan-activity; sid:100004536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prishaartcreations.com",nocase; classtype:trojan-activity; sid:100004537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"production.sparshims.com",nocase; classtype:trojan-activity; sid:100004538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"programaoperadoronline.com.br",nocase; classtype:trojan-activity; sid:100004539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"project.exquitec.com",nocase; classtype:trojan-activity; sid:100004540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promotoradescomplica.com.br",nocase; classtype:trojan-activity; sid:100004541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promoversdubai.com",nocase; classtype:trojan-activity; sid:100004542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq.elin.co.za",nocase; classtype:trojan-activity; sid:100004543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq2.elin.co.za",nocase; classtype:trojan-activity; sid:100004544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosoc.nl",nocase; classtype:trojan-activity; sid:100004545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosyarmakassar.com",nocase; classtype:trojan-activity; sid:100004546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"provence.elin.co.za",nocase; classtype:trojan-activity; sid:100004547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prueba.danielluza.com",nocase; classtype:trojan-activity; sid:100004548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pujashoppe.in",nocase; classtype:trojan-activity; sid:100004549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punchdialogues.com",nocase; classtype:trojan-activity; sid:100004550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punjabdevelopersassociation.com.pk",nocase; classtype:trojan-activity; sid:100004551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"purefoe.top",nocase; classtype:trojan-activity; sid:100004552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pvcprinting.co.uk",nocase; classtype:trojan-activity; sid:100004553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qadir.tickfa.ir",nocase; classtype:trojan-activity; sid:100004554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qatarglobalconsulting.com",nocase; classtype:trojan-activity; sid:100004555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qmsled.com",nocase; classtype:trojan-activity; sid:100004556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quartier-midi.be",nocase; classtype:trojan-activity; sid:100004557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"querocar.com",nocase; classtype:trojan-activity; sid:100004558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rachmat-assuhaimi.my.id",nocase; classtype:trojan-activity; sid:100004559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rainbowisp.info",nocase; classtype:trojan-activity; sid:100004560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raodigitalmedia.com",nocase; classtype:trojan-activity; sid:100004561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rarlabarchiver.ac",nocase; classtype:trojan-activity; sid:100004562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rasadbar.ir",nocase; classtype:trojan-activity; sid:100004563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rashika.ascarvalho.co.za",nocase; classtype:trojan-activity; sid:100004564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ratemyfenancialadvisor.com",nocase; classtype:trojan-activity; sid:100004565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ravenproductionsltd.com",nocase; classtype:trojan-activity; sid:100004566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rc.ixiaoyang.cn",nocase; classtype:trojan-activity; sid:100004567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rcmesilva.charbelsales.com.br",nocase; classtype:trojan-activity; sid:100004568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"readymmade.com",nocase; classtype:trojan-activity; sid:100004569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redchillicrackers.com",nocase; classtype:trojan-activity; sid:100004570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reifenquick.de",nocase; classtype:trojan-activity; sid:100004571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"relaxindulge.co.nz",nocase; classtype:trojan-activity; sid:100004572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"renehavis.com.ua",nocase; classtype:trojan-activity; sid:100004573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"repatriacioncolombia.com",nocase; classtype:trojan-activity; sid:100004574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.uf1.cn",nocase; classtype:trojan-activity; sid:100004575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.digimitra.in",nocase; classtype:trojan-activity; sid:100004576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"resuco.net",nocase; classtype:trojan-activity; sid:100004577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rezkabum.ru",nocase; classtype:trojan-activity; sid:100004578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rhema.com.sg",nocase; classtype:trojan-activity; sid:100004579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richancyber.info",nocase; classtype:trojan-activity; sid:100004580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richmondminerals.co.zm",nocase; classtype:trojan-activity; sid:100004581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinaefoundation.org.za",nocase; classtype:trojan-activity; sid:100004582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinkaisystem-ht.com",nocase; classtype:trojan-activity; sid:100004583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"riverfox.co.za",nocase; classtype:trojan-activity; sid:100004584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkcable.co.in",nocase; classtype:trojan-activity; sid:100004585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkverify.securestudies.com",nocase; classtype:trojan-activity; sid:100004586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roadfurylifts.com",nocase; classtype:trojan-activity; sid:100004587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertmcardle.com",nocase; classtype:trojan-activity; sid:100004588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertsinclair.net",nocase; classtype:trojan-activity; sid:100004589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robinhood-sports.com",nocase; classtype:trojan-activity; sid:100004590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"romanianpoints.com",nocase; classtype:trojan-activity; sid:100004591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ronnietucker.co.uk",nocase; classtype:trojan-activity; sid:100004592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roomsvc.servegate.kr",nocase; classtype:trojan-activity; sid:100004593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshan.academy",nocase; classtype:trojan-activity; sid:100004594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshnijewellery.com",nocase; classtype:trojan-activity; sid:100004595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rs-toolkit.mikestclair.org",nocase; classtype:trojan-activity; sid:100004596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rsgym.net",nocase; classtype:trojan-activity; sid:100004597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubazar.pro",nocase; classtype:trojan-activity; sid:100004598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubycityvietnam.com",nocase; classtype:trojan-activity; sid:100004599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruisgood.ru",nocase; classtype:trojan-activity; sid:100004600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruwadalkuwait.com",nocase; classtype:trojan-activity; sid:100004601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rydchile.cl",nocase; classtype:trojan-activity; sid:100004602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rzminc.com",nocase; classtype:trojan-activity; sid:100004603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.51shijuan.com",nocase; classtype:trojan-activity; sid:100004604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.thechinesemuslim.com",nocase; classtype:trojan-activity; sid:100004605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sacredscentsonline.com",nocase; classtype:trojan-activity; sid:100004606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safcol-colors.com",nocase; classtype:trojan-activity; sid:100004607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safehubsecurity.ca",nocase; classtype:trojan-activity; sid:100004608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safety.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100004609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sahathaikasetpan.com",nocase; classtype:trojan-activity; sid:100004610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"saisoftwareinc.com",nocase; classtype:trojan-activity; sid:100004611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salecorner.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sandovalgraphics.com",nocase; classtype:trojan-activity; sid:100004613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"santyago.org",nocase; classtype:trojan-activity; sid:100004614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sarakem.cl",nocase; classtype:trojan-activity; sid:100004615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sasystemsuk.com",nocase; classtype:trojan-activity; sid:100004616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"savasaachi.systems",nocase; classtype:trojan-activity; sid:100004617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scarfaceindustries.com",nocase; classtype:trojan-activity; sid:100004618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scglobal.co.th",nocase; classtype:trojan-activity; sid:100004619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schalke04rss.de",nocase; classtype:trojan-activity; sid:100004620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scheff.com",nocase; classtype:trojan-activity; sid:100004621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schoolbustracker.softgig.co.ke",nocase; classtype:trojan-activity; sid:100004622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sec-doc-w.com",nocase; classtype:trojan-activity; sid:100004623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"secure-doc-reader.com",nocase; classtype:trojan-activity; sid:100004624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"segalsmetals.elin.co.za",nocase; classtype:trojan-activity; sid:100004625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sellmyphonela.com",nocase; classtype:trojan-activity; sid:100004626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"selltechtoday.com",nocase; classtype:trojan-activity; sid:100004627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"senbiaojita.com",nocase; classtype:trojan-activity; sid:100004628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sentierodelviandante.ml",nocase; classtype:trojan-activity; sid:100004629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serendibsourcing.com",nocase; classtype:trojan-activity; sid:100004630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd.myvnc.com",nocase; classtype:trojan-activity; sid:100004631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd80.myvnc.com",nocase; classtype:trojan-activity; sid:100004632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serviciovirtual.com.ar",nocase; classtype:trojan-activity; sid:100004633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"seyranikenger.com.tr",nocase; classtype:trojan-activity; sid:100004634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sgessy.com.br",nocase; classtype:trojan-activity; sid:100004635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shaheentbfoundation.com",nocase; classtype:trojan-activity; sid:100004636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahikhana.cstdevs.com",nocase; classtype:trojan-activity; sid:100004637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharkrigs.com",nocase; classtype:trojan-activity; sid:100004638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharpelevators.in",nocase; classtype:trojan-activity; sid:100004639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shembefoundation.com",nocase; classtype:trojan-activity; sid:100004640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shivakunwar.com.np",nocase; classtype:trojan-activity; sid:100004641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shoblasaathitrust.org",nocase; classtype:trojan-activity; sid:100004642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shooka-co.com",nocase; classtype:trojan-activity; sid:100004643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shop.goldspot.agency",nocase; classtype:trojan-activity; sid:100004644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shopsofe.com",nocase; classtype:trojan-activity; sid:100004645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shrushtiinfotech.com",nocase; classtype:trojan-activity; sid:100004646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sibernetix.fr",nocase; classtype:trojan-activity; sid:100004647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sige.brisainformatica.com.br",nocase; classtype:trojan-activity; sid:100004648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"signatureads.co.in",nocase; classtype:trojan-activity; sid:100004649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siili.net",nocase; classtype:trojan-activity; sid:100004650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simoneporzi.it",nocase; classtype:trojan-activity; sid:100004651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simplithy.co.uk",nocase; classtype:trojan-activity; sid:100004652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindicato1ucm.cl",nocase; classtype:trojan-activity; sid:100004653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindpol.tiejuris.com.br",nocase; classtype:trojan-activity; sid:100004654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sinergidwireka.com",nocase; classtype:trojan-activity; sid:100004655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sipahielektrik.com",nocase; classtype:trojan-activity; sid:100004656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siperb.in",nocase; classtype:trojan-activity; sid:100004657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sistelligent.com",nocase; classtype:trojan-activity; sid:100004658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skkksolo.beweiretail.com",nocase; classtype:trojan-activity; sid:100004659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyflyfares.com",nocase; classtype:trojan-activity; sid:100004660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyscan.com",nocase; classtype:trojan-activity; sid:100004661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarthouseforum.ru",nocase; classtype:trojan-activity; sid:100004662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarts.tj",nocase; classtype:trojan-activity; sid:100004663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smartzedu.com",nocase; classtype:trojan-activity; sid:100004664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokeandgrowrichtour.com",nocase; classtype:trojan-activity; sid:100004665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokesolutionindia.com",nocase; classtype:trojan-activity; sid:100004666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobethuacademy.com",nocase; classtype:trojan-activity; sid:100004667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.110route.com",nocase; classtype:trojan-activity; sid:100004668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.officelabo.net",nocase; classtype:trojan-activity; sid:100004669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sohs.conceptechs.info",nocase; classtype:trojan-activity; sid:100004670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solar.amazingtribe.lk",nocase; classtype:trojan-activity; sid:100004671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solo2.dbstrony.pl",nocase; classtype:trojan-activity; sid:100004672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somcorbera.cat",nocase; classtype:trojan-activity; sid:100004673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somir.com.mx",nocase; classtype:trojan-activity; sid:100004674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soralapps.com",nocase; classtype:trojan-activity; sid:100004675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sorteio.orgaostalita.com.br",nocase; classtype:trojan-activity; sid:100004676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sota-france.fr",nocase; classtype:trojan-activity; sid:100004677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sowingminerals.cl",nocase; classtype:trojan-activity; sid:100004678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"space.proactint.org",nocase; classtype:trojan-activity; sid:100004679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spaceframe.mobi.space-frame.co.za",nocase; classtype:trojan-activity; sid:100004680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"special-key.cf",nocase; classtype:trojan-activity; sid:100004681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spent.com.pl",nocase; classtype:trojan-activity; sid:100004682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spetsesyachtcharter.gr",nocase; classtype:trojan-activity; sid:100004683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spititourism.com",nocase; classtype:trojan-activity; sid:100004684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spittinfire.com",nocase; classtype:trojan-activity; sid:100004685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sports-net.de",nocase; classtype:trojan-activity; sid:100004686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"src1.minibai.com",nocase; classtype:trojan-activity; sid:100004687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sreenivasapaintingworks.com",nocase; classtype:trojan-activity; sid:100004688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sriglobalit.com",nocase; classtype:trojan-activity; sid:100004689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srvmanos.no-ip.info",nocase; classtype:trojan-activity; sid:100004690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ss.monita.co.id",nocase; classtype:trojan-activity; sid:100004691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"staging.apparelpunch.com",nocase; classtype:trojan-activity; sid:100004692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"starcountry.net",nocase; classtype:trojan-activity; sid:100004693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"static.3001.net",nocase; classtype:trojan-activity; sid:100004694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statsres.com",nocase; classtype:trojan-activity; sid:100004695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statssound.com",nocase; classtype:trojan-activity; sid:100004696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statsspot.com",nocase; classtype:trojan-activity; sid:100004697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statsvilla.com",nocase; classtype:trojan-activity; sid:100004698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stemschool.net",nocase; classtype:trojan-activity; sid:100004699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiepancasetia.ac.id",nocase; classtype:trojan-activity; sid:100004700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stott-thompson.co.uk",nocase; classtype:trojan-activity; sid:100004701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stratexec.co.za",nocase; classtype:trojan-activity; sid:100004702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"streetdemo.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"suboldesign.com",nocase; classtype:trojan-activity; sid:100004704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sumerians.org",nocase; classtype:trojan-activity; sid:100004705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunbrero.com.au",nocase; classtype:trojan-activity; sid:100004706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunmarkholidays.com",nocase; classtype:trojan-activity; sid:100004707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supermercadostia.com",nocase; classtype:trojan-activity; sid:100004708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support-4-free.com",nocase; classtype:trojan-activity; sid:100004709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support.clz.kr",nocase; classtype:trojan-activity; sid:100004710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supportit.online",nocase; classtype:trojan-activity; sid:100004711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sw.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweaty.dk",nocase; classtype:trojan-activity; sid:100004713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweet-diet.com",nocase; classtype:trojan-activity; sid:100004714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swentsai.com",nocase; classtype:trojan-activity; sid:100004715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swiftlogisticseg.com",nocase; classtype:trojan-activity; sid:100004716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swwbia.com",nocase; classtype:trojan-activity; sid:100004717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"syracusecoffee.com",nocase; classtype:trojan-activity; sid:100004718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sys.pbmadu.co.id",nocase; classtype:trojan-activity; sid:100004719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sytraders.co",nocase; classtype:trojan-activity; sid:100004720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.honker.info",nocase; classtype:trojan-activity; sid:100004721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.netcatkit.com",nocase; classtype:trojan-activity; sid:100004722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tacticohosting.com",nocase; classtype:trojan-activity; sid:100004723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tadoo.ca",nocase; classtype:trojan-activity; sid:100004724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tafsantoursandtravels.com",nocase; classtype:trojan-activity; sid:100004725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tallyinvoicecustomization.com",nocase; classtype:trojan-activity; sid:100004726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taltus.co.uk",nocase; classtype:trojan-activity; sid:100004727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tapalkoedacoffee.com",nocase; classtype:trojan-activity; sid:100004728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tarravalleyfoods.com.au",nocase; classtype:trojan-activity; sid:100004729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taurus.ug",nocase; classtype:trojan-activity; sid:100004730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tavo.cl",nocase; classtype:trojan-activity; sid:100004731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taxicabsrilanka.com",nocase; classtype:trojan-activity; sid:100004732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taxpos.com",nocase; classtype:trojan-activity; sid:100004733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tc.snpsresidential.com",nocase; classtype:trojan-activity; sid:100004734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tcy.198424.com",nocase; classtype:trojan-activity; sid:100004735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tdsp.yngw518.com",nocase; classtype:trojan-activity; sid:100004736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"techgms.com",nocase; classtype:trojan-activity; sid:100004737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technogreen.crmmanivela.com",nocase; classtype:trojan-activity; sid:100004738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technohub.searchkero.com",nocase; classtype:trojan-activity; sid:100004739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tecnicaencolectores.com.mx",nocase; classtype:trojan-activity; sid:100004740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tecnologyschool.com",nocase; classtype:trojan-activity; sid:100004741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teduae.com",nocase; classtype:trojan-activity; sid:100004742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teleargentina.com",nocase; classtype:trojan-activity; sid:100004743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telescopelms.com",nocase; classtype:trojan-activity; sid:100004744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telmed.cl",nocase; classtype:trojan-activity; sid:100004745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"temptmag.com",nocase; classtype:trojan-activity; sid:100004746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tentandoserfitness.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.adventser.com",nocase; classtype:trojan-activity; sid:100004748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.letraele.es",nocase; classtype:trojan-activity; sid:100004749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.typoten.com",nocase; classtype:trojan-activity; sid:100004750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.wanepghana.org",nocase; classtype:trojan-activity; sid:100004751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.asistencia247.com",nocase; classtype:trojan-activity; sid:100004752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.milenial.id",nocase; classtype:trojan-activity; sid:100004753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.tenplusone.my",nocase; classtype:trojan-activity; sid:100004754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.basis-web.com",nocase; classtype:trojan-activity; sid:100004755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.marrenconstruction.ie",nocase; classtype:trojan-activity; sid:100004756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.clickitsolutionsmw.com",nocase; classtype:trojan-activity; sid:100004757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.thinkingcorp.in",nocase; classtype:trojan-activity; sid:100004758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testnew.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teteaffiche.stephanebillon.com",nocase; classtype:trojan-activity; sid:100004760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tewoerd.eu",nocase; classtype:trojan-activity; sid:100004761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"textile.softberg.ro",nocase; classtype:trojan-activity; sid:100004762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"texturesbyvinita.com",nocase; classtype:trojan-activity; sid:100004763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tharringtonsponsorship.com",nocase; classtype:trojan-activity; sid:100004764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecleaningladiespdx.com",nocase; classtype:trojan-activity; sid:100004765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecreativecafe.co.uk",nocase; classtype:trojan-activity; sid:100004766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefuturelife.in",nocase; classtype:trojan-activity; sid:100004767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehighlightinterior.com",nocase; classtype:trojan-activity; sid:100004768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehouseofpragya.com",nocase; classtype:trojan-activity; sid:100004769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thekassia.co.uk",nocase; classtype:trojan-activity; sid:100004770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thelaunchpadteam.com",nocase; classtype:trojan-activity; sid:100004771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thesummitpc.net",nocase; classtype:trojan-activity; sid:100004772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theurbantutors.com",nocase; classtype:trojan-activity; sid:100004773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thosewebbs.com",nocase; classtype:trojan-activity; sid:100004774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tianangdep.com",nocase; classtype:trojan-activity; sid:100004775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickfood.tickme.lk",nocase; classtype:trojan-activity; sid:100004776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickjobs.tickme.lk",nocase; classtype:trojan-activity; sid:100004777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickmart.tickme.lk",nocase; classtype:trojan-activity; sid:100004778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"timegonebuy.com",nocase; classtype:trojan-activity; sid:100004779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tksb.net",nocase; classtype:trojan-activity; sid:100004780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tlcc.com.gt",nocase; classtype:trojan-activity; sid:100004781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"todoapp.cstdevs.com",nocase; classtype:trojan-activity; sid:100004782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonydong.com",nocase; classtype:trojan-activity; sid:100004783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonyzone.com",nocase; classtype:trojan-activity; sid:100004784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tooba.tenplusone.my",nocase; classtype:trojan-activity; sid:100004785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topcell9.com",nocase; classtype:trojan-activity; sid:100004786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topicsnepal.com",nocase; classtype:trojan-activity; sid:100004787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toplevel.com.br",nocase; classtype:trojan-activity; sid:100004788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"torresquinterocorp.com",nocase; classtype:trojan-activity; sid:100004789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"towme.services",nocase; classtype:trojan-activity; sid:100004790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toyotacollege.ac.th",nocase; classtype:trojan-activity; sid:100004791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpef.lsoftdemo.com",nocase; classtype:trojan-activity; sid:100004792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpke.hu",nocase; classtype:trojan-activity; sid:100004793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tradezone.ejuicysolutions.com",nocase; classtype:trojan-activity; sid:100004794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"translaterjemah.com",nocase; classtype:trojan-activity; sid:100004795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"travelwithmanta.co.za",nocase; classtype:trojan-activity; sid:100004796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trezors.io.mahlongwa.com",nocase; classtype:trojan-activity; sid:100004797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"triplonet.com.br",nocase; classtype:trojan-activity; sid:100004798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"troki.com.co",nocase; classtype:trojan-activity; sid:100004799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tropics.codeleek.net",nocase; classtype:trojan-activity; sid:100004800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trucks.softwarenecessities.com",nocase; classtype:trojan-activity; sid:100004801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trudelfavreau.com",nocase; classtype:trojan-activity; sid:100004802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsd.jxwan.com",nocase; classtype:trojan-activity; sid:100004803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tulli.info",nocase; classtype:trojan-activity; sid:100004804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tupperware.michaelroberge.ca",nocase; classtype:trojan-activity; sid:100004805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"turanggaresources.com",nocase; classtype:trojan-activity; sid:100004806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uat.indianfilmzone.com",nocase; classtype:trojan-activity; sid:100004807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ublretailerdemo.cstdevs.com",nocase; classtype:trojan-activity; sid:100004808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uc-56.ru",nocase; classtype:trojan-activity; sid:100004809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"udesk.searchkero.com",nocase; classtype:trojan-activity; sid:100004810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ugprs-ubih.org",nocase; classtype:trojan-activity; sid:100004811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ultimate-24.de",nocase; classtype:trojan-activity; sid:100004812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"umwelt-kirchhof.de",nocase; classtype:trojan-activity; sid:100004813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unicorpbrunei.com",nocase; classtype:trojan-activity; sid:100004814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uniengrisb.com",nocase; classtype:trojan-activity; sid:100004815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unisoftcc.com",nocase; classtype:trojan-activity; sid:100004816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unyazitelecom.com",nocase; classtype:trojan-activity; sid:100004817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"upcbpta.com",nocase; classtype:trojan-activity; sid:100004818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"urbantrapfest.cl",nocase; classtype:trojan-activity; sid:100004819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"useformoney.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"usmadetshirts.com",nocase; classtype:trojan-activity; sid:100004821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uss.ac.th",nocase; classtype:trojan-activity; sid:100004822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uzzepay.com.br",nocase; classtype:trojan-activity; sid:100004823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vbcargo.hu",nocase; classtype:trojan-activity; sid:100004824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vcah.co.uk",nocase; classtype:trojan-activity; sid:100004825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vegadelcasero.cl",nocase; classtype:trojan-activity; sid:100004826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vendas.lidiacarmeli.com.br",nocase; classtype:trojan-activity; sid:100004827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vfocus.net",nocase; classtype:trojan-activity; sid:100004828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vidmattic.com",nocase; classtype:trojan-activity; sid:100004829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vienen.gblix.srv.br",nocase; classtype:trojan-activity; sid:100004830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villamarand.com",nocase; classtype:trojan-activity; sid:100004831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villatera.com",nocase; classtype:trojan-activity; sid:100004832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"violinstop.com",nocase; classtype:trojan-activity; sid:100004833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viraltalking.com",nocase; classtype:trojan-activity; sid:100004834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visions.alnisamart.com",nocase; classtype:trojan-activity; sid:100004835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visualhome.cl",nocase; classtype:trojan-activity; sid:100004836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vitoriamodaintima.com.br",nocase; classtype:trojan-activity; sid:100004837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vivationdesign.com",nocase; classtype:trojan-activity; sid:100004838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viveirodoiscorregos.com.br",nocase; classtype:trojan-activity; sid:100004839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vksales.com",nocase; classtype:trojan-activity; sid:100004840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vladimirinternational.com",nocase; classtype:trojan-activity; sid:100004841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vokasi.ub.ac.id",nocase; classtype:trojan-activity; sid:100004842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vologroup.com.br",nocase; classtype:trojan-activity; sid:100004843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"voteyouramerica.dekitout.com",nocase; classtype:trojan-activity; sid:100004844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vpinversiones.cl",nocase; classtype:trojan-activity; sid:100004845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vstsample.com",nocase; classtype:trojan-activity; sid:100004846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vtube.fadlymotivator.com",nocase; classtype:trojan-activity; sid:100004847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vvsskmodinationalschool.com",nocase; classtype:trojan-activity; sid:100004848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepliberia.org",nocase; classtype:trojan-activity; sid:100004849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepniger.org",nocase; classtype:trojan-activity; sid:100004850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weareactum.com",nocase; classtype:trojan-activity; sid:100004851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.eng.ubu.ac.th",nocase; classtype:trojan-activity; sid:100004852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geetle.ga",nocase; classtype:trojan-activity; sid:100004853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geomegasoft.net",nocase; classtype:trojan-activity; sid:100004854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.newinnovationtechnology.com",nocase; classtype:trojan-activity; sid:100004855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.smarts-works.com",nocase; classtype:trojan-activity; sid:100004856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.thebeessolution.com",nocase; classtype:trojan-activity; sid:100004857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webgis.perumdasolo.com",nocase; classtype:trojan-activity; sid:100004858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga",nocase; classtype:trojan-activity; sid:100004859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webpresario.com",nocase; classtype:trojan-activity; sid:100004860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"website-work.com",nocase; classtype:trojan-activity; sid:100004861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weinsteincounseling.com",nocase; classtype:trojan-activity; sid:100004862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wexfashion.com",nocase; classtype:trojan-activity; sid:100004863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whcms.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteglovetailgate.com",nocase; classtype:trojan-activity; sid:100004865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteresponse.com",nocase; classtype:trojan-activity; sid:100004866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wi522012.ferozo.com",nocase; classtype:trojan-activity; sid:100004867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikalen.co.za",nocase; classtype:trojan-activity; sid:100004868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildnights.co.uk",nocase; classtype:trojan-activity; sid:100004869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildtrust.mediadevstaging.com",nocase; classtype:trojan-activity; sid:100004870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wimbamusica.com",nocase; classtype:trojan-activity; sid:100004871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"windcomtechnologies.com",nocase; classtype:trojan-activity; sid:100004872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wishesconcierge.com",nocase; classtype:trojan-activity; sid:100004873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woezon.agency",nocase; classtype:trojan-activity; sid:100004874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wolfgang-brodte.de",nocase; classtype:trojan-activity; sid:100004875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woodsytech.com",nocase; classtype:trojan-activity; sid:100004876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wordpress.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100004877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wozata.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wp.readhere.in",nocase; classtype:trojan-activity; sid:100004879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wpdemo.101clients.com.au",nocase; classtype:trojan-activity; sid:100004880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"writtendeer.com",nocase; classtype:trojan-activity; sid:100004881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ws5588.f3322.net",nocase; classtype:trojan-activity; sid:100004882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wyklej.pl",nocase; classtype:trojan-activity; sid:100004883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"x2vn.com",nocase; classtype:trojan-activity; sid:100004884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xia.beihaixue.com",nocase; classtype:trojan-activity; sid:100004885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xixaoclothing.com",nocase; classtype:trojan-activity; sid:100004886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xk.996is.com",nocase; classtype:trojan-activity; sid:100004887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--80akinnkiib6h.xn--90ais",nocase; classtype:trojan-activity; sid:100004888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--polimerbizmimarlk-rvc.com",nocase; classtype:trojan-activity; sid:100004889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ybom.urbanolab.com",nocase; classtype:trojan-activity; sid:100004890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yeichner.com",nocase; classtype:trojan-activity; sid:100004891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ylfpremium.com",nocase; classtype:trojan-activity; sid:100004892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yoast.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yourtopdog.com.au",nocase; classtype:trojan-activity; sid:100004894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"youtubetrainingacademy.com",nocase; classtype:trojan-activity; sid:100004895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yp.hnggzyjy.cn",nocase; classtype:trojan-activity; sid:100004896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yskadvisors.com",nocase; classtype:trojan-activity; sid:100004897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yummyyogaudaipur.com",nocase; classtype:trojan-activity; sid:100004898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yzkzixun.com",nocase; classtype:trojan-activity; sid:100004899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zytrox.tk",nocase; classtype:trojan-activity; sid:100004900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zz.690tx.com",nocase; classtype:trojan-activity; sid:100004901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amumufree.weebly.com",nocase; http_uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe",nocase; classtype:trojan-activity; sid:100004902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"analogx.com",nocase; http_uri; content:"/files/proxyi.exe",nocase; classtype:trojan-activity; sid:100004903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"b4ad7b79-534a-4e83-953e-c36da8cf27d9.s3.amazonaws.com",nocase; http_uri; content:"/ww/setup.exe",nocase; classtype:trojan-activity; sid:100004904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe",nocase; classtype:trojan-activity; sid:100004905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/dvdfv/anjj/downloads/jami.exe",nocase; classtype:trojan-activity; sid:100004906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/4.exe",nocase; classtype:trojan-activity; sid:100004907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/6.exe",nocase; classtype:trojan-activity; sid:100004908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr.exe",nocase; classtype:trojan-activity; sid:100004909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr3.exe",nocase; classtype:trojan-activity; sid:100004910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/instaler.exe",nocase; classtype:trojan-activity; sid:100004911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/installer.exe",nocase; classtype:trojan-activity; sid:100004912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatej.exe",nocase; classtype:trojan-activity; sid:100004913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatev.exe",nocase; classtype:trojan-activity; sid:100004914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/work.exe",nocase; classtype:trojan-activity; sid:100004915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/component.exe",nocase; classtype:trojan-activity; sid:100004916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe",nocase; classtype:trojan-activity; sid:100004917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/regsvc.exe",nocase; classtype:trojan-activity; sid:100004918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/skygaming/updates/downloads/update.exe",nocase; classtype:trojan-activity; sid:100004919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/001.txt",nocase; classtype:trojan-activity; sid:100004920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1488.txt",nocase; classtype:trojan-activity; sid:100004921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1_cr.txt",nocase; classtype:trojan-activity; sid:100004922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1cr.txt",nocase; classtype:trojan-activity; sid:100004923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1fc2d.txt",nocase; classtype:trojan-activity; sid:100004924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/26a5.txt",nocase; classtype:trojan-activity; sid:100004925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt",nocase; classtype:trojan-activity; sid:100004926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/abjects.txt",nocase; classtype:trojan-activity; sid:100004927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/attached.txt",nocase; classtype:trojan-activity; sid:100004928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/b7f2c.exe",nocase; classtype:trojan-activity; sid:100004929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/battletext.txt",nocase; classtype:trojan-activity; sid:100004930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe",nocase; classtype:trojan-activity; sid:100004931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe",nocase; classtype:trojan-activity; sid:100004932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build.txt",nocase; classtype:trojan-activity; sid:100004933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_makros.exe",nocase; classtype:trojan-activity; sid:100004934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_silent.txt",nocase; classtype:trojan-activity; sid:100004935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_sup.txt",nocase; classtype:trojan-activity; sid:100004936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe",nocase; classtype:trojan-activity; sid:100004937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt",nocase; classtype:trojan-activity; sid:100004938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcr.txt",nocase; classtype:trojan-activity; sid:100004939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildss.txt",nocase; classtype:trojan-activity; sid:100004940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientnik.txt",nocase; classtype:trojan-activity; sid:100004941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientrevers.txt",nocase; classtype:trojan-activity; sid:100004942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dcrat.exe",nocase; classtype:trojan-activity; sid:100004943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices.exe",nocase; classtype:trojan-activity; sid:100004944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices2.exe",nocase; classtype:trojan-activity; sid:100004945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe",nocase; classtype:trojan-activity; sid:100004946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hans.txt",nocase; classtype:trojan-activity; sid:100004947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hulu.txt",nocase; classtype:trojan-activity; sid:100004948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfive.txt",nocase; classtype:trojan-activity; sid:100004949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfour.txt",nocase; classtype:trojan-activity; sid:100004950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelone.txt",nocase; classtype:trojan-activity; sid:100004951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelthree.txt",nocase; classtype:trojan-activity; sid:100004952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/inteltwo.txt",nocase; classtype:trojan-activity; sid:100004953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe",nocase; classtype:trojan-activity; sid:100004954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/kleiman.exe",nocase; classtype:trojan-activity; sid:100004955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe",nocase; classtype:trojan-activity; sid:100004956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/notepadplus.txt",nocase; classtype:trojan-activity; sid:100004957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe",nocase; classtype:trojan-activity; sid:100004958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.exe",nocase; classtype:trojan-activity; sid:100004959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.txt",nocase; classtype:trojan-activity; sid:100004960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt",nocase; classtype:trojan-activity; sid:100004961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/putty.txt",nocase; classtype:trojan-activity; sid:100004962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/rockethcd.txt",nocase; classtype:trojan-activity; sid:100004963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/scvhost900.exe",nocase; classtype:trojan-activity; sid:100004964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/sessionwin.exe",nocase; classtype:trojan-activity; sid:100004965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/siliculose.txt",nocase; classtype:trojan-activity; sid:100004966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/statemobi.txt",nocase; classtype:trojan-activity; sid:100004967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers.exe",nocase; classtype:trojan-activity; sid:100004968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers2.exe",nocase; classtype:trojan-activity; sid:100004969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stgedo.exe",nocase; classtype:trojan-activity; sid:100004970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/svcperf.txt",nocase; classtype:trojan-activity; sid:100004971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe",nocase; classtype:trojan-activity; sid:100004972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurjok.txt",nocase; classtype:trojan-activity; sid:100004973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurusbabac.exe",nocase; classtype:trojan-activity; sid:100004974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/telekiller.exe",nocase; classtype:trojan-activity; sid:100004975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateanddr.txt",nocase; classtype:trojan-activity; sid:100004976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateandr.txt",nocase; classtype:trojan-activity; sid:100004977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/vhajeja.txt",nocase; classtype:trojan-activity; sid:100004978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/word.txt",nocase; classtype:trojan-activity; sid:100004979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/www.txt",nocase; classtype:trojan-activity; sid:100004980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/xlsd.txt",nocase; classtype:trojan-activity; sid:100004981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin",nocase; classtype:trojan-activity; sid:100004982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin",nocase; classtype:trojan-activity; sid:100004983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cd.textfiles.com",nocase; http_uri; content:"/hmatrix/data/hack1226.exe",nocase; classtype:trojan-activity; sid:100004984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq",nocase; classtype:trojan-activity; sid:100004985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/816070119281131570/816070273254162442/all.txt",nocase; classtype:trojan-activity; sid:100004986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/821809080812437507/824392185902006272/mmp1_1.exe",nocase; classtype:trojan-activity; sid:100004987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso",nocase; classtype:trojan-activity; sid:100004988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/823810712891555890/824413943526195210/runpetest.exe",nocase; classtype:trojan-activity; sid:100004989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/824689793140129857/824690065988386816/sendhookfile.exe",nocase; classtype:trojan-activity; sid:100004990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/824689793140129857/824691026852970496/photo.exe",nocase; classtype:trojan-activity; sid:100004991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chiptune.com",nocase; http_uri; content:"/razor/rzr-winner_intro.zip",nocase; classtype:trojan-activity; sid:100004992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz",nocase; classtype:trojan-activity; sid:100004993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar",nocase; classtype:trojan-activity; sid:100004994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codeload.github.com",nocase; http_uri; content:"/meteoradminz/hidden-tear/zip/master",nocase; classtype:trojan-activity; sid:100004995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colfincas.com",nocase; http_uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/",nocase; classtype:trojan-activity; sid:100004996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deepfreedom.org",nocase; http_uri; content:"/qz0h69.pdf",nocase; classtype:trojan-activity; sid:100004997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digitalassets.ams3.digitaloceanspaces.com",nocase; http_uri; content:"/hold/schost.exe",nocase; classtype:trojan-activity; sid:100004998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digitalassets.ams3.digitaloceanspaces.com",nocase; http_uri; content:"/modern/five.exe",nocase; classtype:trojan-activity; sid:100004999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=11jnyjpzkjiie_rzc4xwa2feok3x__yvc",nocase; classtype:trojan-activity; sid:100005000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=151uxflny3vqh_lmghrkgjhhsqxi163sh",nocase; classtype:trojan-activity; sid:100005001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=15iwonkjkhyvri_okkc_llq56aasvnvb9",nocase; classtype:trojan-activity; sid:100005002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1ak46tqftzejmq-og_ky2oupgpmkgujtm",nocase; classtype:trojan-activity; sid:100005003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1brsmnj6g0lxa44ixkypvg5tcxkvi5gjt",nocase; classtype:trojan-activity; sid:100005004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1by_s4vv8gdmmz8wl-lbpjbjy5adcrjk1",nocase; classtype:trojan-activity; sid:100005005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1dpsxfbptpyl-zegto9t29vvcku2rjm9u",nocase; classtype:trojan-activity; sid:100005006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1dwb7nww_ahtjfeed-afxl4hvm_xqkx-h",nocase; classtype:trojan-activity; sid:100005007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1e7t_hnuohxuziwcxihocdievcj5_dsgj",nocase; classtype:trojan-activity; sid:100005008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1erajjbz6gdxhsvvorlykzxyeoq-xu7wn",nocase; classtype:trojan-activity; sid:100005009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1ev7gkzwjgtv2vlbbisg1ragd7nf0-xog",nocase; classtype:trojan-activity; sid:100005010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1ey8zl85vszh-gdmubkoudacqs6zv2dup",nocase; classtype:trojan-activity; sid:100005011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1gq_jf503du9oip5bwzcoi6_kgolr3kx2",nocase; classtype:trojan-activity; sid:100005012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1imrv00kqbfz4ljzwq5qdau1to0zlmaqy",nocase; classtype:trojan-activity; sid:100005013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1j6pvg1rznjh9pkldcyjiogo8ysiyl8_y",nocase; classtype:trojan-activity; sid:100005014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1jlcqojhfhgifmirrsv0o5t-2rl-hblai",nocase; classtype:trojan-activity; sid:100005015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1k6sh5h-nptesem_jsnuxmhzntnvdlgxz",nocase; classtype:trojan-activity; sid:100005016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1lk6n-xrtv0dvdqljl26pzebxzp8tladk",nocase; classtype:trojan-activity; sid:100005017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1lkcqgpimry4yp8grinnhsotnawquozcz",nocase; classtype:trojan-activity; sid:100005018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1m34mp1cggxz-cz3a5ipjrgfog_qx8myx",nocase; classtype:trojan-activity; sid:100005019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1m6kdawqt1fwxea6epcae6t1qevfhl0-5",nocase; classtype:trojan-activity; sid:100005020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1m8w1y1-mxxa2pktrzkwfetwjxrlw1alo",nocase; classtype:trojan-activity; sid:100005021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1m9jxzqcbnb8j8uph1qfcas8b9pngcogj",nocase; classtype:trojan-activity; sid:100005022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1mdnlxs6vy5qk-u4dxz9movem4j3a3o-8",nocase; classtype:trojan-activity; sid:100005023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1od6gtslxvylgyeujmrbvm9yhupmq_1lv",nocase; classtype:trojan-activity; sid:100005024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1ozpasp-mr-e-ui4lshy4qy4a2pl8pxsi",nocase; classtype:trojan-activity; sid:100005025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1q0edpjr7vgo_ytns7dgjcav6317juz9y",nocase; classtype:trojan-activity; sid:100005026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1q5gqeinogsri3i-ynlgvu88ajqnn9siq",nocase; classtype:trojan-activity; sid:100005027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1quyiobd7-d-vcddlhxiqbqrwxyg7ongo",nocase; classtype:trojan-activity; sid:100005028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1rrtyvouwizor2icbcoywdid4w9rwngxi",nocase; classtype:trojan-activity; sid:100005029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1sao6yxf-a0t6wdgdr36srwlju57vigx_",nocase; classtype:trojan-activity; sid:100005030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1st5mtgqyofsskuhlomfihfmz_qx-i32o",nocase; classtype:trojan-activity; sid:100005031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1u5q84w84g_x98ti4uflzhrgvzzfyj_qi",nocase; classtype:trojan-activity; sid:100005032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1umz5zjobot9__v2jxdutyborb2az90hz",nocase; classtype:trojan-activity; sid:100005033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1we-h5qtxj9czhkhzvzg0qqpxufgu_v__",nocase; classtype:trojan-activity; sid:100005034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1wurpipyf0s__fqtn1ov619nx7v1-tcy3",nocase; classtype:trojan-activity; sid:100005035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1wwkqbfluu4qusqz26ewulr48zh9vzq-w",nocase; classtype:trojan-activity; sid:100005036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?id=1yyuejm8cerrq2tctsibww4uetepcmh4i",nocase; classtype:trojan-activity; sid:100005037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com.it-barcelona.com",nocase; http_uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe",nocase; classtype:trojan-activity; sid:100005038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm",nocase; classtype:trojan-activity; sid:100005039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1",nocase; classtype:trojan-activity; sid:100005040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch",nocase; classtype:trojan-activity; sid:100005041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox",nocase; classtype:trojan-activity; sid:100005042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig",nocase; classtype:trojan-activity; sid:100005043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn",nocase; classtype:trojan-activity; sid:100005044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben",nocase; classtype:trojan-activity; sid:100005045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi",nocase; classtype:trojan-activity; sid:100005046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je",nocase; classtype:trojan-activity; sid:100005047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev",nocase; classtype:trojan-activity; sid:100005048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr",nocase; classtype:trojan-activity; sid:100005049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y",nocase; classtype:trojan-activity; sid:100005050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd",nocase; classtype:trojan-activity; sid:100005051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw",nocase; classtype:trojan-activity; sid:100005052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej",nocase; classtype:trojan-activity; sid:100005053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn",nocase; classtype:trojan-activity; sid:100005054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw",nocase; classtype:trojan-activity; sid:100005055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76",nocase; classtype:trojan-activity; sid:100005056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55",nocase; classtype:trojan-activity; sid:100005057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t",nocase; classtype:trojan-activity; sid:100005058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e",nocase; classtype:trojan-activity; sid:100005059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi",nocase; classtype:trojan-activity; sid:100005060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv",nocase; classtype:trojan-activity; sid:100005061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr",nocase; classtype:trojan-activity; sid:100005062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0",nocase; classtype:trojan-activity; sid:100005063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/1zilg/",nocase; classtype:trojan-activity; sid:100005064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/qcgfmfvh/",nocase; classtype:trojan-activity; sid:100005065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-mudhra.com",nocase; http_uri; content:"/downloads/emclick.zip",nocase; classtype:trojan-activity; sid:100005066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe",nocase; classtype:trojan-activity; sid:100005067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe",nocase; classtype:trojan-activity; sid:100005068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/",nocase; classtype:trojan-activity; sid:100005069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/",nocase; classtype:trojan-activity; sid:100005070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/x/",nocase; classtype:trojan-activity; sid:100005071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/",nocase; classtype:trojan-activity; sid:100005072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//",nocase; classtype:trojan-activity; sid:100005073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///",nocase; classtype:trojan-activity; sid:100005074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////",nocase; classtype:trojan-activity; sid:100005075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"file.elecfans.com",nocase; http_uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe",nocase; classtype:trojan-activity; sid:100005076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls",nocase; classtype:trojan-activity; sid:100005077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx",nocase; classtype:trojan-activity; sid:100005078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gist.githubusercontent.com",nocase; http_uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe",nocase; classtype:trojan-activity; sid:100005079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hqdecig.com",nocase; http_uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/",nocase; classtype:trojan-activity; sid:100005080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsecaravans.co.uk",nocase; http_uri; content:"/wp-admin/suy/",nocase; classtype:trojan-activity; sid:100005081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ia801802.us.archive.org",nocase; http_uri; content:"/19/items/startup_20210219/startup.txt",nocase; classtype:trojan-activity; sid:100005082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ie-best.net",nocase; http_uri; content:"/online-timer-kvhxz/ilxl/",nocase; classtype:trojan-activity; sid:100005083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100005084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100005085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jcedu.org",nocase; http_uri; content:"/ebook/cs17.exe",nocase; classtype:trojan-activity; sid:100005086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1",nocase; classtype:trojan-activity; sid:100005087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2",nocase; classtype:trojan-activity; sid:100005088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3",nocase; classtype:trojan-activity; sid:100005089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"justlficante.mediafire.com",nocase; http_uri; content:"/file/jl01o54yy09qrzg/fac215.tgz/file",nocase; classtype:trojan-activity; sid:100005090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karmakoincodes.weebly.com",nocase; http_uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe",nocase; classtype:trojan-activity; sid:100005091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ksh.hu",nocase; http_uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe",nocase; classtype:trojan-activity; sid:100005092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kuaizip.com",nocase; http_uri; content:"/down/affiliate/kuaizip_setup_10029.exe",nocase; classtype:trojan-activity; sid:100005093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linuxforensicsbook.com.s3.amazonaws.com",nocase; http_uri; content:"/linuxforensicscode.zip",nocase; classtype:trojan-activity; sid:100005094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minpic.de",nocase; http_uri; content:"/k/big5/1giof6/",nocase; classtype:trojan-activity; sid:100005095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"morrobaydrugandgift.com",nocase; http_uri; content:"/wp-contentbak/t9m/",nocase; classtype:trojan-activity; sid:100005096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"my.cloudme.com",nocase; http_uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe",nocase; classtype:trojan-activity; sid:100005097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/aacenc.exe",nocase; classtype:trojan-activity; sid:100005098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/doxillionsetup.exe",nocase; classtype:trojan-activity; sid:100005099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newyarlfm.weebly.com",nocase; http_uri; content:"/uploads/4/1/6/6/4166984/keygen.exe",nocase; classtype:trojan-activity; sid:100005100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhipcauytevietnhat.com",nocase; http_uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/",nocase; classtype:trojan-activity; sid:100005101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"note.youdao.com",nocase; http_uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a",nocase; classtype:trojan-activity; sid:100005102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oldschoolvalue.s3.amazonaws.com",nocase; http_uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe",nocase; classtype:trojan-activity; sid:100005103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq",nocase; classtype:trojan-activity; sid:100005104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq",nocase; classtype:trojan-activity; sid:100005105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa",nocase; classtype:trojan-activity; sid:100005106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq",nocase; classtype:trojan-activity; sid:100005107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe",nocase; classtype:trojan-activity; sid:100005108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg",nocase; classtype:trojan-activity; sid:100005109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0",nocase; classtype:trojan-activity; sid:100005110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g",nocase; classtype:trojan-activity; sid:100005111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140",nocase; classtype:trojan-activity; sid:100005112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130",nocase; classtype:trojan-activity; sid:100005113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135",nocase; classtype:trojan-activity; sid:100005114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732",nocase; classtype:trojan-activity; sid:100005115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4",nocase; classtype:trojan-activity; sid:100005116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100005117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100005118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0",nocase; classtype:trojan-activity; sid:100005119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100005120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100005121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100005122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100005123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc",nocase; classtype:trojan-activity; sid:100005124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq",nocase; classtype:trojan-activity; sid:100005125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko",nocase; classtype:trojan-activity; sid:100005126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw",nocase; classtype:trojan-activity; sid:100005127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4",nocase; classtype:trojan-activity; sid:100005128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4",nocase; classtype:trojan-activity; sid:100005129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma",nocase; classtype:trojan-activity; sid:100005130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48",nocase; classtype:trojan-activity; sid:100005131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq",nocase; classtype:trojan-activity; sid:100005132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg",nocase; classtype:trojan-activity; sid:100005133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw",nocase; classtype:trojan-activity; sid:100005134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq",nocase; classtype:trojan-activity; sid:100005135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100005136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100005137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100005138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100005139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4",nocase; classtype:trojan-activity; sid:100005140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100005141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100005142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw",nocase; classtype:trojan-activity; sid:100005143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0",nocase; classtype:trojan-activity; sid:100005144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk",nocase; classtype:trojan-activity; sid:100005145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk",nocase; classtype:trojan-activity; sid:100005146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a",nocase; classtype:trojan-activity; sid:100005147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4",nocase; classtype:trojan-activity; sid:100005148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo",nocase; classtype:trojan-activity; sid:100005149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100005150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100005151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc",nocase; classtype:trojan-activity; sid:100005152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc",nocase; classtype:trojan-activity; sid:100005153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100005154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100005155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100005156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100005157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100005158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100005159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve",nocase; classtype:trojan-activity; sid:100005160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w",nocase; classtype:trojan-activity; sid:100005161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100005162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100005163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg",nocase; classtype:trojan-activity; sid:100005164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60",nocase; classtype:trojan-activity; sid:100005165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg",nocase; classtype:trojan-activity; sid:100005166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4",nocase; classtype:trojan-activity; sid:100005167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c",nocase; classtype:trojan-activity; sid:100005168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0",nocase; classtype:trojan-activity; sid:100005169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc",nocase; classtype:trojan-activity; sid:100005170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100005171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs",nocase; classtype:trojan-activity; sid:100005172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0",nocase; classtype:trojan-activity; sid:100005173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd",nocase; classtype:trojan-activity; sid:100005174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc",nocase; classtype:trojan-activity; sid:100005175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100005176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po",nocase; classtype:trojan-activity; sid:100005177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe",nocase; classtype:trojan-activity; sid:100005178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk",nocase; classtype:trojan-activity; sid:100005179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100005180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100005181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu",nocase; classtype:trojan-activity; sid:100005182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k",nocase; classtype:trojan-activity; sid:100005183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo",nocase; classtype:trojan-activity; sid:100005184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk",nocase; classtype:trojan-activity; sid:100005185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei",nocase; classtype:trojan-activity; sid:100005186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte",nocase; classtype:trojan-activity; sid:100005187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk",nocase; classtype:trojan-activity; sid:100005188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei",nocase; classtype:trojan-activity; sid:100005189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte",nocase; classtype:trojan-activity; sid:100005190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga",nocase; classtype:trojan-activity; sid:100005191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly",nocase; classtype:trojan-activity; sid:100005192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs",nocase; classtype:trojan-activity; sid:100005193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs",nocase; classtype:trojan-activity; sid:100005194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0",nocase; classtype:trojan-activity; sid:100005195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620",nocase; classtype:trojan-activity; sid:100005196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo",nocase; classtype:trojan-activity; sid:100005197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e",nocase; classtype:trojan-activity; sid:100005198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100005199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100005200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw",nocase; classtype:trojan-activity; sid:100005201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw",nocase; classtype:trojan-activity; sid:100005202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4",nocase; classtype:trojan-activity; sid:100005203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w",nocase; classtype:trojan-activity; sid:100005204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100005205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8",nocase; classtype:trojan-activity; sid:100005206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100005207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw",nocase; classtype:trojan-activity; sid:100005208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8",nocase; classtype:trojan-activity; sid:100005209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100005210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100005211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100005212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100005213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq",nocase; classtype:trojan-activity; sid:100005214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o",nocase; classtype:trojan-activity; sid:100005215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc",nocase; classtype:trojan-activity; sid:100005216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0",nocase; classtype:trojan-activity; sid:100005217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100005218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100005219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100005220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100005221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo",nocase; classtype:trojan-activity; sid:100005222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou",nocase; classtype:trojan-activity; sid:100005223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo",nocase; classtype:trojan-activity; sid:100005224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou",nocase; classtype:trojan-activity; sid:100005225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100005226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100005227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100005228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100005229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk",nocase; classtype:trojan-activity; sid:100005230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100005231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100005232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge",nocase; classtype:trojan-activity; sid:100005233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs",nocase; classtype:trojan-activity; sid:100005234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100005235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100005236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100005237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100005238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0",nocase; classtype:trojan-activity; sid:100005239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100005240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100005241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik",nocase; classtype:trojan-activity; sid:100005242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq",nocase; classtype:trojan-activity; sid:100005243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy",nocase; classtype:trojan-activity; sid:100005244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100005245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100005246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y",nocase; classtype:trojan-activity; sid:100005247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100005248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100005249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100005250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100005251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y",nocase; classtype:trojan-activity; sid:100005252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo",nocase; classtype:trojan-activity; sid:100005253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4",nocase; classtype:trojan-activity; sid:100005254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm",nocase; classtype:trojan-activity; sid:100005255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu",nocase; classtype:trojan-activity; sid:100005256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100005257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100005258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc",nocase; classtype:trojan-activity; sid:100005259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y",nocase; classtype:trojan-activity; sid:100005260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8",nocase; classtype:trojan-activity; sid:100005261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0",nocase; classtype:trojan-activity; sid:100005262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc",nocase; classtype:trojan-activity; sid:100005263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs",nocase; classtype:trojan-activity; sid:100005264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts",nocase; classtype:trojan-activity; sid:100005265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc",nocase; classtype:trojan-activity; sid:100005266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg",nocase; classtype:trojan-activity; sid:100005267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y",nocase; classtype:trojan-activity; sid:100005268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday",nocase; classtype:trojan-activity; sid:100005269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0",nocase; classtype:trojan-activity; sid:100005270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas",nocase; classtype:trojan-activity; sid:100005271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve",nocase; classtype:trojan-activity; sid:100005272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy",nocase; classtype:trojan-activity; sid:100005273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14",nocase; classtype:trojan-activity; sid:100005274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i",nocase; classtype:trojan-activity; sid:100005275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa",nocase; classtype:trojan-activity; sid:100005276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu",nocase; classtype:trojan-activity; sid:100005277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c",nocase; classtype:trojan-activity; sid:100005278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy",nocase; classtype:trojan-activity; sid:100005279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q",nocase; classtype:trojan-activity; sid:100005280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm",nocase; classtype:trojan-activity; sid:100005281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4",nocase; classtype:trojan-activity; sid:100005282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho",nocase; classtype:trojan-activity; sid:100005283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18",nocase; classtype:trojan-activity; sid:100005284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q",nocase; classtype:trojan-activity; sid:100005285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm",nocase; classtype:trojan-activity; sid:100005286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na",nocase; classtype:trojan-activity; sid:100005287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk",nocase; classtype:trojan-activity; sid:100005288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe",nocase; classtype:trojan-activity; sid:100005289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi",nocase; classtype:trojan-activity; sid:100005290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc",nocase; classtype:trojan-activity; sid:100005291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc",nocase; classtype:trojan-activity; sid:100005292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100005293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100005294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100005295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100005296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100005297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100005298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100005299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100005300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100005301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100005302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100005303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100005304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4",nocase; classtype:trojan-activity; sid:100005305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu",nocase; classtype:trojan-activity; sid:100005306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi",nocase; classtype:trojan-activity; sid:100005307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8",nocase; classtype:trojan-activity; sid:100005308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8",nocase; classtype:trojan-activity; sid:100005309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100005310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100005311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8",nocase; classtype:trojan-activity; sid:100005312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100005313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100005314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100005315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100005316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g",nocase; classtype:trojan-activity; sid:100005317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum",nocase; classtype:trojan-activity; sid:100005318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi",nocase; classtype:trojan-activity; sid:100005319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy",nocase; classtype:trojan-activity; sid:100005320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o",nocase; classtype:trojan-activity; sid:100005321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa",nocase; classtype:trojan-activity; sid:100005322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100005323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100005324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc",nocase; classtype:trojan-activity; sid:100005325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk",nocase; classtype:trojan-activity; sid:100005326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea",nocase; classtype:trojan-activity; sid:100005327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100005328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100005329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100005330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100005331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100005332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100005333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo",nocase; classtype:trojan-activity; sid:100005334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva",nocase; classtype:trojan-activity; sid:100005335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc",nocase; classtype:trojan-activity; sid:100005336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles",nocase; classtype:trojan-activity; sid:100005337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg",nocase; classtype:trojan-activity; sid:100005338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100005339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100005340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100005341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100005342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw",nocase; classtype:trojan-activity; sid:100005343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8",nocase; classtype:trojan-activity; sid:100005344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq",nocase; classtype:trojan-activity; sid:100005345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug",nocase; classtype:trojan-activity; sid:100005346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua",nocase; classtype:trojan-activity; sid:100005347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe",nocase; classtype:trojan-activity; sid:100005348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa",nocase; classtype:trojan-activity; sid:100005349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe",nocase; classtype:trojan-activity; sid:100005350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4",nocase; classtype:trojan-activity; sid:100005351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa",nocase; classtype:trojan-activity; sid:100005352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w",nocase; classtype:trojan-activity; sid:100005353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo",nocase; classtype:trojan-activity; sid:100005354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4",nocase; classtype:trojan-activity; sid:100005355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa",nocase; classtype:trojan-activity; sid:100005356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w",nocase; classtype:trojan-activity; sid:100005357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo",nocase; classtype:trojan-activity; sid:100005358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi",nocase; classtype:trojan-activity; sid:100005359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e",nocase; classtype:trojan-activity; sid:100005360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100005361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100005362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk",nocase; classtype:trojan-activity; sid:100005363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4",nocase; classtype:trojan-activity; sid:100005364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo",nocase; classtype:trojan-activity; sid:100005365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji",nocase; classtype:trojan-activity; sid:100005366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100005367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100005368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg",nocase; classtype:trojan-activity; sid:100005369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70",nocase; classtype:trojan-activity; sid:100005370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc",nocase; classtype:trojan-activity; sid:100005371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100005372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100005373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100005374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100005375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw",nocase; classtype:trojan-activity; sid:100005376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq",nocase; classtype:trojan-activity; sid:100005377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm",nocase; classtype:trojan-activity; sid:100005378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100005379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100005380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8",nocase; classtype:trojan-activity; sid:100005381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100005382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100005383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!296&authkey=adsdrrjllbu1nwa",nocase; classtype:trojan-activity; sid:100005384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!297&authkey=am7nspchat4aqtw",nocase; classtype:trojan-activity; sid:100005385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21296&authkey=adsdrrjllbu1nwa",nocase; classtype:trojan-activity; sid:100005386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu",nocase; classtype:trojan-activity; sid:100005387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i",nocase; classtype:trojan-activity; sid:100005388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam",nocase; classtype:trojan-activity; sid:100005389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble",nocase; classtype:trojan-activity; sid:100005390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60",nocase; classtype:trojan-activity; sid:100005391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k",nocase; classtype:trojan-activity; sid:100005392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8",nocase; classtype:trojan-activity; sid:100005393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg",nocase; classtype:trojan-activity; sid:100005394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte",nocase; classtype:trojan-activity; sid:100005395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34",nocase; classtype:trojan-activity; sid:100005396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w",nocase; classtype:trojan-activity; sid:100005397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta",nocase; classtype:trojan-activity; sid:100005398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em",nocase; classtype:trojan-activity; sid:100005399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100005400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100005401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100005402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100005403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm",nocase; classtype:trojan-activity; sid:100005404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq",nocase; classtype:trojan-activity; sid:100005405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k",nocase; classtype:trojan-activity; sid:100005406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100005407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100005408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100005409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100005410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100005411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100005412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs",nocase; classtype:trojan-activity; sid:100005413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli",nocase; classtype:trojan-activity; sid:100005414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18",nocase; classtype:trojan-activity; sid:100005415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli",nocase; classtype:trojan-activity; sid:100005416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c",nocase; classtype:trojan-activity; sid:100005417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0",nocase; classtype:trojan-activity; sid:100005418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq",nocase; classtype:trojan-activity; sid:100005419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=80dabacd46496407&resid=80dabacd46496407%21124&authkey=abnj7t59iwijpdy",nocase; classtype:trojan-activity; sid:100005420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda",nocase; classtype:trojan-activity; sid:100005421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm",nocase; classtype:trojan-activity; sid:100005422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk",nocase; classtype:trojan-activity; sid:100005423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4",nocase; classtype:trojan-activity; sid:100005424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c",nocase; classtype:trojan-activity; sid:100005425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100005426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100005427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4",nocase; classtype:trojan-activity; sid:100005428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84",nocase; classtype:trojan-activity; sid:100005429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk",nocase; classtype:trojan-activity; sid:100005430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk",nocase; classtype:trojan-activity; sid:100005431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae",nocase; classtype:trojan-activity; sid:100005432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0",nocase; classtype:trojan-activity; sid:100005433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8",nocase; classtype:trojan-activity; sid:100005434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s",nocase; classtype:trojan-activity; sid:100005435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my",nocase; classtype:trojan-activity; sid:100005436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc",nocase; classtype:trojan-activity; sid:100005437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby",nocase; classtype:trojan-activity; sid:100005438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo",nocase; classtype:trojan-activity; sid:100005439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti",nocase; classtype:trojan-activity; sid:100005440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe",nocase; classtype:trojan-activity; sid:100005441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari",nocase; classtype:trojan-activity; sid:100005442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4",nocase; classtype:trojan-activity; sid:100005443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia",nocase; classtype:trojan-activity; sid:100005444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok",nocase; classtype:trojan-activity; sid:100005445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe",nocase; classtype:trojan-activity; sid:100005446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari",nocase; classtype:trojan-activity; sid:100005447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4",nocase; classtype:trojan-activity; sid:100005448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m",nocase; classtype:trojan-activity; sid:100005449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia",nocase; classtype:trojan-activity; sid:100005450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok",nocase; classtype:trojan-activity; sid:100005451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm",nocase; classtype:trojan-activity; sid:100005452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m",nocase; classtype:trojan-activity; sid:100005453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w",nocase; classtype:trojan-activity; sid:100005454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100005455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100005456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k",nocase; classtype:trojan-activity; sid:100005457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli",nocase; classtype:trojan-activity; sid:100005458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm",nocase; classtype:trojan-activity; sid:100005459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue",nocase; classtype:trojan-activity; sid:100005460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma",nocase; classtype:trojan-activity; sid:100005461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg",nocase; classtype:trojan-activity; sid:100005462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq",nocase; classtype:trojan-activity; sid:100005463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs",nocase; classtype:trojan-activity; sid:100005464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho",nocase; classtype:trojan-activity; sid:100005465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc",nocase; classtype:trojan-activity; sid:100005466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w",nocase; classtype:trojan-activity; sid:100005467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm",nocase; classtype:trojan-activity; sid:100005468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0",nocase; classtype:trojan-activity; sid:100005469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy",nocase; classtype:trojan-activity; sid:100005470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm",nocase; classtype:trojan-activity; sid:100005471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi",nocase; classtype:trojan-activity; sid:100005472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi",nocase; classtype:trojan-activity; sid:100005473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8",nocase; classtype:trojan-activity; sid:100005474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100005475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100005476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o",nocase; classtype:trojan-activity; sid:100005477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4",nocase; classtype:trojan-activity; sid:100005478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi",nocase; classtype:trojan-activity; sid:100005479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100005480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100005481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo",nocase; classtype:trojan-activity; sid:100005482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq",nocase; classtype:trojan-activity; sid:100005483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi",nocase; classtype:trojan-activity; sid:100005484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs",nocase; classtype:trojan-activity; sid:100005485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw",nocase; classtype:trojan-activity; sid:100005486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o",nocase; classtype:trojan-activity; sid:100005487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc",nocase; classtype:trojan-activity; sid:100005488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs",nocase; classtype:trojan-activity; sid:100005489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100005490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100005491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi",nocase; classtype:trojan-activity; sid:100005492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc",nocase; classtype:trojan-activity; sid:100005493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy",nocase; classtype:trojan-activity; sid:100005494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc",nocase; classtype:trojan-activity; sid:100005495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey",nocase; classtype:trojan-activity; sid:100005496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg",nocase; classtype:trojan-activity; sid:100005497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui",nocase; classtype:trojan-activity; sid:100005498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi",nocase; classtype:trojan-activity; sid:100005499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk",nocase; classtype:trojan-activity; sid:100005500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw",nocase; classtype:trojan-activity; sid:100005501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100005502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100005503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e",nocase; classtype:trojan-activity; sid:100005504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100005505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100005506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu",nocase; classtype:trojan-activity; sid:100005507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu",nocase; classtype:trojan-activity; sid:100005508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u",nocase; classtype:trojan-activity; sid:100005509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm",nocase; classtype:trojan-activity; sid:100005510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy",nocase; classtype:trojan-activity; sid:100005511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc",nocase; classtype:trojan-activity; sid:100005512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy",nocase; classtype:trojan-activity; sid:100005513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy",nocase; classtype:trojan-activity; sid:100005514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84",nocase; classtype:trojan-activity; sid:100005515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo",nocase; classtype:trojan-activity; sid:100005516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw",nocase; classtype:trojan-activity; sid:100005517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww",nocase; classtype:trojan-activity; sid:100005518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy",nocase; classtype:trojan-activity; sid:100005519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w",nocase; classtype:trojan-activity; sid:100005520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq",nocase; classtype:trojan-activity; sid:100005521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100005522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100005523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg",nocase; classtype:trojan-activity; sid:100005524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg",nocase; classtype:trojan-activity; sid:100005525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100005526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100005527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m",nocase; classtype:trojan-activity; sid:100005528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8",nocase; classtype:trojan-activity; sid:100005529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1045&authkey=aetgoeo_eku-6ba",nocase; classtype:trojan-activity; sid:100005530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211045&authkey=aetgoeo_eku-6ba",nocase; classtype:trojan-activity; sid:100005531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100005532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100005533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq",nocase; classtype:trojan-activity; sid:100005534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm",nocase; classtype:trojan-activity; sid:100005535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai",nocase; classtype:trojan-activity; sid:100005536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk",nocase; classtype:trojan-activity; sid:100005537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100005538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100005539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100005540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100005541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100005542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100005543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100005544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100005545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100005546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100005547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100005548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100005549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100005550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100005551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100005552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100005553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100005554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100005555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100005556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100005557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8",nocase; classtype:trojan-activity; sid:100005558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc",nocase; classtype:trojan-activity; sid:100005559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc",nocase; classtype:trojan-activity; sid:100005560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw",nocase; classtype:trojan-activity; sid:100005561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21122&authkey=ajqq2okqxfq8iuo",nocase; classtype:trojan-activity; sid:100005562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs",nocase; classtype:trojan-activity; sid:100005563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m",nocase; classtype:trojan-activity; sid:100005564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga",nocase; classtype:trojan-activity; sid:100005565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg",nocase; classtype:trojan-activity; sid:100005566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100005567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100005568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw",nocase; classtype:trojan-activity; sid:100005569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100005570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100005571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100005572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100005573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100005574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100005575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100005576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100005577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100005578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100005579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0",nocase; classtype:trojan-activity; sid:100005580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100005581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100005582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100005583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100005584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy",nocase; classtype:trojan-activity; sid:100005585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774!124&authkey=afq42wqejwvcv8o",nocase; classtype:trojan-activity; sid:100005586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774%21124&authkey=afq42wqejwvcv8o",nocase; classtype:trojan-activity; sid:100005587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe",nocase; classtype:trojan-activity; sid:100005588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq",nocase; classtype:trojan-activity; sid:100005589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4",nocase; classtype:trojan-activity; sid:100005590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq",nocase; classtype:trojan-activity; sid:100005591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100005592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100005593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100005594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100005595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100005596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100005597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo",nocase; classtype:trojan-activity; sid:100005598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo",nocase; classtype:trojan-activity; sid:100005599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw",nocase; classtype:trojan-activity; sid:100005600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0",nocase; classtype:trojan-activity; sid:100005601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4",nocase; classtype:trojan-activity; sid:100005602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs",nocase; classtype:trojan-activity; sid:100005603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0",nocase; classtype:trojan-activity; sid:100005604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q",nocase; classtype:trojan-activity; sid:100005605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100005606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100005607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc",nocase; classtype:trojan-activity; sid:100005608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc",nocase; classtype:trojan-activity; sid:100005609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0",nocase; classtype:trojan-activity; sid:100005610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c",nocase; classtype:trojan-activity; sid:100005611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4a3bd996f92bf71&resid=e4a3bd996f92bf71%211944&authkey=ao3lztaialsza88",nocase; classtype:trojan-activity; sid:100005612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg",nocase; classtype:trojan-activity; sid:100005613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100005614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100005615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq",nocase; classtype:trojan-activity; sid:100005616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom",nocase; classtype:trojan-activity; sid:100005617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da",nocase; classtype:trojan-activity; sid:100005618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100005619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100005620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0",nocase; classtype:trojan-activity; sid:100005621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100005622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100005623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai",nocase; classtype:trojan-activity; sid:100005624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc",nocase; classtype:trojan-activity; sid:100005625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8",nocase; classtype:trojan-activity; sid:100005626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns",nocase; classtype:trojan-activity; sid:100005627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8",nocase; classtype:trojan-activity; sid:100005628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4",nocase; classtype:trojan-activity; sid:100005629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100005630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100005631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100005632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100005633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100005634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100005635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0",nocase; classtype:trojan-activity; sid:100005636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw",nocase; classtype:trojan-activity; sid:100005637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e",nocase; classtype:trojan-activity; sid:100005638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu",nocase; classtype:trojan-activity; sid:100005639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq",nocase; classtype:trojan-activity; sid:100005640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k",nocase; classtype:trojan-activity; sid:100005641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie",nocase; classtype:trojan-activity; sid:100005642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c",nocase; classtype:trojan-activity; sid:100005643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g",nocase; classtype:trojan-activity; sid:100005644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta",nocase; classtype:trojan-activity; sid:100005645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100005646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao",nocase; classtype:trojan-activity; sid:100005647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk",nocase; classtype:trojan-activity; sid:100005648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100005649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk",nocase; classtype:trojan-activity; sid:100005650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw",nocase; classtype:trojan-activity; sid:100005651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty",nocase; classtype:trojan-activity; sid:100005652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22",nocase; classtype:trojan-activity; sid:100005653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100005654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100005655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100005656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100005657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f8d2350982acb14f&resid=f8d2350982acb14f%21140&authkey=ajo86idqg2jvzfq",nocase; classtype:trojan-activity; sid:100005658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc",nocase; classtype:trojan-activity; sid:100005659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu",nocase; classtype:trojan-activity; sid:100005660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw",nocase; classtype:trojan-activity; sid:100005661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!196&authkey=amm2av5ubkbhoru",nocase; classtype:trojan-activity; sid:100005662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!197&authkey=apnt4trskzjga_k",nocase; classtype:trojan-activity; sid:100005663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21196&authkey=amm2av5ubkbhoru",nocase; classtype:trojan-activity; sid:100005664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21197&authkey=apnt4trskzjga_k",nocase; classtype:trojan-activity; sid:100005665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100005666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100005667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100005668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100005669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100005670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100005671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg",nocase; classtype:trojan-activity; sid:100005672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100005673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm",nocase; classtype:trojan-activity; sid:100005674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100005675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/yqvsvlvq",nocase; classtype:trojan-activity; sid:100005676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pierreconsulting.info",nocase; http_uri; content:"/wp-admin/llc/mwcacs65xienqdp/",nocase; classtype:trojan-activity; sid:100005677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pioneiraagronegocio.com.br",nocase; http_uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/",nocase; classtype:trojan-activity; sid:100005678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skoda22.jpg",nocase; classtype:trojan-activity; sid:100005679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg",nocase; classtype:trojan-activity; sid:100005680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qjbutterflyevents.co.za",nocase; http_uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/",nocase; classtype:trojan-activity; sid:100005681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/maersk-bl+draft-copy-shipping-documents.ace",nocase; classtype:trojan-activity; sid:100005682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace",nocase; classtype:trojan-activity; sid:100005683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/purchasing+ordersigned+contractinv-30067121.ace",nocase; classtype:trojan-activity; sid:100005684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll",nocase; classtype:trojan-activity; sid:100005685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe",nocase; classtype:trojan-activity; sid:100005686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe",nocase; classtype:trojan-activity; sid:100005687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe",nocase; classtype:trojan-activity; sid:100005688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe",nocase; classtype:trojan-activity; sid:100005689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar",nocase; classtype:trojan-activity; sid:100005690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/myqseeaccount/one/main/one.htm",nocase; classtype:trojan-activity; sid:100005691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp",nocase; classtype:trojan-activity; sid:100005692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe",nocase; classtype:trojan-activity; sid:100005693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe",nocase; classtype:trojan-activity; sid:100005694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/tennc/webshell/master/other/small_shell.txt",nocase; classtype:trojan-activity; sid:100005695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.yeshen.com",nocase; http_uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe",nocase; classtype:trojan-activity; sid:100005696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sendspace.com",nocase; http_uri; content:"/pro/dl/q05z91",nocase; classtype:trojan-activity; sid:100005697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sites.google.com",nocase; http_uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0",nocase; classtype:trojan-activity; sid:100005698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt",nocase; classtype:trojan-activity; sid:100005699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt",nocase; classtype:trojan-activity; sid:100005700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt",nocase; classtype:trojan-activity; sid:100005701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt",nocase; classtype:trojan-activity; sid:100005702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt",nocase; classtype:trojan-activity; sid:100005703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt",nocase; classtype:trojan-activity; sid:100005704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt",nocase; classtype:trojan-activity; sid:100005705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg",nocase; classtype:trojan-activity; sid:100005706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt",nocase; classtype:trojan-activity; sid:100005707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt",nocase; classtype:trojan-activity; sid:100005708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technologydistilled.com",nocase; http_uri; content:"/a-nurse-ss8d9/z/",nocase; classtype:trojan-activity; sid:100005709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"truemerit.io",nocase; http_uri; content:"/databases/merit.php",nocase; classtype:trojan-activity; sid:100005710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsrv4.ws",nocase; http_uri; content:"/23.exe",nocase; classtype:trojan-activity; sid:100005711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"users.skynet.be",nocase; http_uri; content:"/crisanar/defis/jek_crackme1.7.zip",nocase; classtype:trojan-activity; sid:100005712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/amowvegfrt9ja/",nocase; classtype:trojan-activity; sid:100005713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/",nocase; classtype:trojan-activity; sid:100005714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100005715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100005716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe",nocase; classtype:trojan-activity; sid:100005717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb%5efr_ouverture.exe",nocase; classtype:trojan-activity; sid:100005718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb^fr_ouverture.exe",nocase; classtype:trojan-activity; sid:100005719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe",nocase; classtype:trojan-activity; sid:100005720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/151_155/tidex_-_short_stuff.exe",nocase; classtype:trojan-activity; sid:100005721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikileaks.org",nocase; http_uri; content:"/syria-files/attach/222/222051_instruction.zip",nocase; classtype:trojan-activity; sid:100005722; rev:1;)
diff --git a/urlhaus-filter-suricata-online.rules b/urlhaus-filter-suricata-online.rules
index 035f8484..f285402a 100644
--- a/urlhaus-filter-suricata-online.rules
+++ b/urlhaus-filter-suricata-online.rules
@@ -1,5 +1,5 @@
 # Title: Online Malicious URL Suricata Ruleset
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -7,5778 +7,5722 @@
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"0-24bpautomentes.hu"; classtype:trojan-activity; sid:100000001; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"0cl.sldov.ru"; classtype:trojan-activity; sid:100000002; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.11.234.99"; classtype:trojan-activity; sid:100000003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.222.140.251"; classtype:trojan-activity; sid:100000004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.222.166.69"; classtype:trojan-activity; sid:100000005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.186.151.219"; classtype:trojan-activity; sid:100000004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.222.140.251"; classtype:trojan-activity; sid:100000005; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.222.196.60"; classtype:trojan-activity; sid:100000006; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.245.4.163"; classtype:trojan-activity; sid:100000007; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.107"; classtype:trojan-activity; sid:100000008; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.109"; classtype:trojan-activity; sid:100000009; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.113"; classtype:trojan-activity; sid:100000010; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.127"; classtype:trojan-activity; sid:100000011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.134"; classtype:trojan-activity; sid:100000012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.14"; classtype:trojan-activity; sid:100000012; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.153"; classtype:trojan-activity; sid:100000013; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.16"; classtype:trojan-activity; sid:100000014; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.165"; classtype:trojan-activity; sid:100000015; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.228"; classtype:trojan-activity; sid:100000016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.234"; classtype:trojan-activity; sid:100000017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.237"; classtype:trojan-activity; sid:100000018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.245"; classtype:trojan-activity; sid:100000019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.249"; classtype:trojan-activity; sid:100000020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.25"; classtype:trojan-activity; sid:100000021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.38"; classtype:trojan-activity; sid:100000022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.41"; classtype:trojan-activity; sid:100000023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.43"; classtype:trojan-activity; sid:100000024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.45"; classtype:trojan-activity; sid:100000025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.56"; classtype:trojan-activity; sid:100000026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.69"; classtype:trojan-activity; sid:100000027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.8"; classtype:trojan-activity; sid:100000028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.80"; classtype:trojan-activity; sid:100000029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.98"; classtype:trojan-activity; sid:100000030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.10"; classtype:trojan-activity; sid:100000031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.103"; classtype:trojan-activity; sid:100000032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.105"; classtype:trojan-activity; sid:100000033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.126"; classtype:trojan-activity; sid:100000034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.127"; classtype:trojan-activity; sid:100000035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.130"; classtype:trojan-activity; sid:100000036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.146"; classtype:trojan-activity; sid:100000037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.148"; classtype:trojan-activity; sid:100000038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.15"; classtype:trojan-activity; sid:100000039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.151"; classtype:trojan-activity; sid:100000040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.18"; classtype:trojan-activity; sid:100000041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.32"; classtype:trojan-activity; sid:100000042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.35"; classtype:trojan-activity; sid:100000043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.4"; classtype:trojan-activity; sid:100000044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.48"; classtype:trojan-activity; sid:100000045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.49"; classtype:trojan-activity; sid:100000046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.54"; classtype:trojan-activity; sid:100000047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.59"; classtype:trojan-activity; sid:100000048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.6"; classtype:trojan-activity; sid:100000049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.61"; classtype:trojan-activity; sid:100000050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.71"; classtype:trojan-activity; sid:100000051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.83"; classtype:trojan-activity; sid:100000052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.94"; classtype:trojan-activity; sid:100000053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.247.221.141"; classtype:trojan-activity; sid:100000054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.247.221.142"; classtype:trojan-activity; sid:100000055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.250.159.41"; classtype:trojan-activity; sid:100000056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.252.102.28"; classtype:trojan-activity; sid:100000057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.254.250.52"; classtype:trojan-activity; sid:100000058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.60.77.53"; classtype:trojan-activity; sid:100000059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.65.166.225"; classtype:trojan-activity; sid:100000060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.82.104.89"; classtype:trojan-activity; sid:100000061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.12.184.63"; classtype:trojan-activity; sid:100000062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.2.131.143"; classtype:trojan-activity; sid:100000063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.8.77.4"; classtype:trojan-activity; sid:100000064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1008691.com"; classtype:trojan-activity; sid:100000065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.130.108"; classtype:trojan-activity; sid:100000066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.109.246.33"; classtype:trojan-activity; sid:100000067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.16.183.179"; classtype:trojan-activity; sid:100000068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.16.98.170"; classtype:trojan-activity; sid:100000069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.229.85.127"; classtype:trojan-activity; sid:100000070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.255.36.154"; classtype:trojan-activity; sid:100000071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.105.132"; classtype:trojan-activity; sid:100000072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.106.134"; classtype:trojan-activity; sid:100000073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.145.2"; classtype:trojan-activity; sid:100000074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.76.34"; classtype:trojan-activity; sid:100000075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.30.128.184"; classtype:trojan-activity; sid:100000076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.30.38.204"; classtype:trojan-activity; sid:100000077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.64.119.250"; classtype:trojan-activity; sid:100000078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.64.161.70"; classtype:trojan-activity; sid:100000079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.75.157.99"; classtype:trojan-activity; sid:100000080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.130.115.14"; classtype:trojan-activity; sid:100000081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.141.240.139"; classtype:trojan-activity; sid:100000082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.107.113.22"; classtype:trojan-activity; sid:100000083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.124.104.118"; classtype:trojan-activity; sid:100000084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.125.218.107"; classtype:trojan-activity; sid:100000085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.139.89.205"; classtype:trojan-activity; sid:100000086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.141.138.12"; classtype:trojan-activity; sid:100000087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.145.13.24"; classtype:trojan-activity; sid:100000088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.146.174.208"; classtype:trojan-activity; sid:100000089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.156.221.66"; classtype:trojan-activity; sid:100000090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.159.155.214"; classtype:trojan-activity; sid:100000091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.16.145.25"; classtype:trojan-activity; sid:100000092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.207.1.146"; classtype:trojan-activity; sid:100000093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.217.215.21"; classtype:trojan-activity; sid:100000094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.40"; classtype:trojan-activity; sid:100000095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.3"; classtype:trojan-activity; sid:100000096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.4"; classtype:trojan-activity; sid:100000097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.240.249.121"; classtype:trojan-activity; sid:100000098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.4.117.26"; classtype:trojan-activity; sid:100000099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.66.78.171"; classtype:trojan-activity; sid:100000100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.79.112.254"; classtype:trojan-activity; sid:100000101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.145.111"; classtype:trojan-activity; sid:100000102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.98.170"; classtype:trojan-activity; sid:100000103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.240.130"; classtype:trojan-activity; sid:100000104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.240.228"; classtype:trojan-activity; sid:100000105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.241.123"; classtype:trojan-activity; sid:100000106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.241.94"; classtype:trojan-activity; sid:100000107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.12"; classtype:trojan-activity; sid:100000108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.16"; classtype:trojan-activity; sid:100000109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.17"; classtype:trojan-activity; sid:100000110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.19"; classtype:trojan-activity; sid:100000111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.20"; classtype:trojan-activity; sid:100000112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.27"; classtype:trojan-activity; sid:100000113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.28"; classtype:trojan-activity; sid:100000114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.3"; classtype:trojan-activity; sid:100000115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.30"; classtype:trojan-activity; sid:100000116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.36"; classtype:trojan-activity; sid:100000117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.41"; classtype:trojan-activity; sid:100000118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.46"; classtype:trojan-activity; sid:100000119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.90"; classtype:trojan-activity; sid:100000120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.95"; classtype:trojan-activity; sid:100000121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.184.75.123"; classtype:trojan-activity; sid:100000122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.33.52.85"; classtype:trojan-activity; sid:100000123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.61.86.37"; classtype:trojan-activity; sid:100000124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.1.112.12"; classtype:trojan-activity; sid:100000125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.172.178"; classtype:trojan-activity; sid:100000126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.193.155"; classtype:trojan-activity; sid:100000127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.105.33.43"; classtype:trojan-activity; sid:100000128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.113.177.60"; classtype:trojan-activity; sid:100000129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.165.234"; classtype:trojan-activity; sid:100000130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.193.132"; classtype:trojan-activity; sid:100000131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.249.148"; classtype:trojan-activity; sid:100000132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.155.54"; classtype:trojan-activity; sid:100000133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.219.80"; classtype:trojan-activity; sid:100000134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.144.195"; classtype:trojan-activity; sid:100000135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.250.107"; classtype:trojan-activity; sid:100000136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.197.135"; classtype:trojan-activity; sid:100000137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.31.130"; classtype:trojan-activity; sid:100000138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.181.136.96"; classtype:trojan-activity; sid:100000139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.189.8.75"; classtype:trojan-activity; sid:100000140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.194.242.170"; classtype:trojan-activity; sid:100000141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.219.185.75"; classtype:trojan-activity; sid:100000142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.220.119.25"; classtype:trojan-activity; sid:100000143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.221.96.202"; classtype:trojan-activity; sid:100000144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.201.37"; classtype:trojan-activity; sid:100000145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.250.48"; classtype:trojan-activity; sid:100000146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.55.199.65"; classtype:trojan-activity; sid:100000147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.104.151.108"; classtype:trojan-activity; sid:100000148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.124.90.229"; classtype:trojan-activity; sid:100000149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.233.196.232"; classtype:trojan-activity; sid:100000150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.235.7.228"; classtype:trojan-activity; sid:100000151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.248.58.238"; classtype:trojan-activity; sid:100000152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.86.85.253"; classtype:trojan-activity; sid:100000153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.102"; classtype:trojan-activity; sid:100000154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.230"; classtype:trojan-activity; sid:100000155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.127.90"; classtype:trojan-activity; sid:100000156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.57.246"; classtype:trojan-activity; sid:100000157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.99.37.97"; classtype:trojan-activity; sid:100000158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.10.58.38"; classtype:trojan-activity; sid:100000159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.12.123.11"; classtype:trojan-activity; sid:100000160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.14.58.190"; classtype:trojan-activity; sid:100000161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.187.229.182"; classtype:trojan-activity; sid:100000162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.190.50"; classtype:trojan-activity; sid:100000163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.195.46"; classtype:trojan-activity; sid:100000164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.241.119.168"; classtype:trojan-activity; sid:100000165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.241.23.107"; classtype:trojan-activity; sid:100000166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.247.151.4"; classtype:trojan-activity; sid:100000167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.247.153.186"; classtype:trojan-activity; sid:100000168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.124.254"; classtype:trojan-activity; sid:100000169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.175.141"; classtype:trojan-activity; sid:100000170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.251.194"; classtype:trojan-activity; sid:100000171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.251.10.18"; classtype:trojan-activity; sid:100000172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.213.198"; classtype:trojan-activity; sid:100000173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.51.112"; classtype:trojan-activity; sid:100000174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.255.101.184"; classtype:trojan-activity; sid:100000175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.255.167.147"; classtype:trojan-activity; sid:100000176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.145.127"; classtype:trojan-activity; sid:100000177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.208.21"; classtype:trojan-activity; sid:100000178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.221.77"; classtype:trojan-activity; sid:100000179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.223.92"; classtype:trojan-activity; sid:100000180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.225.24"; classtype:trojan-activity; sid:100000181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.233.147"; classtype:trojan-activity; sid:100000182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.235.57"; classtype:trojan-activity; sid:100000183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.4.2"; classtype:trojan-activity; sid:100000184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110fss.net"; classtype:trojan-activity; sid:100000185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.88.61"; classtype:trojan-activity; sid:100000186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.119.245.114"; classtype:trojan-activity; sid:100000187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.125.67.125"; classtype:trojan-activity; sid:100000188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.162.224.14"; classtype:trojan-activity; sid:100000189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.163.50.120"; classtype:trojan-activity; sid:100000190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.165.21.195"; classtype:trojan-activity; sid:100000191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.165.28.234"; classtype:trojan-activity; sid:100000192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.84.182"; classtype:trojan-activity; sid:100000193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.86.133"; classtype:trojan-activity; sid:100000194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.172.164.104"; classtype:trojan-activity; sid:100000195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.176.182.149"; classtype:trojan-activity; sid:100000196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.179.153.69"; classtype:trojan-activity; sid:100000197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.179.243.126"; classtype:trojan-activity; sid:100000198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.182.232.18"; classtype:trojan-activity; sid:100000199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.177.85"; classtype:trojan-activity; sid:100000200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.23.84"; classtype:trojan-activity; sid:100000201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.230.136"; classtype:trojan-activity; sid:100000202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.27.9"; classtype:trojan-activity; sid:100000203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.48.248"; classtype:trojan-activity; sid:100000204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.114"; classtype:trojan-activity; sid:100000205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.122"; classtype:trojan-activity; sid:100000206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.13"; classtype:trojan-activity; sid:100000207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.66"; classtype:trojan-activity; sid:100000208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.141"; classtype:trojan-activity; sid:100000209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.165"; classtype:trojan-activity; sid:100000210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.128"; classtype:trojan-activity; sid:100000211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.19"; classtype:trojan-activity; sid:100000212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.48"; classtype:trojan-activity; sid:100000213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.222"; classtype:trojan-activity; sid:100000214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.223"; classtype:trojan-activity; sid:100000215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.228"; classtype:trojan-activity; sid:100000216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.15"; classtype:trojan-activity; sid:100000217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.184"; classtype:trojan-activity; sid:100000218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.197"; classtype:trojan-activity; sid:100000219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.200"; classtype:trojan-activity; sid:100000220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.23"; classtype:trojan-activity; sid:100000221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.26.243"; classtype:trojan-activity; sid:100000222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.8.81"; classtype:trojan-activity; sid:100000223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.61.52.53"; classtype:trojan-activity; sid:100000224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.105.117.227"; classtype:trojan-activity; sid:100000225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.100.236"; classtype:trojan-activity; sid:100000226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.108.184"; classtype:trojan-activity; sid:100000227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.31.175"; classtype:trojan-activity; sid:100000228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.122.62.224"; classtype:trojan-activity; sid:100000229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.123.200.47"; classtype:trojan-activity; sid:100000230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.132.134.106"; classtype:trojan-activity; sid:100000231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.132.147.102"; classtype:trojan-activity; sid:100000232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.159.108.96"; classtype:trojan-activity; sid:100000233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.124.75"; classtype:trojan-activity; sid:100000234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.219.168"; classtype:trojan-activity; sid:100000235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.233.9"; classtype:trojan-activity; sid:100000236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.210.211"; classtype:trojan-activity; sid:100000237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.96.252"; classtype:trojan-activity; sid:100000238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.187.91.117"; classtype:trojan-activity; sid:100000239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.214.127.42"; classtype:trojan-activity; sid:100000240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.187.19"; classtype:trojan-activity; sid:100000241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.236.77"; classtype:trojan-activity; sid:100000242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.43.27"; classtype:trojan-activity; sid:100000243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.52.145"; classtype:trojan-activity; sid:100000244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.82.4"; classtype:trojan-activity; sid:100000245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.118.229"; classtype:trojan-activity; sid:100000246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.176.167"; classtype:trojan-activity; sid:100000247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.195.104"; classtype:trojan-activity; sid:100000248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.202.111"; classtype:trojan-activity; sid:100000249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.205.96"; classtype:trojan-activity; sid:100000250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.67.193"; classtype:trojan-activity; sid:100000251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.92.34"; classtype:trojan-activity; sid:100000252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.180.95"; classtype:trojan-activity; sid:100000253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.114"; classtype:trojan-activity; sid:100000254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.137"; classtype:trojan-activity; sid:100000255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.178.109"; classtype:trojan-activity; sid:100000256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.188.28"; classtype:trojan-activity; sid:100000257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.199.19"; classtype:trojan-activity; sid:100000258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.230.251.85"; classtype:trojan-activity; sid:100000259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.121.107"; classtype:trojan-activity; sid:100000260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.134.244"; classtype:trojan-activity; sid:100000261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.16.252"; classtype:trojan-activity; sid:100000262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.194.178"; classtype:trojan-activity; sid:100000263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.216.151"; classtype:trojan-activity; sid:100000264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.218.202"; classtype:trojan-activity; sid:100000265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.149.73"; classtype:trojan-activity; sid:100000266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.188.86"; classtype:trojan-activity; sid:100000267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.126.177"; classtype:trojan-activity; sid:100000268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.171.69"; classtype:trojan-activity; sid:100000269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.228.21"; classtype:trojan-activity; sid:100000270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.141.241"; classtype:trojan-activity; sid:100000271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.144.226"; classtype:trojan-activity; sid:100000272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.172.106"; classtype:trojan-activity; sid:100000273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.197.144"; classtype:trojan-activity; sid:100000274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.230.192"; classtype:trojan-activity; sid:100000275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.75.157"; classtype:trojan-activity; sid:100000276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.143.135"; classtype:trojan-activity; sid:100000277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.17.120"; classtype:trojan-activity; sid:100000278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.190.207"; classtype:trojan-activity; sid:100000279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.194.18"; classtype:trojan-activity; sid:100000280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.227.228"; classtype:trojan-activity; sid:100000281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.39.2"; classtype:trojan-activity; sid:100000282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.73.181"; classtype:trojan-activity; sid:100000283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.184.162"; classtype:trojan-activity; sid:100000284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.216.17"; classtype:trojan-activity; sid:100000285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.241.187.165"; classtype:trojan-activity; sid:100000286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.106.228"; classtype:trojan-activity; sid:100000287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.18.128"; classtype:trojan-activity; sid:100000288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.2.247"; classtype:trojan-activity; sid:100000289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.243.115.183"; classtype:trojan-activity; sid:100000290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.12.89"; classtype:trojan-activity; sid:100000291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.5.141"; classtype:trojan-activity; sid:100000292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.8.24"; classtype:trojan-activity; sid:100000293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.162.50"; classtype:trojan-activity; sid:100000294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.180.49"; classtype:trojan-activity; sid:100000295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.100.14"; classtype:trojan-activity; sid:100000296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.14.135"; classtype:trojan-activity; sid:100000297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.161.45"; classtype:trojan-activity; sid:100000298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.191.118"; classtype:trojan-activity; sid:100000299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.214.146"; classtype:trojan-activity; sid:100000300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.240.226"; classtype:trojan-activity; sid:100000301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.81.173"; classtype:trojan-activity; sid:100000302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.82.122"; classtype:trojan-activity; sid:100000303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.148.90"; classtype:trojan-activity; sid:100000304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.179.239"; classtype:trojan-activity; sid:100000305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.197.164"; classtype:trojan-activity; sid:100000306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.44.153"; classtype:trojan-activity; sid:100000307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.109.217"; classtype:trojan-activity; sid:100000308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.118.157"; classtype:trojan-activity; sid:100000309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.165.240"; classtype:trojan-activity; sid:100000310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.206.69"; classtype:trojan-activity; sid:100000311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.26.129"; classtype:trojan-activity; sid:100000312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.41.142"; classtype:trojan-activity; sid:100000313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.79.98"; classtype:trojan-activity; sid:100000314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.102.173"; classtype:trojan-activity; sid:100000315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.57.99"; classtype:trojan-activity; sid:100000316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.17.5"; classtype:trojan-activity; sid:100000317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.218.210"; classtype:trojan-activity; sid:100000318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.23.55"; classtype:trojan-activity; sid:100000319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.136.84"; classtype:trojan-activity; sid:100000320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.199.150"; classtype:trojan-activity; sid:100000321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.221.244"; classtype:trojan-activity; sid:100000322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.239.103"; classtype:trojan-activity; sid:100000323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.245.249"; classtype:trojan-activity; sid:100000324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.46.212"; classtype:trojan-activity; sid:100000325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.208.123"; classtype:trojan-activity; sid:100000326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.32.5"; classtype:trojan-activity; sid:100000327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.127.212"; classtype:trojan-activity; sid:100000328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.38.10"; classtype:trojan-activity; sid:100000329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.6.129"; classtype:trojan-activity; sid:100000330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.8.235"; classtype:trojan-activity; sid:100000331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.121.163"; classtype:trojan-activity; sid:100000332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.123.174"; classtype:trojan-activity; sid:100000333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.109"; classtype:trojan-activity; sid:100000334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.110"; classtype:trojan-activity; sid:100000335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.111"; classtype:trojan-activity; sid:100000336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.112"; classtype:trojan-activity; sid:100000337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.113"; classtype:trojan-activity; sid:100000338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.117"; classtype:trojan-activity; sid:100000339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.119"; classtype:trojan-activity; sid:100000340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.120"; classtype:trojan-activity; sid:100000341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.122"; classtype:trojan-activity; sid:100000342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.124"; classtype:trojan-activity; sid:100000343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.127"; classtype:trojan-activity; sid:100000344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.128"; classtype:trojan-activity; sid:100000345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.130"; classtype:trojan-activity; sid:100000346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.131"; classtype:trojan-activity; sid:100000347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.132"; classtype:trojan-activity; sid:100000348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.133"; classtype:trojan-activity; sid:100000349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.136"; classtype:trojan-activity; sid:100000350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.138"; classtype:trojan-activity; sid:100000351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.139"; classtype:trojan-activity; sid:100000352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.140"; classtype:trojan-activity; sid:100000353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.142"; classtype:trojan-activity; sid:100000354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.143"; classtype:trojan-activity; sid:100000355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.146"; classtype:trojan-activity; sid:100000356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.149"; classtype:trojan-activity; sid:100000357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.150"; classtype:trojan-activity; sid:100000358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.151"; classtype:trojan-activity; sid:100000359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.155"; classtype:trojan-activity; sid:100000360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.158"; classtype:trojan-activity; sid:100000361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.160"; classtype:trojan-activity; sid:100000362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.162"; classtype:trojan-activity; sid:100000363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.163"; classtype:trojan-activity; sid:100000364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.165"; classtype:trojan-activity; sid:100000365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.168"; classtype:trojan-activity; sid:100000366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.171"; classtype:trojan-activity; sid:100000367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.172"; classtype:trojan-activity; sid:100000368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.175"; classtype:trojan-activity; sid:100000369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.176"; classtype:trojan-activity; sid:100000370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.178"; classtype:trojan-activity; sid:100000371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.179"; classtype:trojan-activity; sid:100000372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.71"; classtype:trojan-activity; sid:100000373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.126.243"; classtype:trojan-activity; sid:100000374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.127.155"; classtype:trojan-activity; sid:100000375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.120"; classtype:trojan-activity; sid:100000376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.121"; classtype:trojan-activity; sid:100000377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.82.29"; classtype:trojan-activity; sid:100000378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.182"; classtype:trojan-activity; sid:100000379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.23"; classtype:trojan-activity; sid:100000380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.85.113"; classtype:trojan-activity; sid:100000381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.87.203"; classtype:trojan-activity; sid:100000382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.87.213"; classtype:trojan-activity; sid:100000383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.88.116"; classtype:trojan-activity; sid:100000384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.212"; classtype:trojan-activity; sid:100000385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.247"; classtype:trojan-activity; sid:100000386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.149"; classtype:trojan-activity; sid:100000387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.150"; classtype:trojan-activity; sid:100000388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.158"; classtype:trojan-activity; sid:100000389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.159"; classtype:trojan-activity; sid:100000390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.168"; classtype:trojan-activity; sid:100000391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.177"; classtype:trojan-activity; sid:100000392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.178"; classtype:trojan-activity; sid:100000393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.181"; classtype:trojan-activity; sid:100000394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.188"; classtype:trojan-activity; sid:100000395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.190"; classtype:trojan-activity; sid:100000396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.197"; classtype:trojan-activity; sid:100000397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.211"; classtype:trojan-activity; sid:100000398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.219"; classtype:trojan-activity; sid:100000399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.229"; classtype:trojan-activity; sid:100000400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.230"; classtype:trojan-activity; sid:100000401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.245"; classtype:trojan-activity; sid:100000402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.247"; classtype:trojan-activity; sid:100000403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.54"; classtype:trojan-activity; sid:100000404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.55"; classtype:trojan-activity; sid:100000405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.57"; classtype:trojan-activity; sid:100000406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.60"; classtype:trojan-activity; sid:100000407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.90"; classtype:trojan-activity; sid:100000408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.91"; classtype:trojan-activity; sid:100000409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.100.228"; classtype:trojan-activity; sid:100000410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.27"; classtype:trojan-activity; sid:100000411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.30"; classtype:trojan-activity; sid:100000412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.31"; classtype:trojan-activity; sid:100000413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.37"; classtype:trojan-activity; sid:100000414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.38"; classtype:trojan-activity; sid:100000415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.41"; classtype:trojan-activity; sid:100000416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.42"; classtype:trojan-activity; sid:100000417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.43"; classtype:trojan-activity; sid:100000418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.45"; classtype:trojan-activity; sid:100000419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.52"; classtype:trojan-activity; sid:100000420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.57"; classtype:trojan-activity; sid:100000421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.58"; classtype:trojan-activity; sid:100000422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.60"; classtype:trojan-activity; sid:100000423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.62"; classtype:trojan-activity; sid:100000424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.126.156"; classtype:trojan-activity; sid:100000425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.35.237"; classtype:trojan-activity; sid:100000426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.38.100"; classtype:trojan-activity; sid:100000427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.38.19"; classtype:trojan-activity; sid:100000428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.118"; classtype:trojan-activity; sid:100000429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.119"; classtype:trojan-activity; sid:100000430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.121"; classtype:trojan-activity; sid:100000431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.136"; classtype:trojan-activity; sid:100000432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.37"; classtype:trojan-activity; sid:100000433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.52"; classtype:trojan-activity; sid:100000434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.57"; classtype:trojan-activity; sid:100000435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.61"; classtype:trojan-activity; sid:100000436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.70"; classtype:trojan-activity; sid:100000437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.73"; classtype:trojan-activity; sid:100000438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.77"; classtype:trojan-activity; sid:100000439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.90"; classtype:trojan-activity; sid:100000440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.176.16"; classtype:trojan-activity; sid:100000441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.211.135"; classtype:trojan-activity; sid:100000442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.82.160"; classtype:trojan-activity; sid:100000443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.224.79"; classtype:trojan-activity; sid:100000444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.65.53.175"; classtype:trojan-activity; sid:100000445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.153.37"; classtype:trojan-activity; sid:100000446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.159"; classtype:trojan-activity; sid:100000447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.49"; classtype:trojan-activity; sid:100000448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.53"; classtype:trojan-activity; sid:100000449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.112"; classtype:trojan-activity; sid:100000450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.84"; classtype:trojan-activity; sid:100000451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.78.45.158"; classtype:trojan-activity; sid:100000452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.118.16"; classtype:trojan-activity; sid:100000453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.127.91"; classtype:trojan-activity; sid:100000454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.215.101"; classtype:trojan-activity; sid:100000455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.81.161.10"; classtype:trojan-activity; sid:100000456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.81.199.218"; classtype:trojan-activity; sid:100000457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.131.124"; classtype:trojan-activity; sid:100000458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.146.253"; classtype:trojan-activity; sid:100000459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.18.255"; classtype:trojan-activity; sid:100000460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.224.139"; classtype:trojan-activity; sid:100000461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.227.41"; classtype:trojan-activity; sid:100000462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.228.175"; classtype:trojan-activity; sid:100000463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.83.118.203"; classtype:trojan-activity; sid:100000464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.83.230.37"; classtype:trojan-activity; sid:100000465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.86.133.125"; classtype:trojan-activity; sid:100000466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.9.140.247"; classtype:trojan-activity; sid:100000467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.91.219.195"; classtype:trojan-activity; sid:100000468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.93.29.211"; classtype:trojan-activity; sid:100000469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.95.80.165"; classtype:trojan-activity; sid:100000470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.0.74.25"; classtype:trojan-activity; sid:100000471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.11.95.254"; classtype:trojan-activity; sid:100000472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.110.204.254"; classtype:trojan-activity; sid:100000473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.110.243.79"; classtype:trojan-activity; sid:100000474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.150.147"; classtype:trojan-activity; sid:100000475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.176.26"; classtype:trojan-activity; sid:100000476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.44.33"; classtype:trojan-activity; sid:100000477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.89.82"; classtype:trojan-activity; sid:100000478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.118.13.194"; classtype:trojan-activity; sid:100000479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.118.133.113"; classtype:trojan-activity; sid:100000480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.118.250.227"; classtype:trojan-activity; sid:100000481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.118.6.104"; classtype:trojan-activity; sid:100000482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.238.68"; classtype:trojan-activity; sid:100000483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.59.84"; classtype:trojan-activity; sid:100000484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.58.249"; classtype:trojan-activity; sid:100000485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.172.250.35"; classtype:trojan-activity; sid:100000486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.189.243.248"; classtype:trojan-activity; sid:100000487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.194.133.9"; classtype:trojan-activity; sid:100000488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.194.135.154"; classtype:trojan-activity; sid:100000489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.163.26"; classtype:trojan-activity; sid:100000490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.166.46"; classtype:trojan-activity; sid:100000491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.168.190"; classtype:trojan-activity; sid:100000492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.201.219.47"; classtype:trojan-activity; sid:100000493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.225.171.27"; classtype:trojan-activity; sid:100000494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.226.42.250"; classtype:trojan-activity; sid:100000495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.128.9"; classtype:trojan-activity; sid:100000496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.169.170"; classtype:trojan-activity; sid:100000497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.194.172"; classtype:trojan-activity; sid:100000498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.35.229"; classtype:trojan-activity; sid:100000499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.211.131"; classtype:trojan-activity; sid:100000500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.93.142"; classtype:trojan-activity; sid:100000501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.232.211.182"; classtype:trojan-activity; sid:100000502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.234.224.130"; classtype:trojan-activity; sid:100000503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.235.116.209"; classtype:trojan-activity; sid:100000504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.253.144.141"; classtype:trojan-activity; sid:100000505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.254.169.251"; classtype:trojan-activity; sid:100000506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.128.133"; classtype:trojan-activity; sid:100000507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.133.16"; classtype:trojan-activity; sid:100000508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.144.42"; classtype:trojan-activity; sid:100000509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.154.21"; classtype:trojan-activity; sid:100000510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.191.47"; classtype:trojan-activity; sid:100000511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.61.204.205"; classtype:trojan-activity; sid:100000512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.86.204.13"; classtype:trojan-activity; sid:100000513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.87.203.239"; classtype:trojan-activity; sid:100000514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.87.227.222"; classtype:trojan-activity; sid:100000515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.100.120"; classtype:trojan-activity; sid:100000516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.104.194"; classtype:trojan-activity; sid:100000517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.111.36"; classtype:trojan-activity; sid:100000518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.209.47"; classtype:trojan-activity; sid:100000519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.232.36"; classtype:trojan-activity; sid:100000520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.38.232"; classtype:trojan-activity; sid:100000521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.232"; classtype:trojan-activity; sid:100000017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.234"; classtype:trojan-activity; sid:100000018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.237"; classtype:trojan-activity; sid:100000019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.245"; classtype:trojan-activity; sid:100000020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.249"; classtype:trojan-activity; sid:100000021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.25"; classtype:trojan-activity; sid:100000022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.38"; classtype:trojan-activity; sid:100000023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.41"; classtype:trojan-activity; sid:100000024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.43"; classtype:trojan-activity; sid:100000025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.45"; classtype:trojan-activity; sid:100000026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.56"; classtype:trojan-activity; sid:100000027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.69"; classtype:trojan-activity; sid:100000028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.8"; classtype:trojan-activity; sid:100000029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.80"; classtype:trojan-activity; sid:100000030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.94"; classtype:trojan-activity; sid:100000031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.98"; classtype:trojan-activity; sid:100000032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.10"; classtype:trojan-activity; sid:100000033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.103"; classtype:trojan-activity; sid:100000034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.105"; classtype:trojan-activity; sid:100000035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.126"; classtype:trojan-activity; sid:100000036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.127"; classtype:trojan-activity; sid:100000037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.130"; classtype:trojan-activity; sid:100000038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.146"; classtype:trojan-activity; sid:100000039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.148"; classtype:trojan-activity; sid:100000040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.15"; classtype:trojan-activity; sid:100000041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.151"; classtype:trojan-activity; sid:100000042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.18"; classtype:trojan-activity; sid:100000043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.32"; classtype:trojan-activity; sid:100000044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.35"; classtype:trojan-activity; sid:100000045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.4"; classtype:trojan-activity; sid:100000046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.49"; classtype:trojan-activity; sid:100000047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.54"; classtype:trojan-activity; sid:100000048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.58"; classtype:trojan-activity; sid:100000049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.59"; classtype:trojan-activity; sid:100000050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.6"; classtype:trojan-activity; sid:100000051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.61"; classtype:trojan-activity; sid:100000052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.71"; classtype:trojan-activity; sid:100000053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.83"; classtype:trojan-activity; sid:100000054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.94"; classtype:trojan-activity; sid:100000055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.247.221.141"; classtype:trojan-activity; sid:100000056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.247.221.142"; classtype:trojan-activity; sid:100000057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.250.159.41"; classtype:trojan-activity; sid:100000058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.252.102.28"; classtype:trojan-activity; sid:100000059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.254.250.52"; classtype:trojan-activity; sid:100000060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.60.77.53"; classtype:trojan-activity; sid:100000061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.65.166.225"; classtype:trojan-activity; sid:100000062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.82.104.89"; classtype:trojan-activity; sid:100000063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.12.184.63"; classtype:trojan-activity; sid:100000064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.2.131.143"; classtype:trojan-activity; sid:100000065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.8.77.4"; classtype:trojan-activity; sid:100000066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1008691.com"; classtype:trojan-activity; sid:100000067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.130.108"; classtype:trojan-activity; sid:100000068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.16.183.179"; classtype:trojan-activity; sid:100000069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.16.98.170"; classtype:trojan-activity; sid:100000070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.229.85.127"; classtype:trojan-activity; sid:100000071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.255.36.154"; classtype:trojan-activity; sid:100000072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.105.132"; classtype:trojan-activity; sid:100000073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.106.134"; classtype:trojan-activity; sid:100000074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.145.2"; classtype:trojan-activity; sid:100000075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.76.34"; classtype:trojan-activity; sid:100000076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.30.128.184"; classtype:trojan-activity; sid:100000077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.30.38.204"; classtype:trojan-activity; sid:100000078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.64.119.250"; classtype:trojan-activity; sid:100000079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.64.161.70"; classtype:trojan-activity; sid:100000080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.66.81.70"; classtype:trojan-activity; sid:100000081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.75.157.99"; classtype:trojan-activity; sid:100000082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.130.115.14"; classtype:trojan-activity; sid:100000083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.141.240.139"; classtype:trojan-activity; sid:100000084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.107.113.22"; classtype:trojan-activity; sid:100000085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.124.104.118"; classtype:trojan-activity; sid:100000086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.125.218.107"; classtype:trojan-activity; sid:100000087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.126.35.40"; classtype:trojan-activity; sid:100000088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.139.89.205"; classtype:trojan-activity; sid:100000089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.141.138.12"; classtype:trojan-activity; sid:100000090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.145.13.24"; classtype:trojan-activity; sid:100000091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.146.174.208"; classtype:trojan-activity; sid:100000092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.153.92.76"; classtype:trojan-activity; sid:100000093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.156.221.66"; classtype:trojan-activity; sid:100000094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.159.155.214"; classtype:trojan-activity; sid:100000095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.16.145.25"; classtype:trojan-activity; sid:100000096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.207.1.146"; classtype:trojan-activity; sid:100000097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.214.191.141"; classtype:trojan-activity; sid:100000098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.217.215.21"; classtype:trojan-activity; sid:100000099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.40"; classtype:trojan-activity; sid:100000100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.3"; classtype:trojan-activity; sid:100000101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.4"; classtype:trojan-activity; sid:100000102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.240.249.121"; classtype:trojan-activity; sid:100000103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.245.49.180"; classtype:trojan-activity; sid:100000104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.4.117.26"; classtype:trojan-activity; sid:100000105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.66.78.171"; classtype:trojan-activity; sid:100000106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.79.112.254"; classtype:trojan-activity; sid:100000107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.98.170"; classtype:trojan-activity; sid:100000108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.240.130"; classtype:trojan-activity; sid:100000109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.240.228"; classtype:trojan-activity; sid:100000110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.241.123"; classtype:trojan-activity; sid:100000111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.241.94"; classtype:trojan-activity; sid:100000112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.12"; classtype:trojan-activity; sid:100000113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.14"; classtype:trojan-activity; sid:100000114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.16"; classtype:trojan-activity; sid:100000115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.17"; classtype:trojan-activity; sid:100000116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.19"; classtype:trojan-activity; sid:100000117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.20"; classtype:trojan-activity; sid:100000118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.27"; classtype:trojan-activity; sid:100000119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.28"; classtype:trojan-activity; sid:100000120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.3"; classtype:trojan-activity; sid:100000121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.30"; classtype:trojan-activity; sid:100000122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.36"; classtype:trojan-activity; sid:100000123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.41"; classtype:trojan-activity; sid:100000124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.46"; classtype:trojan-activity; sid:100000125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.49"; classtype:trojan-activity; sid:100000126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.54"; classtype:trojan-activity; sid:100000127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.58"; classtype:trojan-activity; sid:100000128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.90"; classtype:trojan-activity; sid:100000129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.95"; classtype:trojan-activity; sid:100000130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.184.75.123"; classtype:trojan-activity; sid:100000131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.33.52.85"; classtype:trojan-activity; sid:100000132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.61.86.37"; classtype:trojan-activity; sid:100000133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.1.112.12"; classtype:trojan-activity; sid:100000134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.172.178"; classtype:trojan-activity; sid:100000135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.193.155"; classtype:trojan-activity; sid:100000136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.105.33.43"; classtype:trojan-activity; sid:100000137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.113.177.60"; classtype:trojan-activity; sid:100000138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.165.234"; classtype:trojan-activity; sid:100000139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.193.132"; classtype:trojan-activity; sid:100000140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.249.148"; classtype:trojan-activity; sid:100000141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.155.54"; classtype:trojan-activity; sid:100000142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.219.80"; classtype:trojan-activity; sid:100000143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.144.195"; classtype:trojan-activity; sid:100000144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.250.107"; classtype:trojan-activity; sid:100000145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.197.135"; classtype:trojan-activity; sid:100000146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.31.130"; classtype:trojan-activity; sid:100000147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.181.136.96"; classtype:trojan-activity; sid:100000148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.189.8.75"; classtype:trojan-activity; sid:100000149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.194.242.170"; classtype:trojan-activity; sid:100000150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.219.185.75"; classtype:trojan-activity; sid:100000151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.220.119.25"; classtype:trojan-activity; sid:100000152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.221.96.202"; classtype:trojan-activity; sid:100000153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.201.37"; classtype:trojan-activity; sid:100000154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.250.48"; classtype:trojan-activity; sid:100000155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.55.199.65"; classtype:trojan-activity; sid:100000156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.104.151.108"; classtype:trojan-activity; sid:100000157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.124.90.229"; classtype:trojan-activity; sid:100000158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.233.196.232"; classtype:trojan-activity; sid:100000159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.235.7.228"; classtype:trojan-activity; sid:100000160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.86.85.253"; classtype:trojan-activity; sid:100000161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.102"; classtype:trojan-activity; sid:100000162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.230"; classtype:trojan-activity; sid:100000163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.127.90"; classtype:trojan-activity; sid:100000164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.57.246"; classtype:trojan-activity; sid:100000165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.99.37.97"; classtype:trojan-activity; sid:100000166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.10.58.38"; classtype:trojan-activity; sid:100000167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.12.123.11"; classtype:trojan-activity; sid:100000168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.14.58.190"; classtype:trojan-activity; sid:100000169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.187.229.182"; classtype:trojan-activity; sid:100000170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.190.50"; classtype:trojan-activity; sid:100000171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.195.46"; classtype:trojan-activity; sid:100000172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.241.119.168"; classtype:trojan-activity; sid:100000173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.241.23.107"; classtype:trojan-activity; sid:100000174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.247.151.4"; classtype:trojan-activity; sid:100000175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.247.153.186"; classtype:trojan-activity; sid:100000176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.124.254"; classtype:trojan-activity; sid:100000177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.175.141"; classtype:trojan-activity; sid:100000178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.251.194"; classtype:trojan-activity; sid:100000179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.251.10.18"; classtype:trojan-activity; sid:100000180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.213.198"; classtype:trojan-activity; sid:100000181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.51.112"; classtype:trojan-activity; sid:100000182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.255.101.184"; classtype:trojan-activity; sid:100000183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.255.167.147"; classtype:trojan-activity; sid:100000184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.145.127"; classtype:trojan-activity; sid:100000185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.209.175"; classtype:trojan-activity; sid:100000186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.221.77"; classtype:trojan-activity; sid:100000187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.235.57"; classtype:trojan-activity; sid:100000188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.4.2"; classtype:trojan-activity; sid:100000189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110fss.net"; classtype:trojan-activity; sid:100000190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.111.207"; classtype:trojan-activity; sid:100000191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.88.61"; classtype:trojan-activity; sid:100000192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.119.245.114"; classtype:trojan-activity; sid:100000193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.125.67.125"; classtype:trojan-activity; sid:100000194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.162.224.14"; classtype:trojan-activity; sid:100000195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.163.50.120"; classtype:trojan-activity; sid:100000196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.165.21.195"; classtype:trojan-activity; sid:100000197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.165.28.234"; classtype:trojan-activity; sid:100000198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.84.182"; classtype:trojan-activity; sid:100000199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.86.133"; classtype:trojan-activity; sid:100000200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.172.164.104"; classtype:trojan-activity; sid:100000201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.176.182.149"; classtype:trojan-activity; sid:100000202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.179.153.69"; classtype:trojan-activity; sid:100000203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.179.243.126"; classtype:trojan-activity; sid:100000204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.182.232.18"; classtype:trojan-activity; sid:100000205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.177.85"; classtype:trojan-activity; sid:100000206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.23.84"; classtype:trojan-activity; sid:100000207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.230.136"; classtype:trojan-activity; sid:100000208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.27.9"; classtype:trojan-activity; sid:100000209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.48.248"; classtype:trojan-activity; sid:100000210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.114"; classtype:trojan-activity; sid:100000211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.122"; classtype:trojan-activity; sid:100000212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.13"; classtype:trojan-activity; sid:100000213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.66"; classtype:trojan-activity; sid:100000214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.141"; classtype:trojan-activity; sid:100000215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.165"; classtype:trojan-activity; sid:100000216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.128"; classtype:trojan-activity; sid:100000217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.19"; classtype:trojan-activity; sid:100000218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.48"; classtype:trojan-activity; sid:100000219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.222"; classtype:trojan-activity; sid:100000220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.223"; classtype:trojan-activity; sid:100000221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.228"; classtype:trojan-activity; sid:100000222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.15"; classtype:trojan-activity; sid:100000223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.184"; classtype:trojan-activity; sid:100000224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.197"; classtype:trojan-activity; sid:100000225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.200"; classtype:trojan-activity; sid:100000226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.23"; classtype:trojan-activity; sid:100000227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.26.243"; classtype:trojan-activity; sid:100000228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.8.81"; classtype:trojan-activity; sid:100000229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.61.52.53"; classtype:trojan-activity; sid:100000230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.108.184"; classtype:trojan-activity; sid:100000231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.31.175"; classtype:trojan-activity; sid:100000232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.122.62.224"; classtype:trojan-activity; sid:100000233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.122.63.70"; classtype:trojan-activity; sid:100000234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.132.134.106"; classtype:trojan-activity; sid:100000235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.132.147.102"; classtype:trojan-activity; sid:100000236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.159.108.96"; classtype:trojan-activity; sid:100000237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.167.165.139"; classtype:trojan-activity; sid:100000238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.124.75"; classtype:trojan-activity; sid:100000239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.233.9"; classtype:trojan-activity; sid:100000240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.210.211"; classtype:trojan-activity; sid:100000241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.96.252"; classtype:trojan-activity; sid:100000242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.187.91.117"; classtype:trojan-activity; sid:100000243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.214.127.42"; classtype:trojan-activity; sid:100000244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.187.19"; classtype:trojan-activity; sid:100000245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.236.77"; classtype:trojan-activity; sid:100000246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.43.27"; classtype:trojan-activity; sid:100000247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.52.145"; classtype:trojan-activity; sid:100000248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.82.4"; classtype:trojan-activity; sid:100000249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.118.229"; classtype:trojan-activity; sid:100000250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.195.104"; classtype:trojan-activity; sid:100000251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.202.111"; classtype:trojan-activity; sid:100000252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.67.193"; classtype:trojan-activity; sid:100000253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.92.34"; classtype:trojan-activity; sid:100000254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.180.95"; classtype:trojan-activity; sid:100000255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.114"; classtype:trojan-activity; sid:100000256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.137"; classtype:trojan-activity; sid:100000257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.178.109"; classtype:trojan-activity; sid:100000258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.188.28"; classtype:trojan-activity; sid:100000259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.199.19"; classtype:trojan-activity; sid:100000260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.230.251.85"; classtype:trojan-activity; sid:100000261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.134.244"; classtype:trojan-activity; sid:100000262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.16.252"; classtype:trojan-activity; sid:100000263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.194.178"; classtype:trojan-activity; sid:100000264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.216.151"; classtype:trojan-activity; sid:100000265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.218.202"; classtype:trojan-activity; sid:100000266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.149.73"; classtype:trojan-activity; sid:100000267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.188.86"; classtype:trojan-activity; sid:100000268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.126.177"; classtype:trojan-activity; sid:100000269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.171.69"; classtype:trojan-activity; sid:100000270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.228.21"; classtype:trojan-activity; sid:100000271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.141.241"; classtype:trojan-activity; sid:100000272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.144.226"; classtype:trojan-activity; sid:100000273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.172.106"; classtype:trojan-activity; sid:100000274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.197.144"; classtype:trojan-activity; sid:100000275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.230.192"; classtype:trojan-activity; sid:100000276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.75.157"; classtype:trojan-activity; sid:100000277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.143.135"; classtype:trojan-activity; sid:100000278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.17.120"; classtype:trojan-activity; sid:100000279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.190.207"; classtype:trojan-activity; sid:100000280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.194.18"; classtype:trojan-activity; sid:100000281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.227.228"; classtype:trojan-activity; sid:100000282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.39.2"; classtype:trojan-activity; sid:100000283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.73.181"; classtype:trojan-activity; sid:100000284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.184.162"; classtype:trojan-activity; sid:100000285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.216.17"; classtype:trojan-activity; sid:100000286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.241.187.165"; classtype:trojan-activity; sid:100000287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.106.228"; classtype:trojan-activity; sid:100000288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.18.128"; classtype:trojan-activity; sid:100000289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.2.247"; classtype:trojan-activity; sid:100000290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.97.131"; classtype:trojan-activity; sid:100000291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.243.115.183"; classtype:trojan-activity; sid:100000292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.12.89"; classtype:trojan-activity; sid:100000293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.178.153"; classtype:trojan-activity; sid:100000294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.5.141"; classtype:trojan-activity; sid:100000295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.8.24"; classtype:trojan-activity; sid:100000296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.162.50"; classtype:trojan-activity; sid:100000297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.180.49"; classtype:trojan-activity; sid:100000298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.100.14"; classtype:trojan-activity; sid:100000299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.16.222"; classtype:trojan-activity; sid:100000300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.161.45"; classtype:trojan-activity; sid:100000301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.191.118"; classtype:trojan-activity; sid:100000302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.214.146"; classtype:trojan-activity; sid:100000303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.240.226"; classtype:trojan-activity; sid:100000304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.25.42"; classtype:trojan-activity; sid:100000305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.81.173"; classtype:trojan-activity; sid:100000306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.82.122"; classtype:trojan-activity; sid:100000307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.148.90"; classtype:trojan-activity; sid:100000308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.179.239"; classtype:trojan-activity; sid:100000309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.197.164"; classtype:trojan-activity; sid:100000310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.44.153"; classtype:trojan-activity; sid:100000311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.109.217"; classtype:trojan-activity; sid:100000312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.118.157"; classtype:trojan-activity; sid:100000313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.165.240"; classtype:trojan-activity; sid:100000314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.206.69"; classtype:trojan-activity; sid:100000315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.26.129"; classtype:trojan-activity; sid:100000316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.41.142"; classtype:trojan-activity; sid:100000317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.79.98"; classtype:trojan-activity; sid:100000318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.102.173"; classtype:trojan-activity; sid:100000319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.57.99"; classtype:trojan-activity; sid:100000320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.17.5"; classtype:trojan-activity; sid:100000321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.218.210"; classtype:trojan-activity; sid:100000322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.23.55"; classtype:trojan-activity; sid:100000323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.136.84"; classtype:trojan-activity; sid:100000324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.199.150"; classtype:trojan-activity; sid:100000325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.221.244"; classtype:trojan-activity; sid:100000326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.239.103"; classtype:trojan-activity; sid:100000327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.245.249"; classtype:trojan-activity; sid:100000328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.46.212"; classtype:trojan-activity; sid:100000329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.128.160"; classtype:trojan-activity; sid:100000330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.188.228"; classtype:trojan-activity; sid:100000331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.208.123"; classtype:trojan-activity; sid:100000332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.32.5"; classtype:trojan-activity; sid:100000333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.127.212"; classtype:trojan-activity; sid:100000334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.38.10"; classtype:trojan-activity; sid:100000335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.6.129"; classtype:trojan-activity; sid:100000336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.8.235"; classtype:trojan-activity; sid:100000337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.121.163"; classtype:trojan-activity; sid:100000338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.123.174"; classtype:trojan-activity; sid:100000339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.109"; classtype:trojan-activity; sid:100000340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.110"; classtype:trojan-activity; sid:100000341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.111"; classtype:trojan-activity; sid:100000342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.112"; classtype:trojan-activity; sid:100000343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.113"; classtype:trojan-activity; sid:100000344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.117"; classtype:trojan-activity; sid:100000345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.119"; classtype:trojan-activity; sid:100000346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.122"; classtype:trojan-activity; sid:100000347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.124"; classtype:trojan-activity; sid:100000348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.127"; classtype:trojan-activity; sid:100000349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.128"; classtype:trojan-activity; sid:100000350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.130"; classtype:trojan-activity; sid:100000351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.131"; classtype:trojan-activity; sid:100000352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.132"; classtype:trojan-activity; sid:100000353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.133"; classtype:trojan-activity; sid:100000354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.136"; classtype:trojan-activity; sid:100000355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.138"; classtype:trojan-activity; sid:100000356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.139"; classtype:trojan-activity; sid:100000357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.142"; classtype:trojan-activity; sid:100000358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.143"; classtype:trojan-activity; sid:100000359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.146"; classtype:trojan-activity; sid:100000360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.149"; classtype:trojan-activity; sid:100000361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.150"; classtype:trojan-activity; sid:100000362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.151"; classtype:trojan-activity; sid:100000363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.155"; classtype:trojan-activity; sid:100000364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.158"; classtype:trojan-activity; sid:100000365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.160"; classtype:trojan-activity; sid:100000366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.162"; classtype:trojan-activity; sid:100000367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.163"; classtype:trojan-activity; sid:100000368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.165"; classtype:trojan-activity; sid:100000369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.168"; classtype:trojan-activity; sid:100000370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.171"; classtype:trojan-activity; sid:100000371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.172"; classtype:trojan-activity; sid:100000372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.174"; classtype:trojan-activity; sid:100000373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.175"; classtype:trojan-activity; sid:100000374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.176"; classtype:trojan-activity; sid:100000375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.178"; classtype:trojan-activity; sid:100000376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.179"; classtype:trojan-activity; sid:100000377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.71"; classtype:trojan-activity; sid:100000378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.126.243"; classtype:trojan-activity; sid:100000379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.127.155"; classtype:trojan-activity; sid:100000380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.120"; classtype:trojan-activity; sid:100000381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.121"; classtype:trojan-activity; sid:100000382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.82.29"; classtype:trojan-activity; sid:100000383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.182"; classtype:trojan-activity; sid:100000384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.23"; classtype:trojan-activity; sid:100000385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.85.113"; classtype:trojan-activity; sid:100000386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.87.203"; classtype:trojan-activity; sid:100000387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.87.213"; classtype:trojan-activity; sid:100000388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.88.116"; classtype:trojan-activity; sid:100000389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.212"; classtype:trojan-activity; sid:100000390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.247"; classtype:trojan-activity; sid:100000391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.133"; classtype:trojan-activity; sid:100000392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.149"; classtype:trojan-activity; sid:100000393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.150"; classtype:trojan-activity; sid:100000394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.158"; classtype:trojan-activity; sid:100000395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.164"; classtype:trojan-activity; sid:100000396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.168"; classtype:trojan-activity; sid:100000397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.177"; classtype:trojan-activity; sid:100000398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.178"; classtype:trojan-activity; sid:100000399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.181"; classtype:trojan-activity; sid:100000400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.182"; classtype:trojan-activity; sid:100000401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.188"; classtype:trojan-activity; sid:100000402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.190"; classtype:trojan-activity; sid:100000403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.194"; classtype:trojan-activity; sid:100000404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.197"; classtype:trojan-activity; sid:100000405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.211"; classtype:trojan-activity; sid:100000406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.219"; classtype:trojan-activity; sid:100000407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.229"; classtype:trojan-activity; sid:100000408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.230"; classtype:trojan-activity; sid:100000409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.245"; classtype:trojan-activity; sid:100000410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.247"; classtype:trojan-activity; sid:100000411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.54"; classtype:trojan-activity; sid:100000412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.55"; classtype:trojan-activity; sid:100000413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.57"; classtype:trojan-activity; sid:100000414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.60"; classtype:trojan-activity; sid:100000415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.90"; classtype:trojan-activity; sid:100000416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.91"; classtype:trojan-activity; sid:100000417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.100.228"; classtype:trojan-activity; sid:100000418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.30"; classtype:trojan-activity; sid:100000419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.31"; classtype:trojan-activity; sid:100000420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.36"; classtype:trojan-activity; sid:100000421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.37"; classtype:trojan-activity; sid:100000422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.38"; classtype:trojan-activity; sid:100000423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.41"; classtype:trojan-activity; sid:100000424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.42"; classtype:trojan-activity; sid:100000425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.43"; classtype:trojan-activity; sid:100000426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.51"; classtype:trojan-activity; sid:100000427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.52"; classtype:trojan-activity; sid:100000428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.57"; classtype:trojan-activity; sid:100000429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.58"; classtype:trojan-activity; sid:100000430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.60"; classtype:trojan-activity; sid:100000431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.62"; classtype:trojan-activity; sid:100000432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.126.156"; classtype:trojan-activity; sid:100000433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.35.237"; classtype:trojan-activity; sid:100000434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.38.100"; classtype:trojan-activity; sid:100000435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.38.19"; classtype:trojan-activity; sid:100000436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.118"; classtype:trojan-activity; sid:100000437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.119"; classtype:trojan-activity; sid:100000438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.121"; classtype:trojan-activity; sid:100000439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.136"; classtype:trojan-activity; sid:100000440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.37"; classtype:trojan-activity; sid:100000441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.52"; classtype:trojan-activity; sid:100000442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.53"; classtype:trojan-activity; sid:100000443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.57"; classtype:trojan-activity; sid:100000444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.61"; classtype:trojan-activity; sid:100000445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.70"; classtype:trojan-activity; sid:100000446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.73"; classtype:trojan-activity; sid:100000447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.77"; classtype:trojan-activity; sid:100000448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.90"; classtype:trojan-activity; sid:100000449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.176.16"; classtype:trojan-activity; sid:100000450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.211.135"; classtype:trojan-activity; sid:100000451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.82.160"; classtype:trojan-activity; sid:100000452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.87.98"; classtype:trojan-activity; sid:100000453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.224.79"; classtype:trojan-activity; sid:100000454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.65.53.175"; classtype:trojan-activity; sid:100000455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.153.37"; classtype:trojan-activity; sid:100000456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.159"; classtype:trojan-activity; sid:100000457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.49"; classtype:trojan-activity; sid:100000458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.53"; classtype:trojan-activity; sid:100000459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.112"; classtype:trojan-activity; sid:100000460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.84"; classtype:trojan-activity; sid:100000461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.226.202"; classtype:trojan-activity; sid:100000462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.231.35"; classtype:trojan-activity; sid:100000463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.78.45.158"; classtype:trojan-activity; sid:100000464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.118.16"; classtype:trojan-activity; sid:100000465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.127.91"; classtype:trojan-activity; sid:100000466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.215.101"; classtype:trojan-activity; sid:100000467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.81.161.10"; classtype:trojan-activity; sid:100000468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.81.199.218"; classtype:trojan-activity; sid:100000469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.131.124"; classtype:trojan-activity; sid:100000470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.146.253"; classtype:trojan-activity; sid:100000471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.18.255"; classtype:trojan-activity; sid:100000472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.224.139"; classtype:trojan-activity; sid:100000473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.227.41"; classtype:trojan-activity; sid:100000474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.228.175"; classtype:trojan-activity; sid:100000475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.83.118.203"; classtype:trojan-activity; sid:100000476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.83.230.37"; classtype:trojan-activity; sid:100000477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.86.133.125"; classtype:trojan-activity; sid:100000478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.9.140.247"; classtype:trojan-activity; sid:100000479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.91.219.195"; classtype:trojan-activity; sid:100000480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.93.29.211"; classtype:trojan-activity; sid:100000481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.0.74.25"; classtype:trojan-activity; sid:100000482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.11.95.254"; classtype:trojan-activity; sid:100000483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.110.204.254"; classtype:trojan-activity; sid:100000484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.118.13.194"; classtype:trojan-activity; sid:100000485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.118.159.178"; classtype:trojan-activity; sid:100000486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.119.37.141"; classtype:trojan-activity; sid:100000487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.238.68"; classtype:trojan-activity; sid:100000488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.59.84"; classtype:trojan-activity; sid:100000489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.58.249"; classtype:trojan-activity; sid:100000490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.172.250.35"; classtype:trojan-activity; sid:100000491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.189.243.248"; classtype:trojan-activity; sid:100000492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.193.29.42"; classtype:trojan-activity; sid:100000493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.194.133.9"; classtype:trojan-activity; sid:100000494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.194.135.154"; classtype:trojan-activity; sid:100000495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.163.26"; classtype:trojan-activity; sid:100000496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.166.46"; classtype:trojan-activity; sid:100000497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.168.190"; classtype:trojan-activity; sid:100000498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.201.219.47"; classtype:trojan-activity; sid:100000499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.226.42.250"; classtype:trojan-activity; sid:100000500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.128.9"; classtype:trojan-activity; sid:100000501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.169.170"; classtype:trojan-activity; sid:100000502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.194.172"; classtype:trojan-activity; sid:100000503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.35.229"; classtype:trojan-activity; sid:100000504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.211.131"; classtype:trojan-activity; sid:100000505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.93.142"; classtype:trojan-activity; sid:100000506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.232.156.157"; classtype:trojan-activity; sid:100000507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.234.224.130"; classtype:trojan-activity; sid:100000508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.235.116.209"; classtype:trojan-activity; sid:100000509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.253.144.141"; classtype:trojan-activity; sid:100000510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.254.169.251"; classtype:trojan-activity; sid:100000511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.128.133"; classtype:trojan-activity; sid:100000512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.154.21"; classtype:trojan-activity; sid:100000513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.191.47"; classtype:trojan-activity; sid:100000514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.61.204.205"; classtype:trojan-activity; sid:100000515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.86.204.13"; classtype:trojan-activity; sid:100000516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.87.203.239"; classtype:trojan-activity; sid:100000517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.232.36"; classtype:trojan-activity; sid:100000518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.38.232"; classtype:trojan-activity; sid:100000519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.39.21"; classtype:trojan-activity; sid:100000520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.90.27.218"; classtype:trojan-activity; sid:100000521; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.92.93.208"; classtype:trojan-activity; sid:100000522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.199.204.37"; classtype:trojan-activity; sid:100000523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.199.253.235"; classtype:trojan-activity; sid:100000524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.224.203.128"; classtype:trojan-activity; sid:100000525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.226.100.56"; classtype:trojan-activity; sid:100000526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.227.156.119"; classtype:trojan-activity; sid:100000527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.228.205.101"; classtype:trojan-activity; sid:100000528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.228.242.109"; classtype:trojan-activity; sid:100000529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.229.165.194"; classtype:trojan-activity; sid:100000530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.229.52.14"; classtype:trojan-activity; sid:100000531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.234.189.154"; classtype:trojan-activity; sid:100000532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.235.115.236"; classtype:trojan-activity; sid:100000533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.30.54.64"; classtype:trojan-activity; sid:100000534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.161.94"; classtype:trojan-activity; sid:100000535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.172.42"; classtype:trojan-activity; sid:100000536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.165.216.112"; classtype:trojan-activity; sid:100000537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.171.239.28"; classtype:trojan-activity; sid:100000538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.193.83.0"; classtype:trojan-activity; sid:100000539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.201.38.185"; classtype:trojan-activity; sid:100000540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.201.98.176"; classtype:trojan-activity; sid:100000541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.208.97.42"; classtype:trojan-activity; sid:100000542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.209.234.226"; classtype:trojan-activity; sid:100000543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.223.159.80"; classtype:trojan-activity; sid:100000544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.229.250.130"; classtype:trojan-activity; sid:100000545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.23.88.135"; classtype:trojan-activity; sid:100000546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.42.47.36"; classtype:trojan-activity; sid:100000547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.163.47"; classtype:trojan-activity; sid:100000548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.179.43"; classtype:trojan-activity; sid:100000549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.188.17"; classtype:trojan-activity; sid:100000550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.200.115"; classtype:trojan-activity; sid:100000551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.49.84"; classtype:trojan-activity; sid:100000552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.124.80"; classtype:trojan-activity; sid:100000553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.158.175"; classtype:trojan-activity; sid:100000554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.36.220"; classtype:trojan-activity; sid:100000555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.43.52"; classtype:trojan-activity; sid:100000556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.80.117"; classtype:trojan-activity; sid:100000557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.96.88"; classtype:trojan-activity; sid:100000558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.15.24"; classtype:trojan-activity; sid:100000559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.199.253.235"; classtype:trojan-activity; sid:100000523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.224.203.128"; classtype:trojan-activity; sid:100000524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.226.100.56"; classtype:trojan-activity; sid:100000525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.227.156.119"; classtype:trojan-activity; sid:100000526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.228.205.101"; classtype:trojan-activity; sid:100000527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.228.242.109"; classtype:trojan-activity; sid:100000528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.229.165.194"; classtype:trojan-activity; sid:100000529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.229.52.14"; classtype:trojan-activity; sid:100000530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.234.189.154"; classtype:trojan-activity; sid:100000531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.235.115.236"; classtype:trojan-activity; sid:100000532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.161.94"; classtype:trojan-activity; sid:100000533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.172.42"; classtype:trojan-activity; sid:100000534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.165.216.112"; classtype:trojan-activity; sid:100000535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.171.239.28"; classtype:trojan-activity; sid:100000536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.193.83.0"; classtype:trojan-activity; sid:100000537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.201.38.185"; classtype:trojan-activity; sid:100000538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.201.98.176"; classtype:trojan-activity; sid:100000539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.205.197.221"; classtype:trojan-activity; sid:100000540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.208.97.42"; classtype:trojan-activity; sid:100000541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.209.234.226"; classtype:trojan-activity; sid:100000542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.223.159.80"; classtype:trojan-activity; sid:100000543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.229.250.130"; classtype:trojan-activity; sid:100000544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.42.47.36"; classtype:trojan-activity; sid:100000545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.163.47"; classtype:trojan-activity; sid:100000546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.179.43"; classtype:trojan-activity; sid:100000547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.188.17"; classtype:trojan-activity; sid:100000548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.201.26"; classtype:trojan-activity; sid:100000549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.41.101"; classtype:trojan-activity; sid:100000550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.124.80"; classtype:trojan-activity; sid:100000551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.158.175"; classtype:trojan-activity; sid:100000552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.24.63"; classtype:trojan-activity; sid:100000553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.36.220"; classtype:trojan-activity; sid:100000554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.79.131"; classtype:trojan-activity; sid:100000555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.1.41"; classtype:trojan-activity; sid:100000556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.168.160"; classtype:trojan-activity; sid:100000557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.171.192"; classtype:trojan-activity; sid:100000558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.175.205"; classtype:trojan-activity; sid:100000559; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.19.136"; classtype:trojan-activity; sid:100000560; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.20.73"; classtype:trojan-activity; sid:100000561; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.206.128"; classtype:trojan-activity; sid:100000562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.226.30"; classtype:trojan-activity; sid:100000563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.228.168"; classtype:trojan-activity; sid:100000564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.238.227"; classtype:trojan-activity; sid:100000565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.239.77"; classtype:trojan-activity; sid:100000566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.240.72"; classtype:trojan-activity; sid:100000567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.211.74"; classtype:trojan-activity; sid:100000563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.238.227"; classtype:trojan-activity; sid:100000564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.239.77"; classtype:trojan-activity; sid:100000565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.242.7"; classtype:trojan-activity; sid:100000566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.247.46"; classtype:trojan-activity; sid:100000567; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.61.82"; classtype:trojan-activity; sid:100000568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.91.30"; classtype:trojan-activity; sid:100000569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.96.254"; classtype:trojan-activity; sid:100000570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.104.85"; classtype:trojan-activity; sid:100000571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.106.209"; classtype:trojan-activity; sid:100000572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.79.78"; classtype:trojan-activity; sid:100000569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.91.30"; classtype:trojan-activity; sid:100000570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.96.254"; classtype:trojan-activity; sid:100000571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.7.254"; classtype:trojan-activity; sid:100000572; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.17.196"; classtype:trojan-activity; sid:100000573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.53.200.130"; classtype:trojan-activity; sid:100000574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.53.224.134"; classtype:trojan-activity; sid:100000575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.53.234.210"; classtype:trojan-activity; sid:100000576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.53.238.224"; classtype:trojan-activity; sid:100000577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.123.147"; classtype:trojan-activity; sid:100000578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.70.108"; classtype:trojan-activity; sid:100000579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.105.154"; classtype:trojan-activity; sid:100000580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.144.42"; classtype:trojan-activity; sid:100000581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.145.147"; classtype:trojan-activity; sid:100000582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.157.96"; classtype:trojan-activity; sid:100000583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.158.230"; classtype:trojan-activity; sid:100000584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.158.250"; classtype:trojan-activity; sid:100000585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.161.38"; classtype:trojan-activity; sid:100000586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.179.168"; classtype:trojan-activity; sid:100000587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.206.35"; classtype:trojan-activity; sid:100000588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.206.78"; classtype:trojan-activity; sid:100000589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.26.94"; classtype:trojan-activity; sid:100000590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.42.200"; classtype:trojan-activity; sid:100000591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.111.63"; classtype:trojan-activity; sid:100000592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.114.17"; classtype:trojan-activity; sid:100000593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.132.61"; classtype:trojan-activity; sid:100000594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.133.96"; classtype:trojan-activity; sid:100000595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.134.79"; classtype:trojan-activity; sid:100000596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.137.48"; classtype:trojan-activity; sid:100000597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.139.122"; classtype:trojan-activity; sid:100000598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.143.241"; classtype:trojan-activity; sid:100000599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.145.102"; classtype:trojan-activity; sid:100000600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.148.22"; classtype:trojan-activity; sid:100000601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.151.65"; classtype:trojan-activity; sid:100000602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.151.68"; classtype:trojan-activity; sid:100000603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.154.147"; classtype:trojan-activity; sid:100000604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.175.2"; classtype:trojan-activity; sid:100000605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.189.162"; classtype:trojan-activity; sid:100000606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.31.54"; classtype:trojan-activity; sid:100000607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.98.205"; classtype:trojan-activity; sid:100000608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.99.235"; classtype:trojan-activity; sid:100000609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.132.199"; classtype:trojan-activity; sid:100000610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.134.143"; classtype:trojan-activity; sid:100000611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.161.17"; classtype:trojan-activity; sid:100000612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.90.143"; classtype:trojan-activity; sid:100000613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.198.69"; classtype:trojan-activity; sid:100000614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.209.196"; classtype:trojan-activity; sid:100000615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.212.193"; classtype:trojan-activity; sid:100000616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.214.107"; classtype:trojan-activity; sid:100000617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.228.237"; classtype:trojan-activity; sid:100000618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.235.229"; classtype:trojan-activity; sid:100000619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.253.202"; classtype:trojan-activity; sid:100000620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.57.171"; classtype:trojan-activity; sid:100000621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.82.123"; classtype:trojan-activity; sid:100000622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.102.110"; classtype:trojan-activity; sid:100000623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.118.201"; classtype:trojan-activity; sid:100000624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.118.90"; classtype:trojan-activity; sid:100000625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.139.74"; classtype:trojan-activity; sid:100000626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.152.207"; classtype:trojan-activity; sid:100000627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.155.83"; classtype:trojan-activity; sid:100000628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.26.39"; classtype:trojan-activity; sid:100000629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.139.175"; classtype:trojan-activity; sid:100000630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.141.147"; classtype:trojan-activity; sid:100000631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.180.149"; classtype:trojan-activity; sid:100000632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.189.77"; classtype:trojan-activity; sid:100000633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.21.130"; classtype:trojan-activity; sid:100000634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.37.6"; classtype:trojan-activity; sid:100000635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.53.188"; classtype:trojan-activity; sid:100000636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.73.3.11"; classtype:trojan-activity; sid:100000637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.75.217.79"; classtype:trojan-activity; sid:100000638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.78.133.146"; classtype:trojan-activity; sid:100000639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.92.174.231"; classtype:trojan-activity; sid:100000640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.96.61.246"; classtype:trojan-activity; sid:100000641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.97.136.10"; classtype:trojan-activity; sid:100000642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.124.219.2"; classtype:trojan-activity; sid:100000643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.149.243.14"; classtype:trojan-activity; sid:100000644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.2.100.221"; classtype:trojan-activity; sid:100000645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.206.164.46"; classtype:trojan-activity; sid:100000646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.207.71.237"; classtype:trojan-activity; sid:100000647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.211.100.26"; classtype:trojan-activity; sid:100000648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.212.132.119"; classtype:trojan-activity; sid:100000649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.212.142.215"; classtype:trojan-activity; sid:100000650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.30.4.2"; classtype:trojan-activity; sid:100000651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.30.95.156"; classtype:trojan-activity; sid:100000652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.72.51.230"; classtype:trojan-activity; sid:100000653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.73.222.118"; classtype:trojan-activity; sid:100000654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.75.199.105"; classtype:trojan-activity; sid:100000655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.75.212.119"; classtype:trojan-activity; sid:100000656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.76.114.71"; classtype:trojan-activity; sid:100000657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.11.234.35"; classtype:trojan-activity; sid:100000658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.12.48.157"; classtype:trojan-activity; sid:100000659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.156.69.22"; classtype:trojan-activity; sid:100000660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.192.224.103"; classtype:trojan-activity; sid:100000661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.192.225.161"; classtype:trojan-activity; sid:100000662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.192.225.195"; classtype:trojan-activity; sid:100000663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.192.227.137"; classtype:trojan-activity; sid:100000664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.160.78"; classtype:trojan-activity; sid:100000665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.163.210"; classtype:trojan-activity; sid:100000666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.166.103"; classtype:trojan-activity; sid:100000667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.166.20"; classtype:trojan-activity; sid:100000668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.138"; classtype:trojan-activity; sid:100000669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.5"; classtype:trojan-activity; sid:100000670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.210.52"; classtype:trojan-activity; sid:100000671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.236.14"; classtype:trojan-activity; sid:100000672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.243.40"; classtype:trojan-activity; sid:100000673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.200.76.54"; classtype:trojan-activity; sid:100000674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.200.76.60"; classtype:trojan-activity; sid:100000675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.67.238"; classtype:trojan-activity; sid:100000676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.67.246"; classtype:trojan-activity; sid:100000677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.67.4"; classtype:trojan-activity; sid:100000678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.70.96"; classtype:trojan-activity; sid:100000679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.71.179"; classtype:trojan-activity; sid:100000680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.207.5.156"; classtype:trojan-activity; sid:100000681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.208.134.226"; classtype:trojan-activity; sid:100000682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.208.134.64"; classtype:trojan-activity; sid:100000683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.11.104"; classtype:trojan-activity; sid:100000684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.14.17"; classtype:trojan-activity; sid:100000685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.14.30"; classtype:trojan-activity; sid:100000686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.14.62"; classtype:trojan-activity; sid:100000687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.15.179"; classtype:trojan-activity; sid:100000688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.43.219"; classtype:trojan-activity; sid:100000689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.44.116"; classtype:trojan-activity; sid:100000690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.46.160"; classtype:trojan-activity; sid:100000691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.47.183"; classtype:trojan-activity; sid:100000692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.8.163"; classtype:trojan-activity; sid:100000693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.215.248.14"; classtype:trojan-activity; sid:100000694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.215.251.253"; classtype:trojan-activity; sid:100000695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.160.108"; classtype:trojan-activity; sid:100000696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.162.50"; classtype:trojan-activity; sid:100000697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.164.19"; classtype:trojan-activity; sid:100000698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.164.21"; classtype:trojan-activity; sid:100000699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.169.141"; classtype:trojan-activity; sid:100000700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.172.16"; classtype:trojan-activity; sid:100000701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.174.16"; classtype:trojan-activity; sid:100000702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.241.64.105"; classtype:trojan-activity; sid:100000703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.241.67.141"; classtype:trojan-activity; sid:100000704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.242.208.153"; classtype:trojan-activity; sid:100000705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.242.208.95"; classtype:trojan-activity; sid:100000706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.247.200.129"; classtype:trojan-activity; sid:100000707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.247.202.150"; classtype:trojan-activity; sid:100000708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.247.203.156"; classtype:trojan-activity; sid:100000709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.247.204.118"; classtype:trojan-activity; sid:100000710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.247.204.66"; classtype:trojan-activity; sid:100000711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.60.194"; classtype:trojan-activity; sid:100000712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.26.235.164"; classtype:trojan-activity; sid:100000713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.27.10.73"; classtype:trojan-activity; sid:100000714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.60.204.190"; classtype:trojan-activity; sid:100000715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.113.146"; classtype:trojan-activity; sid:100000716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.195.140"; classtype:trojan-activity; sid:100000717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.252.82"; classtype:trojan-activity; sid:100000718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.53.15"; classtype:trojan-activity; sid:100000719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.86.105.110"; classtype:trojan-activity; sid:100000720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.91.240.50"; classtype:trojan-activity; sid:100000721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.93.115.242"; classtype:trojan-activity; sid:100000722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.93.79.40"; classtype:trojan-activity; sid:100000723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.172.80.79"; classtype:trojan-activity; sid:100000724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.104.35"; classtype:trojan-activity; sid:100000725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.157.64"; classtype:trojan-activity; sid:100000726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.7.132"; classtype:trojan-activity; sid:100000727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.211.38.112"; classtype:trojan-activity; sid:100000728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.32.74"; classtype:trojan-activity; sid:100000729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.5.149"; classtype:trojan-activity; sid:100000730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.72.141"; classtype:trojan-activity; sid:100000731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.12.130"; classtype:trojan-activity; sid:100000732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.128.147"; classtype:trojan-activity; sid:100000733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.208.215"; classtype:trojan-activity; sid:100000734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.209.108"; classtype:trojan-activity; sid:100000735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.214.72"; classtype:trojan-activity; sid:100000736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.88.146"; classtype:trojan-activity; sid:100000737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.150"; classtype:trojan-activity; sid:100000738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.6"; classtype:trojan-activity; sid:100000739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.221.162"; classtype:trojan-activity; sid:100000740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.63.194"; classtype:trojan-activity; sid:100000741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.65.93"; classtype:trojan-activity; sid:100000742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.250.51.192"; classtype:trojan-activity; sid:100000743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.42.125.246"; classtype:trojan-activity; sid:100000744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.43.180.33"; classtype:trojan-activity; sid:100000745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.68.245.69"; classtype:trojan-activity; sid:100000746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.70.83.140"; classtype:trojan-activity; sid:100000747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.120.136"; classtype:trojan-activity; sid:100000748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.200.198"; classtype:trojan-activity; sid:100000749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.240.136"; classtype:trojan-activity; sid:100000750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.240.239"; classtype:trojan-activity; sid:100000751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.50.253"; classtype:trojan-activity; sid:100000752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.70.70"; classtype:trojan-activity; sid:100000753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.125.92"; classtype:trojan-activity; sid:100000754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.161.110"; classtype:trojan-activity; sid:100000755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.164.102"; classtype:trojan-activity; sid:100000756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.218.157"; classtype:trojan-activity; sid:100000757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.50.203"; classtype:trojan-activity; sid:100000758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.58.82"; classtype:trojan-activity; sid:100000759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.83.79.43"; classtype:trojan-activity; sid:100000760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.91.24.27"; classtype:trojan-activity; sid:100000761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.179.164"; classtype:trojan-activity; sid:100000762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.183.235"; classtype:trojan-activity; sid:100000763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.239.217"; classtype:trojan-activity; sid:100000764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.100.40.250"; classtype:trojan-activity; sid:100000765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.108.251.176"; classtype:trojan-activity; sid:100000766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.109.34.245"; classtype:trojan-activity; sid:100000767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.112.22.58"; classtype:trojan-activity; sid:100000768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.112.27.20"; classtype:trojan-activity; sid:100000769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.115.247.23"; classtype:trojan-activity; sid:100000770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.119.52.202"; classtype:trojan-activity; sid:100000771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.123.125.139"; classtype:trojan-activity; sid:100000772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.123.216.42"; classtype:trojan-activity; sid:100000773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.123.218.76"; classtype:trojan-activity; sid:100000774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.123.221.158"; classtype:trojan-activity; sid:100000775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.123.237.218"; classtype:trojan-activity; sid:100000776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.14.143.145"; classtype:trojan-activity; sid:100000777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.147.213.57"; classtype:trojan-activity; sid:100000778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.162.109.111"; classtype:trojan-activity; sid:100000779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.144.208"; classtype:trojan-activity; sid:100000780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.207.197"; classtype:trojan-activity; sid:100000781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.93.191"; classtype:trojan-activity; sid:100000782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.18.235"; classtype:trojan-activity; sid:100000783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.31.76"; classtype:trojan-activity; sid:100000784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.107.93"; classtype:trojan-activity; sid:100000785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.163.220"; classtype:trojan-activity; sid:100000786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.174.63"; classtype:trojan-activity; sid:100000787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.241.222"; classtype:trojan-activity; sid:100000788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.27.77"; classtype:trojan-activity; sid:100000789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.68.145"; classtype:trojan-activity; sid:100000790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.170.241"; classtype:trojan-activity; sid:100000791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.19.254"; classtype:trojan-activity; sid:100000792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.97.6"; classtype:trojan-activity; sid:100000793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.1.13"; classtype:trojan-activity; sid:100000794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.2.214"; classtype:trojan-activity; sid:100000795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.26.33"; classtype:trojan-activity; sid:100000796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.63.195"; classtype:trojan-activity; sid:100000797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.201.188"; classtype:trojan-activity; sid:100000798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.248.123"; classtype:trojan-activity; sid:100000799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.249.140"; classtype:trojan-activity; sid:100000800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.120.180"; classtype:trojan-activity; sid:100000801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.157.219"; classtype:trojan-activity; sid:100000802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.16.149"; classtype:trojan-activity; sid:100000803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.170.212"; classtype:trojan-activity; sid:100000804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.190.180"; classtype:trojan-activity; sid:100000805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.43.1"; classtype:trojan-activity; sid:100000806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.75.8"; classtype:trojan-activity; sid:100000807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.18.38.144"; classtype:trojan-activity; sid:100000808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.101.151"; classtype:trojan-activity; sid:100000809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.106.217"; classtype:trojan-activity; sid:100000810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.227"; classtype:trojan-activity; sid:100000811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.79"; classtype:trojan-activity; sid:100000812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.11.29"; classtype:trojan-activity; sid:100000813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.231.79"; classtype:trojan-activity; sid:100000814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.33.161"; classtype:trojan-activity; sid:100000815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.9.35"; classtype:trojan-activity; sid:100000816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.94.80"; classtype:trojan-activity; sid:100000817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.119.21"; classtype:trojan-activity; sid:100000818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.124.203"; classtype:trojan-activity; sid:100000819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.115.103"; classtype:trojan-activity; sid:100000820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.9.82"; classtype:trojan-activity; sid:100000821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.14.112"; classtype:trojan-activity; sid:100000822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.172.199"; classtype:trojan-activity; sid:100000823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.237.89"; classtype:trojan-activity; sid:100000824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.43.193"; classtype:trojan-activity; sid:100000825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.186.140.160"; classtype:trojan-activity; sid:100000826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.186.22.245"; classtype:trojan-activity; sid:100000827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.195.161"; classtype:trojan-activity; sid:100000828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.220.115"; classtype:trojan-activity; sid:100000829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.137.195"; classtype:trojan-activity; sid:100000830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.227.244"; classtype:trojan-activity; sid:100000831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.190.211.99"; classtype:trojan-activity; sid:100000832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.190.234.181"; classtype:trojan-activity; sid:100000833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.190.240.238"; classtype:trojan-activity; sid:100000834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.150.85"; classtype:trojan-activity; sid:100000835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.187.206"; classtype:trojan-activity; sid:100000836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.215.221"; classtype:trojan-activity; sid:100000837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.240.20"; classtype:trojan-activity; sid:100000838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.253.206"; classtype:trojan-activity; sid:100000839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.204.30.144"; classtype:trojan-activity; sid:100000840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.250.129.231"; classtype:trojan-activity; sid:100000841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.105.221"; classtype:trojan-activity; sid:100000842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.12.85"; classtype:trojan-activity; sid:100000843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.14.251"; classtype:trojan-activity; sid:100000844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.131.155"; classtype:trojan-activity; sid:100000845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.46"; classtype:trojan-activity; sid:100000846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.71"; classtype:trojan-activity; sid:100000847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.144.75"; classtype:trojan-activity; sid:100000848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.148.115"; classtype:trojan-activity; sid:100000849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.155.57"; classtype:trojan-activity; sid:100000850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.172.28"; classtype:trojan-activity; sid:100000851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.195.90"; classtype:trojan-activity; sid:100000852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.96.37.55"; classtype:trojan-activity; sid:100000853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.96.70.116"; classtype:trojan-activity; sid:100000854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.188.187"; classtype:trojan-activity; sid:100000855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.190.152"; classtype:trojan-activity; sid:100000856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.232.62"; classtype:trojan-activity; sid:100000857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.132.113.2"; classtype:trojan-activity; sid:100000858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.15.69.83"; classtype:trojan-activity; sid:100000859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.6"; classtype:trojan-activity; sid:100000860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.7"; classtype:trojan-activity; sid:100000861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.8"; classtype:trojan-activity; sid:100000862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.9"; classtype:trojan-activity; sid:100000863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.207.39.227"; classtype:trojan-activity; sid:100000864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.153.54"; classtype:trojan-activity; sid:100000865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.212.5"; classtype:trojan-activity; sid:100000866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.142.222.22"; classtype:trojan-activity; sid:100000867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.150.213.110"; classtype:trojan-activity; sid:100000868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.151.248.134"; classtype:trojan-activity; sid:100000869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.177"; classtype:trojan-activity; sid:100000870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.178"; classtype:trojan-activity; sid:100000871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.180"; classtype:trojan-activity; sid:100000872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.181"; classtype:trojan-activity; sid:100000873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.183"; classtype:trojan-activity; sid:100000874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.184"; classtype:trojan-activity; sid:100000875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.185"; classtype:trojan-activity; sid:100000876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.186"; classtype:trojan-activity; sid:100000877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.188"; classtype:trojan-activity; sid:100000878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.191"; classtype:trojan-activity; sid:100000879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.193"; classtype:trojan-activity; sid:100000880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.196"; classtype:trojan-activity; sid:100000881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.197"; classtype:trojan-activity; sid:100000882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.198"; classtype:trojan-activity; sid:100000883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.199"; classtype:trojan-activity; sid:100000884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.200"; classtype:trojan-activity; sid:100000885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.201"; classtype:trojan-activity; sid:100000886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.202"; classtype:trojan-activity; sid:100000887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.204"; classtype:trojan-activity; sid:100000888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.207"; classtype:trojan-activity; sid:100000889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.208"; classtype:trojan-activity; sid:100000890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.212"; classtype:trojan-activity; sid:100000891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.213"; classtype:trojan-activity; sid:100000892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.215"; classtype:trojan-activity; sid:100000893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.233"; classtype:trojan-activity; sid:100000894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.93.227"; classtype:trojan-activity; sid:100000895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.121.243"; classtype:trojan-activity; sid:100000896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.206"; classtype:trojan-activity; sid:100000897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.225"; classtype:trojan-activity; sid:100000898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.235"; classtype:trojan-activity; sid:100000899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.240"; classtype:trojan-activity; sid:100000900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.243"; classtype:trojan-activity; sid:100000901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.60"; classtype:trojan-activity; sid:100000902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.127.187"; classtype:trojan-activity; sid:100000903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.99.127"; classtype:trojan-activity; sid:100000904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.210.89.79"; classtype:trojan-activity; sid:100000905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.43.34.242"; classtype:trojan-activity; sid:100000906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.5.15.95"; classtype:trojan-activity; sid:100000907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.66.60"; classtype:trojan-activity; sid:100000908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.93.115"; classtype:trojan-activity; sid:100000909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.57.98.208"; classtype:trojan-activity; sid:100000910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.141.142"; classtype:trojan-activity; sid:100000911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.8.11"; classtype:trojan-activity; sid:100000912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.69.131.51"; classtype:trojan-activity; sid:100000913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.7.75.99"; classtype:trojan-activity; sid:100000914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.7.90.104"; classtype:trojan-activity; sid:100000915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.83.189.232"; classtype:trojan-activity; sid:100000916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.165.112"; classtype:trojan-activity; sid:100000917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.169.113"; classtype:trojan-activity; sid:100000918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.170.109"; classtype:trojan-activity; sid:100000919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.173.234"; classtype:trojan-activity; sid:100000920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.185.141"; classtype:trojan-activity; sid:100000921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.236.95"; classtype:trojan-activity; sid:100000922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.238.10"; classtype:trojan-activity; sid:100000923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.238.244"; classtype:trojan-activity; sid:100000924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.9.32.51"; classtype:trojan-activity; sid:100000925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.114.164"; classtype:trojan-activity; sid:100000926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.96.8"; classtype:trojan-activity; sid:100000927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.121.44.222"; classtype:trojan-activity; sid:100000928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.123.53.25"; classtype:trojan-activity; sid:100000929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.127.155.220"; classtype:trojan-activity; sid:100000930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.136.249.5"; classtype:trojan-activity; sid:100000931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.141.11.56"; classtype:trojan-activity; sid:100000932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.15.142.137"; classtype:trojan-activity; sid:100000933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.151.78.190"; classtype:trojan-activity; sid:100000934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.159.22.144"; classtype:trojan-activity; sid:100000935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.17.103.176"; classtype:trojan-activity; sid:100000936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.170.234.142"; classtype:trojan-activity; sid:100000937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.185.31.2"; classtype:trojan-activity; sid:100000938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.190.36.8"; classtype:trojan-activity; sid:100000939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.225.11.163"; classtype:trojan-activity; sid:100000940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.226.82.202"; classtype:trojan-activity; sid:100000941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.23.57.130"; classtype:trojan-activity; sid:100000942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.230.171.198"; classtype:trojan-activity; sid:100000943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.231.103.95"; classtype:trojan-activity; sid:100000944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.233.18.172"; classtype:trojan-activity; sid:100000945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.238.175.87"; classtype:trojan-activity; sid:100000946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.239.15.74"; classtype:trojan-activity; sid:100000947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.24.116.173"; classtype:trojan-activity; sid:100000948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.25.101.86"; classtype:trojan-activity; sid:100000949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.254.43.215"; classtype:trojan-activity; sid:100000950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.254.76.17"; classtype:trojan-activity; sid:100000951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.101.93"; classtype:trojan-activity; sid:100000952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.102.1"; classtype:trojan-activity; sid:100000953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.107.189"; classtype:trojan-activity; sid:100000954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.97.195"; classtype:trojan-activity; sid:100000955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.98.151"; classtype:trojan-activity; sid:100000956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.88.99.236"; classtype:trojan-activity; sid:100000957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.100.150.204"; classtype:trojan-activity; sid:100000958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.137.52.122"; classtype:trojan-activity; sid:100000959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.160.147.53"; classtype:trojan-activity; sid:100000960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.176.44.34"; classtype:trojan-activity; sid:100000961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.188.86.225"; classtype:trojan-activity; sid:100000962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.190.19.204"; classtype:trojan-activity; sid:100000963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.192.190.203"; classtype:trojan-activity; sid:100000964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.66.28"; classtype:trojan-activity; sid:100000965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.72.23"; classtype:trojan-activity; sid:100000966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.79.27"; classtype:trojan-activity; sid:100000967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.37.85"; classtype:trojan-activity; sid:100000968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.41.23"; classtype:trojan-activity; sid:100000969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.252.199.3"; classtype:trojan-activity; sid:100000970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.252.250.22"; classtype:trojan-activity; sid:100000971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.183.207"; classtype:trojan-activity; sid:100000972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.29.37"; classtype:trojan-activity; sid:100000973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.33.214"; classtype:trojan-activity; sid:100000974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.0.240.58"; classtype:trojan-activity; sid:100000975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.131.225"; classtype:trojan-activity; sid:100000976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.41.32"; classtype:trojan-activity; sid:100000977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.83.136"; classtype:trojan-activity; sid:100000978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.11.207"; classtype:trojan-activity; sid:100000979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.4.168"; classtype:trojan-activity; sid:100000980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.7.1"; classtype:trojan-activity; sid:100000981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.71.166"; classtype:trojan-activity; sid:100000982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.238"; classtype:trojan-activity; sid:100000983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.244"; classtype:trojan-activity; sid:100000984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.170.237"; classtype:trojan-activity; sid:100000985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.182.187"; classtype:trojan-activity; sid:100000986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.19.248"; classtype:trojan-activity; sid:100000987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.200.98"; classtype:trojan-activity; sid:100000988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.238.188"; classtype:trojan-activity; sid:100000989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.12.7.82"; classtype:trojan-activity; sid:100000990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.128.205"; classtype:trojan-activity; sid:100000991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.133.91"; classtype:trojan-activity; sid:100000992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.177.161"; classtype:trojan-activity; sid:100000993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.84.36"; classtype:trojan-activity; sid:100000994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.88.123"; classtype:trojan-activity; sid:100000995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.13.44.60"; classtype:trojan-activity; sid:100000996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.202.8"; classtype:trojan-activity; sid:100000997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.208.52"; classtype:trojan-activity; sid:100000998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.23.110"; classtype:trojan-activity; sid:100000999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.37.182"; classtype:trojan-activity; sid:100001000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.61.210"; classtype:trojan-activity; sid:100001001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.77.225"; classtype:trojan-activity; sid:100001002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.131.186.250"; classtype:trojan-activity; sid:100001003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.132.219.147"; classtype:trojan-activity; sid:100001004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.125.77"; classtype:trojan-activity; sid:100001005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.144.138"; classtype:trojan-activity; sid:100001006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.184.77"; classtype:trojan-activity; sid:100001007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.98.135"; classtype:trojan-activity; sid:100001008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.14.130"; classtype:trojan-activity; sid:100001009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.50.186"; classtype:trojan-activity; sid:100001010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.157.193"; classtype:trojan-activity; sid:100001011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.39.36"; classtype:trojan-activity; sid:100001012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.71.150"; classtype:trojan-activity; sid:100001013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.172.149"; classtype:trojan-activity; sid:100001014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.86.82"; classtype:trojan-activity; sid:100001015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.93.154"; classtype:trojan-activity; sid:100001016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.144.211.86"; classtype:trojan-activity; sid:100001017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.152.42.4"; classtype:trojan-activity; sid:100001018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.152.43.21"; classtype:trojan-activity; sid:100001019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.153.80.178"; classtype:trojan-activity; sid:100001020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.236.114"; classtype:trojan-activity; sid:100001021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.94.1"; classtype:trojan-activity; sid:100001022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.155.118.36"; classtype:trojan-activity; sid:100001023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.156.136.21"; classtype:trojan-activity; sid:100001024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.137.101"; classtype:trojan-activity; sid:100001025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.31.110"; classtype:trojan-activity; sid:100001026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.8.100"; classtype:trojan-activity; sid:100001027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.101.163"; classtype:trojan-activity; sid:100001028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.194.233"; classtype:trojan-activity; sid:100001029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.149.235"; classtype:trojan-activity; sid:100001030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.53.237"; classtype:trojan-activity; sid:100001031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.235.37"; classtype:trojan-activity; sid:100001032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.35.146"; classtype:trojan-activity; sid:100001033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.52.79"; classtype:trojan-activity; sid:100001034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.60.238"; classtype:trojan-activity; sid:100001035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.112.240"; classtype:trojan-activity; sid:100001036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.184.191"; classtype:trojan-activity; sid:100001037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.98.141"; classtype:trojan-activity; sid:100001038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.212.29.154"; classtype:trojan-activity; sid:100001039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.213.225.130"; classtype:trojan-activity; sid:100001040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.130.162"; classtype:trojan-activity; sid:100001041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.152.249"; classtype:trojan-activity; sid:100001042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.100.219"; classtype:trojan-activity; sid:100001043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.116.110"; classtype:trojan-activity; sid:100001044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.184.57"; classtype:trojan-activity; sid:100001045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.246.103"; classtype:trojan-activity; sid:100001046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.235.226.3"; classtype:trojan-activity; sid:100001047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.103.89"; classtype:trojan-activity; sid:100001048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.181.57"; classtype:trojan-activity; sid:100001049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.79.61"; classtype:trojan-activity; sid:100001050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.148.58"; classtype:trojan-activity; sid:100001051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.184.124"; classtype:trojan-activity; sid:100001052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.27.44.219"; classtype:trojan-activity; sid:100001053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.28.217.23"; classtype:trojan-activity; sid:100001054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.11.40"; classtype:trojan-activity; sid:100001055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.166.2"; classtype:trojan-activity; sid:100001056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.176.22"; classtype:trojan-activity; sid:100001057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.177.93"; classtype:trojan-activity; sid:100001058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.193.171"; classtype:trojan-activity; sid:100001059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.209.154"; classtype:trojan-activity; sid:100001060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.241.118"; classtype:trojan-activity; sid:100001061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.76.117"; classtype:trojan-activity; sid:100001062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.83.66"; classtype:trojan-activity; sid:100001063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.85.149"; classtype:trojan-activity; sid:100001064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.123.60"; classtype:trojan-activity; sid:100001065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.143.203"; classtype:trojan-activity; sid:100001066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.146.238"; classtype:trojan-activity; sid:100001067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.190.167"; classtype:trojan-activity; sid:100001068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.5.242"; classtype:trojan-activity; sid:100001069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.8.211"; classtype:trojan-activity; sid:100001070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.56.94"; classtype:trojan-activity; sid:100001071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.194.169"; classtype:trojan-activity; sid:100001072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.245.207"; classtype:trojan-activity; sid:100001073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.105.105.222"; classtype:trojan-activity; sid:100001074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.162.169"; classtype:trojan-activity; sid:100001075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.221.150"; classtype:trojan-activity; sid:100001076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.76.230"; classtype:trojan-activity; sid:100001077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.167.20"; classtype:trojan-activity; sid:100001078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.40.31"; classtype:trojan-activity; sid:100001079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.104.82"; classtype:trojan-activity; sid:100001080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.130.95"; classtype:trojan-activity; sid:100001081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.131.71"; classtype:trojan-activity; sid:100001082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.136.75"; classtype:trojan-activity; sid:100001083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.151.135"; classtype:trojan-activity; sid:100001084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.26.243"; classtype:trojan-activity; sid:100001085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.26.78"; classtype:trojan-activity; sid:100001086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.41.48"; classtype:trojan-activity; sid:100001087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.54.33"; classtype:trojan-activity; sid:100001088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.72.208"; classtype:trojan-activity; sid:100001089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.132.110.150"; classtype:trojan-activity; sid:100001090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.135.34.157"; classtype:trojan-activity; sid:100001091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.135.34.49"; classtype:trojan-activity; sid:100001092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.136.175"; classtype:trojan-activity; sid:100001093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.236.6"; classtype:trojan-activity; sid:100001094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.160.126.238"; classtype:trojan-activity; sid:100001095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.154.237"; classtype:trojan-activity; sid:100001096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.65.64"; classtype:trojan-activity; sid:100001097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.65.98"; classtype:trojan-activity; sid:100001098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.72.102"; classtype:trojan-activity; sid:100001099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.77.191"; classtype:trojan-activity; sid:100001100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.89.212"; classtype:trojan-activity; sid:100001101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.90.243"; classtype:trojan-activity; sid:100001102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.165.123.7"; classtype:trojan-activity; sid:100001103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.187.111.160"; classtype:trojan-activity; sid:100001104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.199.56.198"; classtype:trojan-activity; sid:100001105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.226.24.117"; classtype:trojan-activity; sid:100001106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.230.174.233"; classtype:trojan-activity; sid:100001107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.234.6.130"; classtype:trojan-activity; sid:100001108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.254.254.61"; classtype:trojan-activity; sid:100001109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.5.92.20"; classtype:trojan-activity; sid:100001110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.6.0.4"; classtype:trojan-activity; sid:100001111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.67.89.28"; classtype:trojan-activity; sid:100001112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.7.254.85"; classtype:trojan-activity; sid:100001113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.80.46.73"; classtype:trojan-activity; sid:100001114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.91.237.147"; classtype:trojan-activity; sid:100001115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.93.94.207"; classtype:trojan-activity; sid:100001116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.95.17.41"; classtype:trojan-activity; sid:100001117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.105.219.169"; classtype:trojan-activity; sid:100001118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.126.69.95"; classtype:trojan-activity; sid:100001119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.128.28.161"; classtype:trojan-activity; sid:100001120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.142.93.34"; classtype:trojan-activity; sid:100001121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.168.10.234"; classtype:trojan-activity; sid:100001122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.191.113.212"; classtype:trojan-activity; sid:100001123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.209.71.6"; classtype:trojan-activity; sid:100001124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.36.148.42"; classtype:trojan-activity; sid:100001125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.1.127"; classtype:trojan-activity; sid:100001126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.113.66"; classtype:trojan-activity; sid:100001127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.160.116"; classtype:trojan-activity; sid:100001128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.17.14"; classtype:trojan-activity; sid:100001129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.237.130"; classtype:trojan-activity; sid:100001130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.25.140"; classtype:trojan-activity; sid:100001131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.65.120"; classtype:trojan-activity; sid:100001132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.73.6"; classtype:trojan-activity; sid:100001133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.74.153"; classtype:trojan-activity; sid:100001134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.75.22"; classtype:trojan-activity; sid:100001135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.208.139"; classtype:trojan-activity; sid:100001136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.244.43"; classtype:trojan-activity; sid:100001137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.6.192"; classtype:trojan-activity; sid:100001138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.7.204"; classtype:trojan-activity; sid:100001139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.74.22"; classtype:trojan-activity; sid:100001140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.96.238"; classtype:trojan-activity; sid:100001141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.96.33"; classtype:trojan-activity; sid:100001142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.97.81"; classtype:trojan-activity; sid:100001143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.107.136"; classtype:trojan-activity; sid:100001144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.124.114"; classtype:trojan-activity; sid:100001145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.98.24"; classtype:trojan-activity; sid:100001146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.98.35"; classtype:trojan-activity; sid:100001147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.112.123"; classtype:trojan-activity; sid:100001148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.112.182"; classtype:trojan-activity; sid:100001149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.133.130"; classtype:trojan-activity; sid:100001150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.167.192"; classtype:trojan-activity; sid:100001151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.2.169"; classtype:trojan-activity; sid:100001152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.21.157"; classtype:trojan-activity; sid:100001153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.215.244"; classtype:trojan-activity; sid:100001154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.26.36"; classtype:trojan-activity; sid:100001155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.33.20"; classtype:trojan-activity; sid:100001156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.37.138"; classtype:trojan-activity; sid:100001157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.53.50"; classtype:trojan-activity; sid:100001158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.53.9"; classtype:trojan-activity; sid:100001159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.60.218"; classtype:trojan-activity; sid:100001160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.73.19"; classtype:trojan-activity; sid:100001161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.92.62"; classtype:trojan-activity; sid:100001162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.10.125"; classtype:trojan-activity; sid:100001163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.107.182"; classtype:trojan-activity; sid:100001164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.175.118"; classtype:trojan-activity; sid:100001165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.198.62"; classtype:trojan-activity; sid:100001166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.212.131"; classtype:trojan-activity; sid:100001167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.243.220"; classtype:trojan-activity; sid:100001168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.31.79"; classtype:trojan-activity; sid:100001169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.8.227"; classtype:trojan-activity; sid:100001170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.153.91"; classtype:trojan-activity; sid:100001171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.55.146"; classtype:trojan-activity; sid:100001172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.138.117"; classtype:trojan-activity; sid:100001173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.166.125"; classtype:trojan-activity; sid:100001174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.205.88"; classtype:trojan-activity; sid:100001175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.206.160"; classtype:trojan-activity; sid:100001176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.217.52"; classtype:trojan-activity; sid:100001177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.241.237"; classtype:trojan-activity; sid:100001178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.241.188"; classtype:trojan-activity; sid:100001179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.245.200"; classtype:trojan-activity; sid:100001180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.250.98"; classtype:trojan-activity; sid:100001181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.252.106"; classtype:trojan-activity; sid:100001182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.254.154"; classtype:trojan-activity; sid:100001183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.254.44"; classtype:trojan-activity; sid:100001184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.28.18"; classtype:trojan-activity; sid:100001185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.45.218"; classtype:trojan-activity; sid:100001186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.57.80"; classtype:trojan-activity; sid:100001187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.91.51"; classtype:trojan-activity; sid:100001188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.79.192.197"; classtype:trojan-activity; sid:100001189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"128.116.133.92"; classtype:trojan-activity; sid:100001190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"130.255.159.133"; classtype:trojan-activity; sid:100001191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"134.195.139.4"; classtype:trojan-activity; sid:100001192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"134.255.93.203"; classtype:trojan-activity; sid:100001193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"135.181.192.170"; classtype:trojan-activity; sid:100001194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"138.99.204.224"; classtype:trojan-activity; sid:100001195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.159.226.180"; classtype:trojan-activity; sid:100001196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.173.198"; classtype:trojan-activity; sid:100001197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.174.162"; classtype:trojan-activity; sid:100001198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.216.102.151"; classtype:trojan-activity; sid:100001199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.227.46.137"; classtype:trojan-activity; sid:100001200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.102.17.222"; classtype:trojan-activity; sid:100001201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.102.97.204"; classtype:trojan-activity; sid:100001202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.136.80.242"; classtype:trojan-activity; sid:100001203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.109.129"; classtype:trojan-activity; sid:100001204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.109.26"; classtype:trojan-activity; sid:100001205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.215"; classtype:trojan-activity; sid:100001206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.51"; classtype:trojan-activity; sid:100001207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.155.220.240"; classtype:trojan-activity; sid:100001208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.160.24.71"; classtype:trojan-activity; sid:100001209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.169.164.77"; classtype:trojan-activity; sid:100001210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.181.64.108"; classtype:trojan-activity; sid:100001211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.189.247.118"; classtype:trojan-activity; sid:100001212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.205.201.192"; classtype:trojan-activity; sid:100001213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.248.187.0"; classtype:trojan-activity; sid:100001214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.37.222.190"; classtype:trojan-activity; sid:100001215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.45.127.110"; classtype:trojan-activity; sid:100001216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.25.17"; classtype:trojan-activity; sid:100001217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.98.241"; classtype:trojan-activity; sid:100001218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.55.29.2"; classtype:trojan-activity; sid:100001219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.98.184.178"; classtype:trojan-activity; sid:100001220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"140.237.30.113"; classtype:trojan-activity; sid:100001221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"140.237.5.43"; classtype:trojan-activity; sid:100001222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.11.216.5"; classtype:trojan-activity; sid:100001223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.177.56.127"; classtype:trojan-activity; sid:100001224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"146.71.79.230"; classtype:trojan-activity; sid:100001225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"148.69.108.177"; classtype:trojan-activity; sid:100001226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.20.176.179"; classtype:trojan-activity; sid:100001227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.112"; classtype:trojan-activity; sid:100001228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.134"; classtype:trojan-activity; sid:100001229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.180"; classtype:trojan-activity; sid:100001230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.182"; classtype:trojan-activity; sid:100001231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.184"; classtype:trojan-activity; sid:100001232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.191"; classtype:trojan-activity; sid:100001233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.213"; classtype:trojan-activity; sid:100001234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.235"; classtype:trojan-activity; sid:100001235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.27"; classtype:trojan-activity; sid:100001236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.43"; classtype:trojan-activity; sid:100001237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.87"; classtype:trojan-activity; sid:100001238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.99"; classtype:trojan-activity; sid:100001239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.124.194"; classtype:trojan-activity; sid:100001240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.36.210"; classtype:trojan-activity; sid:100001241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.85.55"; classtype:trojan-activity; sid:100001242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"150.116.207.99"; classtype:trojan-activity; sid:100001243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.177.163.87"; classtype:trojan-activity; sid:100001244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.33.230.191"; classtype:trojan-activity; sid:100001245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.73.124.231"; classtype:trojan-activity; sid:100001246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.225.96"; classtype:trojan-activity; sid:100001247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.234.167"; classtype:trojan-activity; sid:100001248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.40.207"; classtype:trojan-activity; sid:100001249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.43.136"; classtype:trojan-activity; sid:100001250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.44.44"; classtype:trojan-activity; sid:100001251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.135.92"; classtype:trojan-activity; sid:100001252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.23.76"; classtype:trojan-activity; sid:100001253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.29.28"; classtype:trojan-activity; sid:100001254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.35.111.46"; classtype:trojan-activity; sid:100001255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.35.27.49"; classtype:trojan-activity; sid:100001256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.36.126.35"; classtype:trojan-activity; sid:100001257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.101.165.14"; classtype:trojan-activity; sid:100001258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.174.213.128"; classtype:trojan-activity; sid:100001259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.51.125.115"; classtype:trojan-activity; sid:100001260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"159.224.74.112"; classtype:trojan-activity; sid:100001261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.165.238"; classtype:trojan-activity; sid:100001262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.205.175"; classtype:trojan-activity; sid:100001263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.194.28.60"; classtype:trojan-activity; sid:100001264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.209.98.174"; classtype:trojan-activity; sid:100001265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.125.6"; classtype:trojan-activity; sid:100001266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.157.64"; classtype:trojan-activity; sid:100001267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.18.93"; classtype:trojan-activity; sid:100001268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.193.148"; classtype:trojan-activity; sid:100001269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.195.248"; classtype:trojan-activity; sid:100001270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.200.199"; classtype:trojan-activity; sid:100001271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.202.193"; classtype:trojan-activity; sid:100001272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.202.195"; classtype:trojan-activity; sid:100001273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.202.21"; classtype:trojan-activity; sid:100001274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.203.198"; classtype:trojan-activity; sid:100001275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.204.156"; classtype:trojan-activity; sid:100001276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.204.244"; classtype:trojan-activity; sid:100001277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.204.34"; classtype:trojan-activity; sid:100001278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.207.61"; classtype:trojan-activity; sid:100001279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.243.131"; classtype:trojan-activity; sid:100001280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.255.165"; classtype:trojan-activity; sid:100001281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.204.208.169"; classtype:trojan-activity; sid:100001282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.204.211.228"; classtype:trojan-activity; sid:100001283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.204.211.58"; classtype:trojan-activity; sid:100001284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.53.206.228"; classtype:trojan-activity; sid:100001285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"165.90.16.5"; classtype:trojan-activity; sid:100001286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"168.90.204.207"; classtype:trojan-activity; sid:100001287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"170.81.238.178"; classtype:trojan-activity; sid:100001288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.113.36.216"; classtype:trojan-activity; sid:100001289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.118.18.184"; classtype:trojan-activity; sid:100001290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.118.210.67"; classtype:trojan-activity; sid:100001291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.217.149"; classtype:trojan-activity; sid:100001292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.218.208"; classtype:trojan-activity; sid:100001293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.219.150"; classtype:trojan-activity; sid:100001294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.248.222"; classtype:trojan-activity; sid:100001295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.255.96"; classtype:trojan-activity; sid:100001296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.120.125.147"; classtype:trojan-activity; sid:100001297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.121.6.162"; classtype:trojan-activity; sid:100001298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.123.134.239"; classtype:trojan-activity; sid:100001299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.242.71"; classtype:trojan-activity; sid:100001300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.30.233"; classtype:trojan-activity; sid:100001301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.30.93"; classtype:trojan-activity; sid:100001302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.64.223"; classtype:trojan-activity; sid:100001303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.65.22"; classtype:trojan-activity; sid:100001304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.75.68"; classtype:trojan-activity; sid:100001305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.126.70.133"; classtype:trojan-activity; sid:100001306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.223.72.123"; classtype:trojan-activity; sid:100001307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.112.42"; classtype:trojan-activity; sid:100001308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.114.181"; classtype:trojan-activity; sid:100001309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.179.178"; classtype:trojan-activity; sid:100001310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.160.138"; classtype:trojan-activity; sid:100001311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.161.234"; classtype:trojan-activity; sid:100001312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.162.156"; classtype:trojan-activity; sid:100001313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.174.198"; classtype:trojan-activity; sid:100001314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.36.249.91"; classtype:trojan-activity; sid:100001315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.145.146"; classtype:trojan-activity; sid:100001316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.148.69"; classtype:trojan-activity; sid:100001317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.217.222"; classtype:trojan-activity; sid:100001318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.219.189"; classtype:trojan-activity; sid:100001319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.223.110"; classtype:trojan-activity; sid:100001320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.223.213"; classtype:trojan-activity; sid:100001321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.105.36.168"; classtype:trojan-activity; sid:100001322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.114.244.127"; classtype:trojan-activity; sid:100001323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.185"; classtype:trojan-activity; sid:100001324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.190"; classtype:trojan-activity; sid:100001325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.81.19"; classtype:trojan-activity; sid:100001326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.167.85.89"; classtype:trojan-activity; sid:100001327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.169.46.85"; classtype:trojan-activity; sid:100001328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.19.58.108"; classtype:trojan-activity; sid:100001329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.233.85.171"; classtype:trojan-activity; sid:100001330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.235.209.70"; classtype:trojan-activity; sid:100001331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.25.113.8"; classtype:trojan-activity; sid:100001332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.95.134"; classtype:trojan-activity; sid:100001333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.97.25"; classtype:trojan-activity; sid:100001334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.119.108"; classtype:trojan-activity; sid:100001335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.92.166"; classtype:trojan-activity; sid:100001336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.106.33.85"; classtype:trojan-activity; sid:100001337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.48.181.23"; classtype:trojan-activity; sid:100001338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.61.3.149"; classtype:trojan-activity; sid:100001339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.73.246.193"; classtype:trojan-activity; sid:100001340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.81.78.7"; classtype:trojan-activity; sid:100001341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.83.73.163"; classtype:trojan-activity; sid:100001342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.10.147.167"; classtype:trojan-activity; sid:100001343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.11.193.66"; classtype:trojan-activity; sid:100001344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.115.241.87"; classtype:trojan-activity; sid:100001345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.117.66.74"; classtype:trojan-activity; sid:100001346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.145.200.216"; classtype:trojan-activity; sid:100001347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.146.17.227"; classtype:trojan-activity; sid:100001348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.150.168.92"; classtype:trojan-activity; sid:100001349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.153.144.2"; classtype:trojan-activity; sid:100001350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.162.137.166"; classtype:trojan-activity; sid:100001351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.162.195.27"; classtype:trojan-activity; sid:100001352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.162.69.13"; classtype:trojan-activity; sid:100001353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.165.90.198"; classtype:trojan-activity; sid:100001354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.168.139.182"; classtype:trojan-activity; sid:100001355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.17.90.14"; classtype:trojan-activity; sid:100001356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.174.93.57"; classtype:trojan-activity; sid:100001357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.199.33.139"; classtype:trojan-activity; sid:100001358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.201.104.192"; classtype:trojan-activity; sid:100001359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.208.230.8"; classtype:trojan-activity; sid:100001360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.212.6.169"; classtype:trojan-activity; sid:100001361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.42.46.118"; classtype:trojan-activity; sid:100001362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.8.113.55"; classtype:trojan-activity; sid:100001363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.9.24.110"; classtype:trojan-activity; sid:100001364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.14"; classtype:trojan-activity; sid:100001365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.35"; classtype:trojan-activity; sid:100001366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.63"; classtype:trojan-activity; sid:100001367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.66"; classtype:trojan-activity; sid:100001368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.67"; classtype:trojan-activity; sid:100001369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.104"; classtype:trojan-activity; sid:100001370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.113"; classtype:trojan-activity; sid:100001371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.120"; classtype:trojan-activity; sid:100001372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.128"; classtype:trojan-activity; sid:100001373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.138"; classtype:trojan-activity; sid:100001374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.59"; classtype:trojan-activity; sid:100001375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.65"; classtype:trojan-activity; sid:100001376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.66"; classtype:trojan-activity; sid:100001377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.76"; classtype:trojan-activity; sid:100001378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.84"; classtype:trojan-activity; sid:100001379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.88"; classtype:trojan-activity; sid:100001380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.93"; classtype:trojan-activity; sid:100001381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.174.139"; classtype:trojan-activity; sid:100001382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.12.117.70"; classtype:trojan-activity; sid:100001383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.4.115"; classtype:trojan-activity; sid:100001384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.115"; classtype:trojan-activity; sid:100001385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.127"; classtype:trojan-activity; sid:100001386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.9.243"; classtype:trojan-activity; sid:100001387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.124.7.225"; classtype:trojan-activity; sid:100001388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.40.142"; classtype:trojan-activity; sid:100001389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.84.106"; classtype:trojan-activity; sid:100001390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.11.92.78"; classtype:trojan-activity; sid:100001391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.131.226.235"; classtype:trojan-activity; sid:100001392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.229.64.218"; classtype:trojan-activity; sid:100001393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.44.61.243"; classtype:trojan-activity; sid:100001394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.86.235.143"; classtype:trojan-activity; sid:100001395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.124.182.187"; classtype:trojan-activity; sid:100001396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.125.98"; classtype:trojan-activity; sid:100001397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.25.82"; classtype:trojan-activity; sid:100001398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.45.2"; classtype:trojan-activity; sid:100001399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.57.166"; classtype:trojan-activity; sid:100001400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.150.174.65"; classtype:trojan-activity; sid:100001401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.151.143.2"; classtype:trojan-activity; sid:100001402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.165.122.141"; classtype:trojan-activity; sid:100001403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.0.140"; classtype:trojan-activity; sid:100001404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.0.42"; classtype:trojan-activity; sid:100001405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.0.47"; classtype:trojan-activity; sid:100001406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.139"; classtype:trojan-activity; sid:100001407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.143"; classtype:trojan-activity; sid:100001408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.153"; classtype:trojan-activity; sid:100001409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.182"; classtype:trojan-activity; sid:100001410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.224"; classtype:trojan-activity; sid:100001411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.244"; classtype:trojan-activity; sid:100001412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.247"; classtype:trojan-activity; sid:100001413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.249"; classtype:trojan-activity; sid:100001414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.250"; classtype:trojan-activity; sid:100001415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.252"; classtype:trojan-activity; sid:100001416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.80"; classtype:trojan-activity; sid:100001417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.99"; classtype:trojan-activity; sid:100001418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.102"; classtype:trojan-activity; sid:100001419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.34"; classtype:trojan-activity; sid:100001420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.42"; classtype:trojan-activity; sid:100001421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.71"; classtype:trojan-activity; sid:100001422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.78"; classtype:trojan-activity; sid:100001423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.110"; classtype:trojan-activity; sid:100001424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.129"; classtype:trojan-activity; sid:100001425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.180"; classtype:trojan-activity; sid:100001426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.187"; classtype:trojan-activity; sid:100001427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.190"; classtype:trojan-activity; sid:100001428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.218"; classtype:trojan-activity; sid:100001429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.34"; classtype:trojan-activity; sid:100001430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.4"; classtype:trojan-activity; sid:100001431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.87"; classtype:trojan-activity; sid:100001432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.110"; classtype:trojan-activity; sid:100001433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.243"; classtype:trojan-activity; sid:100001434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.134"; classtype:trojan-activity; sid:100001435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.152"; classtype:trojan-activity; sid:100001436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.190"; classtype:trojan-activity; sid:100001437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.221"; classtype:trojan-activity; sid:100001438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.228"; classtype:trojan-activity; sid:100001439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.245"; classtype:trojan-activity; sid:100001440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.35"; classtype:trojan-activity; sid:100001441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.53"; classtype:trojan-activity; sid:100001442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.172"; classtype:trojan-activity; sid:100001443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.195"; classtype:trojan-activity; sid:100001444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.27"; classtype:trojan-activity; sid:100001445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.106"; classtype:trojan-activity; sid:100001446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.110"; classtype:trojan-activity; sid:100001447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.120"; classtype:trojan-activity; sid:100001448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.140"; classtype:trojan-activity; sid:100001449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.155"; classtype:trojan-activity; sid:100001450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.16"; classtype:trojan-activity; sid:100001451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.169"; classtype:trojan-activity; sid:100001452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.183"; classtype:trojan-activity; sid:100001453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.196"; classtype:trojan-activity; sid:100001454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.206"; classtype:trojan-activity; sid:100001455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.49"; classtype:trojan-activity; sid:100001456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.125"; classtype:trojan-activity; sid:100001457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.146"; classtype:trojan-activity; sid:100001458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.197"; classtype:trojan-activity; sid:100001459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.217"; classtype:trojan-activity; sid:100001460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.220"; classtype:trojan-activity; sid:100001461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.245"; classtype:trojan-activity; sid:100001462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.104"; classtype:trojan-activity; sid:100001463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.106"; classtype:trojan-activity; sid:100001464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.118"; classtype:trojan-activity; sid:100001465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.18"; classtype:trojan-activity; sid:100001466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.193"; classtype:trojan-activity; sid:100001467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.37"; classtype:trojan-activity; sid:100001468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.77"; classtype:trojan-activity; sid:100001469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.0"; classtype:trojan-activity; sid:100001470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.133"; classtype:trojan-activity; sid:100001471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.149"; classtype:trojan-activity; sid:100001472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.240"; classtype:trojan-activity; sid:100001473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.245"; classtype:trojan-activity; sid:100001474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.83"; classtype:trojan-activity; sid:100001475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.87"; classtype:trojan-activity; sid:100001476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.94"; classtype:trojan-activity; sid:100001477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.132"; classtype:trojan-activity; sid:100001478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.140"; classtype:trojan-activity; sid:100001479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.37"; classtype:trojan-activity; sid:100001480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.77"; classtype:trojan-activity; sid:100001481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.109"; classtype:trojan-activity; sid:100001482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.165"; classtype:trojan-activity; sid:100001483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.176"; classtype:trojan-activity; sid:100001484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.184"; classtype:trojan-activity; sid:100001485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.204"; classtype:trojan-activity; sid:100001486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.57"; classtype:trojan-activity; sid:100001487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.6"; classtype:trojan-activity; sid:100001488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.155"; classtype:trojan-activity; sid:100001489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.169"; classtype:trojan-activity; sid:100001490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.197"; classtype:trojan-activity; sid:100001491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.198"; classtype:trojan-activity; sid:100001492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.221"; classtype:trojan-activity; sid:100001493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.250"; classtype:trojan-activity; sid:100001494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.105"; classtype:trojan-activity; sid:100001495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.159"; classtype:trojan-activity; sid:100001496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.187"; classtype:trojan-activity; sid:100001497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.190"; classtype:trojan-activity; sid:100001498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.203"; classtype:trojan-activity; sid:100001499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.206"; classtype:trojan-activity; sid:100001500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.36"; classtype:trojan-activity; sid:100001501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.98"; classtype:trojan-activity; sid:100001502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.139"; classtype:trojan-activity; sid:100001503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.147"; classtype:trojan-activity; sid:100001504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.159"; classtype:trojan-activity; sid:100001505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.4"; classtype:trojan-activity; sid:100001506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.46"; classtype:trojan-activity; sid:100001507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.59"; classtype:trojan-activity; sid:100001508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.66"; classtype:trojan-activity; sid:100001509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.85"; classtype:trojan-activity; sid:100001510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.174"; classtype:trojan-activity; sid:100001511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.200"; classtype:trojan-activity; sid:100001512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.254"; classtype:trojan-activity; sid:100001513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.29"; classtype:trojan-activity; sid:100001514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.51"; classtype:trojan-activity; sid:100001515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.55"; classtype:trojan-activity; sid:100001516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.63"; classtype:trojan-activity; sid:100001517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.90"; classtype:trojan-activity; sid:100001518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.99"; classtype:trojan-activity; sid:100001519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.138"; classtype:trojan-activity; sid:100001520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.206"; classtype:trojan-activity; sid:100001521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.208"; classtype:trojan-activity; sid:100001522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.188"; classtype:trojan-activity; sid:100001523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.200"; classtype:trojan-activity; sid:100001524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.227"; classtype:trojan-activity; sid:100001525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.48"; classtype:trojan-activity; sid:100001526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.64"; classtype:trojan-activity; sid:100001527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.209"; classtype:trojan-activity; sid:100001528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.215"; classtype:trojan-activity; sid:100001529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.39"; classtype:trojan-activity; sid:100001530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.51"; classtype:trojan-activity; sid:100001531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.112"; classtype:trojan-activity; sid:100001532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.113"; classtype:trojan-activity; sid:100001533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.165"; classtype:trojan-activity; sid:100001534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.192"; classtype:trojan-activity; sid:100001535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.198"; classtype:trojan-activity; sid:100001536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.47"; classtype:trojan-activity; sid:100001537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.60"; classtype:trojan-activity; sid:100001538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.215"; classtype:trojan-activity; sid:100001539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.237"; classtype:trojan-activity; sid:100001540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.26"; classtype:trojan-activity; sid:100001541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.56"; classtype:trojan-activity; sid:100001542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.73"; classtype:trojan-activity; sid:100001543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.86"; classtype:trojan-activity; sid:100001544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.138"; classtype:trojan-activity; sid:100001545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.151"; classtype:trojan-activity; sid:100001546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.40"; classtype:trojan-activity; sid:100001547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.53"; classtype:trojan-activity; sid:100001548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.70"; classtype:trojan-activity; sid:100001549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.97"; classtype:trojan-activity; sid:100001550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.133"; classtype:trojan-activity; sid:100001551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.162"; classtype:trojan-activity; sid:100001552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.184"; classtype:trojan-activity; sid:100001553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.196"; classtype:trojan-activity; sid:100001554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.203"; classtype:trojan-activity; sid:100001555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.231"; classtype:trojan-activity; sid:100001556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.4"; classtype:trojan-activity; sid:100001557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.116"; classtype:trojan-activity; sid:100001558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.122"; classtype:trojan-activity; sid:100001559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.123"; classtype:trojan-activity; sid:100001560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.155"; classtype:trojan-activity; sid:100001561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.190"; classtype:trojan-activity; sid:100001562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.229"; classtype:trojan-activity; sid:100001563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.63"; classtype:trojan-activity; sid:100001564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.83"; classtype:trojan-activity; sid:100001565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.123"; classtype:trojan-activity; sid:100001566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.130"; classtype:trojan-activity; sid:100001567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.168"; classtype:trojan-activity; sid:100001568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.201"; classtype:trojan-activity; sid:100001569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.217"; classtype:trojan-activity; sid:100001570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.245"; classtype:trojan-activity; sid:100001571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.26"; classtype:trojan-activity; sid:100001572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.28"; classtype:trojan-activity; sid:100001573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.191"; classtype:trojan-activity; sid:100001574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.196"; classtype:trojan-activity; sid:100001575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.2"; classtype:trojan-activity; sid:100001576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.30"; classtype:trojan-activity; sid:100001577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.40"; classtype:trojan-activity; sid:100001578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.56"; classtype:trojan-activity; sid:100001579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.7"; classtype:trojan-activity; sid:100001580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.90"; classtype:trojan-activity; sid:100001581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.109"; classtype:trojan-activity; sid:100001582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.122"; classtype:trojan-activity; sid:100001583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.131"; classtype:trojan-activity; sid:100001584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.197"; classtype:trojan-activity; sid:100001585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.4"; classtype:trojan-activity; sid:100001586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.79"; classtype:trojan-activity; sid:100001587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.89"; classtype:trojan-activity; sid:100001588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.9"; classtype:trojan-activity; sid:100001589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.14"; classtype:trojan-activity; sid:100001590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.153"; classtype:trojan-activity; sid:100001591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.174"; classtype:trojan-activity; sid:100001592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.227"; classtype:trojan-activity; sid:100001593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.39"; classtype:trojan-activity; sid:100001594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.167"; classtype:trojan-activity; sid:100001595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.171"; classtype:trojan-activity; sid:100001596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.220"; classtype:trojan-activity; sid:100001597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.222"; classtype:trojan-activity; sid:100001598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.237"; classtype:trojan-activity; sid:100001599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.61"; classtype:trojan-activity; sid:100001600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.62"; classtype:trojan-activity; sid:100001601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.83"; classtype:trojan-activity; sid:100001602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.93"; classtype:trojan-activity; sid:100001603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.10"; classtype:trojan-activity; sid:100001604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.119"; classtype:trojan-activity; sid:100001605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.122"; classtype:trojan-activity; sid:100001606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.15"; classtype:trojan-activity; sid:100001607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.159"; classtype:trojan-activity; sid:100001608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.166"; classtype:trojan-activity; sid:100001609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.176"; classtype:trojan-activity; sid:100001610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.230"; classtype:trojan-activity; sid:100001611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.231"; classtype:trojan-activity; sid:100001612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.236"; classtype:trojan-activity; sid:100001613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.237"; classtype:trojan-activity; sid:100001614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.63"; classtype:trojan-activity; sid:100001615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.64"; classtype:trojan-activity; sid:100001616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.75"; classtype:trojan-activity; sid:100001617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.1"; classtype:trojan-activity; sid:100001618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.157"; classtype:trojan-activity; sid:100001619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.19"; classtype:trojan-activity; sid:100001620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.220"; classtype:trojan-activity; sid:100001621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.237"; classtype:trojan-activity; sid:100001622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.250"; classtype:trojan-activity; sid:100001623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.178"; classtype:trojan-activity; sid:100001624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.185"; classtype:trojan-activity; sid:100001625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.230"; classtype:trojan-activity; sid:100001626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.60"; classtype:trojan-activity; sid:100001627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.69"; classtype:trojan-activity; sid:100001628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.166"; classtype:trojan-activity; sid:100001629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.199"; classtype:trojan-activity; sid:100001630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.215"; classtype:trojan-activity; sid:100001631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.217"; classtype:trojan-activity; sid:100001632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.253"; classtype:trojan-activity; sid:100001633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.35"; classtype:trojan-activity; sid:100001634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.45"; classtype:trojan-activity; sid:100001635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.5"; classtype:trojan-activity; sid:100001636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.85"; classtype:trojan-activity; sid:100001637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.1"; classtype:trojan-activity; sid:100001638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.108"; classtype:trojan-activity; sid:100001639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.114"; classtype:trojan-activity; sid:100001640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.123"; classtype:trojan-activity; sid:100001641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.179"; classtype:trojan-activity; sid:100001642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.221"; classtype:trojan-activity; sid:100001643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.49"; classtype:trojan-activity; sid:100001644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.59"; classtype:trojan-activity; sid:100001645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.73"; classtype:trojan-activity; sid:100001646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.97"; classtype:trojan-activity; sid:100001647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.245"; classtype:trojan-activity; sid:100001648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.93"; classtype:trojan-activity; sid:100001649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.163"; classtype:trojan-activity; sid:100001650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.174"; classtype:trojan-activity; sid:100001651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.229"; classtype:trojan-activity; sid:100001652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.44"; classtype:trojan-activity; sid:100001653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.108"; classtype:trojan-activity; sid:100001654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.110"; classtype:trojan-activity; sid:100001655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.123"; classtype:trojan-activity; sid:100001656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.188"; classtype:trojan-activity; sid:100001657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.237"; classtype:trojan-activity; sid:100001658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.41"; classtype:trojan-activity; sid:100001659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.47"; classtype:trojan-activity; sid:100001660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.5"; classtype:trojan-activity; sid:100001661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.54"; classtype:trojan-activity; sid:100001662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.117"; classtype:trojan-activity; sid:100001663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.170"; classtype:trojan-activity; sid:100001664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.225"; classtype:trojan-activity; sid:100001665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.237"; classtype:trojan-activity; sid:100001666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.24"; classtype:trojan-activity; sid:100001667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.70"; classtype:trojan-activity; sid:100001668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.149"; classtype:trojan-activity; sid:100001669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.170"; classtype:trojan-activity; sid:100001670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.184"; classtype:trojan-activity; sid:100001671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.233"; classtype:trojan-activity; sid:100001672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.238"; classtype:trojan-activity; sid:100001673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.76"; classtype:trojan-activity; sid:100001674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.8"; classtype:trojan-activity; sid:100001675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.110"; classtype:trojan-activity; sid:100001676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.147"; classtype:trojan-activity; sid:100001677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.237"; classtype:trojan-activity; sid:100001678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.247"; classtype:trojan-activity; sid:100001679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.102"; classtype:trojan-activity; sid:100001680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.156"; classtype:trojan-activity; sid:100001681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.228"; classtype:trojan-activity; sid:100001682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.250"; classtype:trojan-activity; sid:100001683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.36"; classtype:trojan-activity; sid:100001684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.138"; classtype:trojan-activity; sid:100001685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.170"; classtype:trojan-activity; sid:100001686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.171"; classtype:trojan-activity; sid:100001687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.172"; classtype:trojan-activity; sid:100001688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.177"; classtype:trojan-activity; sid:100001689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.216"; classtype:trojan-activity; sid:100001690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.218"; classtype:trojan-activity; sid:100001691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.238"; classtype:trojan-activity; sid:100001692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.243"; classtype:trojan-activity; sid:100001693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.77"; classtype:trojan-activity; sid:100001694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.113"; classtype:trojan-activity; sid:100001695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.117"; classtype:trojan-activity; sid:100001696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.169"; classtype:trojan-activity; sid:100001697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.177"; classtype:trojan-activity; sid:100001698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.28"; classtype:trojan-activity; sid:100001699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.46"; classtype:trojan-activity; sid:100001700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.56"; classtype:trojan-activity; sid:100001701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.64"; classtype:trojan-activity; sid:100001702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.75"; classtype:trojan-activity; sid:100001703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.77"; classtype:trojan-activity; sid:100001704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.112"; classtype:trojan-activity; sid:100001705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.116"; classtype:trojan-activity; sid:100001706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.164"; classtype:trojan-activity; sid:100001707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.165"; classtype:trojan-activity; sid:100001708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.209"; classtype:trojan-activity; sid:100001709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.215"; classtype:trojan-activity; sid:100001710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.219"; classtype:trojan-activity; sid:100001711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.224"; classtype:trojan-activity; sid:100001712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.246"; classtype:trojan-activity; sid:100001713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.34"; classtype:trojan-activity; sid:100001714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.106"; classtype:trojan-activity; sid:100001715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.122"; classtype:trojan-activity; sid:100001716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.138"; classtype:trojan-activity; sid:100001717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.14"; classtype:trojan-activity; sid:100001718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.167"; classtype:trojan-activity; sid:100001719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.171"; classtype:trojan-activity; sid:100001720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.177"; classtype:trojan-activity; sid:100001721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.179"; classtype:trojan-activity; sid:100001722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.199"; classtype:trojan-activity; sid:100001723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.202"; classtype:trojan-activity; sid:100001724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.215"; classtype:trojan-activity; sid:100001725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.225"; classtype:trojan-activity; sid:100001726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.233"; classtype:trojan-activity; sid:100001727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.239"; classtype:trojan-activity; sid:100001728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.32"; classtype:trojan-activity; sid:100001729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.37"; classtype:trojan-activity; sid:100001730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.46"; classtype:trojan-activity; sid:100001731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.48"; classtype:trojan-activity; sid:100001732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.68"; classtype:trojan-activity; sid:100001733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.69"; classtype:trojan-activity; sid:100001734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.102"; classtype:trojan-activity; sid:100001735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.199"; classtype:trojan-activity; sid:100001736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.16"; classtype:trojan-activity; sid:100001737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.173"; classtype:trojan-activity; sid:100001738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.174"; classtype:trojan-activity; sid:100001739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.2"; classtype:trojan-activity; sid:100001740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.201"; classtype:trojan-activity; sid:100001741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.207"; classtype:trojan-activity; sid:100001742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.220"; classtype:trojan-activity; sid:100001743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.116"; classtype:trojan-activity; sid:100001744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.130"; classtype:trojan-activity; sid:100001745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.166"; classtype:trojan-activity; sid:100001746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.172"; classtype:trojan-activity; sid:100001747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.190"; classtype:trojan-activity; sid:100001748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.196"; classtype:trojan-activity; sid:100001749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.214"; classtype:trojan-activity; sid:100001750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.0"; classtype:trojan-activity; sid:100001751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.135"; classtype:trojan-activity; sid:100001752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.213"; classtype:trojan-activity; sid:100001753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.252"; classtype:trojan-activity; sid:100001754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.70"; classtype:trojan-activity; sid:100001755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.93"; classtype:trojan-activity; sid:100001756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.96"; classtype:trojan-activity; sid:100001757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.171"; classtype:trojan-activity; sid:100001758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.251"; classtype:trojan-activity; sid:100001759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.6"; classtype:trojan-activity; sid:100001760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.197"; classtype:trojan-activity; sid:100001761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.198"; classtype:trojan-activity; sid:100001762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.2"; classtype:trojan-activity; sid:100001763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.20"; classtype:trojan-activity; sid:100001764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.211"; classtype:trojan-activity; sid:100001765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.229"; classtype:trojan-activity; sid:100001766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.243"; classtype:trojan-activity; sid:100001767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.89"; classtype:trojan-activity; sid:100001768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.95"; classtype:trojan-activity; sid:100001769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.112"; classtype:trojan-activity; sid:100001770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.141"; classtype:trojan-activity; sid:100001771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.162"; classtype:trojan-activity; sid:100001772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.173"; classtype:trojan-activity; sid:100001773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.181"; classtype:trojan-activity; sid:100001774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.2"; classtype:trojan-activity; sid:100001775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.208"; classtype:trojan-activity; sid:100001776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.215"; classtype:trojan-activity; sid:100001777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.228"; classtype:trojan-activity; sid:100001778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.234"; classtype:trojan-activity; sid:100001779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.26"; classtype:trojan-activity; sid:100001780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.28"; classtype:trojan-activity; sid:100001781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.63"; classtype:trojan-activity; sid:100001782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.1"; classtype:trojan-activity; sid:100001783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.2"; classtype:trojan-activity; sid:100001784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.200"; classtype:trojan-activity; sid:100001785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.243"; classtype:trojan-activity; sid:100001786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.144"; classtype:trojan-activity; sid:100001787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.21"; classtype:trojan-activity; sid:100001788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.38"; classtype:trojan-activity; sid:100001789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.83"; classtype:trojan-activity; sid:100001790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.0"; classtype:trojan-activity; sid:100001791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.127"; classtype:trojan-activity; sid:100001792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.129"; classtype:trojan-activity; sid:100001793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.218"; classtype:trojan-activity; sid:100001794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.231"; classtype:trojan-activity; sid:100001795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.245"; classtype:trojan-activity; sid:100001796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.33"; classtype:trojan-activity; sid:100001797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.107"; classtype:trojan-activity; sid:100001798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.135"; classtype:trojan-activity; sid:100001799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.153"; classtype:trojan-activity; sid:100001800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.223"; classtype:trojan-activity; sid:100001801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.26"; classtype:trojan-activity; sid:100001802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.38"; classtype:trojan-activity; sid:100001803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.56"; classtype:trojan-activity; sid:100001804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.6"; classtype:trojan-activity; sid:100001805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.81"; classtype:trojan-activity; sid:100001806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.83"; classtype:trojan-activity; sid:100001807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.1"; classtype:trojan-activity; sid:100001808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.132"; classtype:trojan-activity; sid:100001809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.141"; classtype:trojan-activity; sid:100001810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.165"; classtype:trojan-activity; sid:100001811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.191"; classtype:trojan-activity; sid:100001812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.28"; classtype:trojan-activity; sid:100001813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.98"; classtype:trojan-activity; sid:100001814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.158"; classtype:trojan-activity; sid:100001815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.245"; classtype:trojan-activity; sid:100001816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.57"; classtype:trojan-activity; sid:100001817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.144"; classtype:trojan-activity; sid:100001818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.219"; classtype:trojan-activity; sid:100001819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.222"; classtype:trojan-activity; sid:100001820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.231"; classtype:trojan-activity; sid:100001821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.95"; classtype:trojan-activity; sid:100001822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.155"; classtype:trojan-activity; sid:100001823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.166"; classtype:trojan-activity; sid:100001824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.226"; classtype:trojan-activity; sid:100001825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.228"; classtype:trojan-activity; sid:100001826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.41"; classtype:trojan-activity; sid:100001827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.56"; classtype:trojan-activity; sid:100001828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.67"; classtype:trojan-activity; sid:100001829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.82"; classtype:trojan-activity; sid:100001830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.203"; classtype:trojan-activity; sid:100001831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.34"; classtype:trojan-activity; sid:100001832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.171"; classtype:trojan-activity; sid:100001833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.1"; classtype:trojan-activity; sid:100001834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.106"; classtype:trojan-activity; sid:100001835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.121"; classtype:trojan-activity; sid:100001836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.138"; classtype:trojan-activity; sid:100001837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.147"; classtype:trojan-activity; sid:100001838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.217"; classtype:trojan-activity; sid:100001839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.30"; classtype:trojan-activity; sid:100001840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.33"; classtype:trojan-activity; sid:100001841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.69"; classtype:trojan-activity; sid:100001842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.0"; classtype:trojan-activity; sid:100001843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.134"; classtype:trojan-activity; sid:100001844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.143"; classtype:trojan-activity; sid:100001845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.155"; classtype:trojan-activity; sid:100001846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.186"; classtype:trojan-activity; sid:100001847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.197"; classtype:trojan-activity; sid:100001848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.217"; classtype:trojan-activity; sid:100001849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.22"; classtype:trojan-activity; sid:100001850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.241"; classtype:trojan-activity; sid:100001851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.70"; classtype:trojan-activity; sid:100001852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.89"; classtype:trojan-activity; sid:100001853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.90"; classtype:trojan-activity; sid:100001854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.95"; classtype:trojan-activity; sid:100001855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.96"; classtype:trojan-activity; sid:100001856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.191"; classtype:trojan-activity; sid:100001857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.205"; classtype:trojan-activity; sid:100001858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.6"; classtype:trojan-activity; sid:100001859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.87"; classtype:trojan-activity; sid:100001860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.119"; classtype:trojan-activity; sid:100001861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.187"; classtype:trojan-activity; sid:100001862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.224"; classtype:trojan-activity; sid:100001863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.42"; classtype:trojan-activity; sid:100001864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.11"; classtype:trojan-activity; sid:100001865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.141"; classtype:trojan-activity; sid:100001866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.151"; classtype:trojan-activity; sid:100001867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.168"; classtype:trojan-activity; sid:100001868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.245"; classtype:trojan-activity; sid:100001869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.110"; classtype:trojan-activity; sid:100001870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.168"; classtype:trojan-activity; sid:100001871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.139"; classtype:trojan-activity; sid:100001872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.247"; classtype:trojan-activity; sid:100001873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.3"; classtype:trojan-activity; sid:100001874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.17"; classtype:trojan-activity; sid:100001875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.51"; classtype:trojan-activity; sid:100001876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.131"; classtype:trojan-activity; sid:100001877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.177"; classtype:trojan-activity; sid:100001878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.22"; classtype:trojan-activity; sid:100001879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.236"; classtype:trojan-activity; sid:100001880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.237"; classtype:trojan-activity; sid:100001881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.27"; classtype:trojan-activity; sid:100001882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.137"; classtype:trojan-activity; sid:100001883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.160"; classtype:trojan-activity; sid:100001884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.202"; classtype:trojan-activity; sid:100001885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.66"; classtype:trojan-activity; sid:100001886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.161"; classtype:trojan-activity; sid:100001887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.212"; classtype:trojan-activity; sid:100001888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.71"; classtype:trojan-activity; sid:100001889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.94"; classtype:trojan-activity; sid:100001890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.135"; classtype:trojan-activity; sid:100001891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.151"; classtype:trojan-activity; sid:100001892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.186"; classtype:trojan-activity; sid:100001893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.217"; classtype:trojan-activity; sid:100001894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.4"; classtype:trojan-activity; sid:100001895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.5"; classtype:trojan-activity; sid:100001896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.56"; classtype:trojan-activity; sid:100001897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.58"; classtype:trojan-activity; sid:100001898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.79"; classtype:trojan-activity; sid:100001899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.158"; classtype:trojan-activity; sid:100001900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.163"; classtype:trojan-activity; sid:100001901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.205"; classtype:trojan-activity; sid:100001902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.214"; classtype:trojan-activity; sid:100001903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.225"; classtype:trojan-activity; sid:100001904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.64"; classtype:trojan-activity; sid:100001905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.103"; classtype:trojan-activity; sid:100001906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.14"; classtype:trojan-activity; sid:100001907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.163"; classtype:trojan-activity; sid:100001908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.181"; classtype:trojan-activity; sid:100001909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.25"; classtype:trojan-activity; sid:100001910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.29"; classtype:trojan-activity; sid:100001911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.38"; classtype:trojan-activity; sid:100001912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.41"; classtype:trojan-activity; sid:100001913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.47"; classtype:trojan-activity; sid:100001914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.77"; classtype:trojan-activity; sid:100001915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.103"; classtype:trojan-activity; sid:100001916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.11"; classtype:trojan-activity; sid:100001917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.120"; classtype:trojan-activity; sid:100001918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.18"; classtype:trojan-activity; sid:100001919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.196"; classtype:trojan-activity; sid:100001920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.24"; classtype:trojan-activity; sid:100001921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.252"; classtype:trojan-activity; sid:100001922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.33"; classtype:trojan-activity; sid:100001923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.37"; classtype:trojan-activity; sid:100001924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.50"; classtype:trojan-activity; sid:100001925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.54"; classtype:trojan-activity; sid:100001926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.72"; classtype:trojan-activity; sid:100001927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.75"; classtype:trojan-activity; sid:100001928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.10"; classtype:trojan-activity; sid:100001929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.141"; classtype:trojan-activity; sid:100001930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.179"; classtype:trojan-activity; sid:100001931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.28"; classtype:trojan-activity; sid:100001932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.29"; classtype:trojan-activity; sid:100001933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.74"; classtype:trojan-activity; sid:100001934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.79"; classtype:trojan-activity; sid:100001935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.161"; classtype:trojan-activity; sid:100001936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.33"; classtype:trojan-activity; sid:100001937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.47"; classtype:trojan-activity; sid:100001938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.54"; classtype:trojan-activity; sid:100001939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.134"; classtype:trojan-activity; sid:100001940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.157"; classtype:trojan-activity; sid:100001941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.189"; classtype:trojan-activity; sid:100001942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.209"; classtype:trojan-activity; sid:100001943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.212"; classtype:trojan-activity; sid:100001944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.251"; classtype:trojan-activity; sid:100001945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.156"; classtype:trojan-activity; sid:100001946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.163"; classtype:trojan-activity; sid:100001947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.17"; classtype:trojan-activity; sid:100001948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.171"; classtype:trojan-activity; sid:100001949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.219"; classtype:trojan-activity; sid:100001950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.237"; classtype:trojan-activity; sid:100001951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.111"; classtype:trojan-activity; sid:100001952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.115"; classtype:trojan-activity; sid:100001953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.166"; classtype:trojan-activity; sid:100001954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.168"; classtype:trojan-activity; sid:100001955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.208"; classtype:trojan-activity; sid:100001956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.42"; classtype:trojan-activity; sid:100001957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.43"; classtype:trojan-activity; sid:100001958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.70"; classtype:trojan-activity; sid:100001959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.8"; classtype:trojan-activity; sid:100001960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.84"; classtype:trojan-activity; sid:100001961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.167"; classtype:trojan-activity; sid:100001962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.21"; classtype:trojan-activity; sid:100001963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.73"; classtype:trojan-activity; sid:100001964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.96"; classtype:trojan-activity; sid:100001965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.12"; classtype:trojan-activity; sid:100001966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.156"; classtype:trojan-activity; sid:100001967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.158"; classtype:trojan-activity; sid:100001968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.187"; classtype:trojan-activity; sid:100001969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.22"; classtype:trojan-activity; sid:100001970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.30"; classtype:trojan-activity; sid:100001971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.50"; classtype:trojan-activity; sid:100001972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.115"; classtype:trojan-activity; sid:100001973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.202"; classtype:trojan-activity; sid:100001974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.236"; classtype:trojan-activity; sid:100001975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.105"; classtype:trojan-activity; sid:100001976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.123"; classtype:trojan-activity; sid:100001977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.186"; classtype:trojan-activity; sid:100001978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.192"; classtype:trojan-activity; sid:100001979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.199"; classtype:trojan-activity; sid:100001980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.211"; classtype:trojan-activity; sid:100001981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.228"; classtype:trojan-activity; sid:100001982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.43"; classtype:trojan-activity; sid:100001983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.54"; classtype:trojan-activity; sid:100001984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.93"; classtype:trojan-activity; sid:100001985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.0"; classtype:trojan-activity; sid:100001986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.36"; classtype:trojan-activity; sid:100001987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.51"; classtype:trojan-activity; sid:100001988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.8"; classtype:trojan-activity; sid:100001989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.81"; classtype:trojan-activity; sid:100001990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.83"; classtype:trojan-activity; sid:100001991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.89"; classtype:trojan-activity; sid:100001992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.109"; classtype:trojan-activity; sid:100001993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.44"; classtype:trojan-activity; sid:100001994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.66"; classtype:trojan-activity; sid:100001995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.85"; classtype:trojan-activity; sid:100001996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.111"; classtype:trojan-activity; sid:100001997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.112"; classtype:trojan-activity; sid:100001998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.119"; classtype:trojan-activity; sid:100001999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.128"; classtype:trojan-activity; sid:100002000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.18"; classtype:trojan-activity; sid:100002001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.4"; classtype:trojan-activity; sid:100002002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.96"; classtype:trojan-activity; sid:100002003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.6"; classtype:trojan-activity; sid:100002004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.60"; classtype:trojan-activity; sid:100002005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.71"; classtype:trojan-activity; sid:100002006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.109"; classtype:trojan-activity; sid:100002007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.12"; classtype:trojan-activity; sid:100002008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.147"; classtype:trojan-activity; sid:100002009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.18"; classtype:trojan-activity; sid:100002010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.196"; classtype:trojan-activity; sid:100002011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.218"; classtype:trojan-activity; sid:100002012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.246"; classtype:trojan-activity; sid:100002013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.38"; classtype:trojan-activity; sid:100002014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.5"; classtype:trojan-activity; sid:100002015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.50"; classtype:trojan-activity; sid:100002016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.64"; classtype:trojan-activity; sid:100002017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.71"; classtype:trojan-activity; sid:100002018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.83"; classtype:trojan-activity; sid:100002019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.202"; classtype:trojan-activity; sid:100002020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.45"; classtype:trojan-activity; sid:100002021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.55"; classtype:trojan-activity; sid:100002022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.84"; classtype:trojan-activity; sid:100002023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.108"; classtype:trojan-activity; sid:100002024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.13"; classtype:trojan-activity; sid:100002025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.222"; classtype:trojan-activity; sid:100002026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.30"; classtype:trojan-activity; sid:100002027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.37"; classtype:trojan-activity; sid:100002028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.73.127"; classtype:trojan-activity; sid:100002029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.73.77"; classtype:trojan-activity; sid:100002030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.73.96"; classtype:trojan-activity; sid:100002031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.182"; classtype:trojan-activity; sid:100002032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.48"; classtype:trojan-activity; sid:100002033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.130"; classtype:trojan-activity; sid:100002034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.181"; classtype:trojan-activity; sid:100002035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.19"; classtype:trojan-activity; sid:100002036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.84"; classtype:trojan-activity; sid:100002037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.87"; classtype:trojan-activity; sid:100002038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.103"; classtype:trojan-activity; sid:100002039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.109"; classtype:trojan-activity; sid:100002040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.209"; classtype:trojan-activity; sid:100002041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.21"; classtype:trojan-activity; sid:100002042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.217"; classtype:trojan-activity; sid:100002043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.83"; classtype:trojan-activity; sid:100002044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.9"; classtype:trojan-activity; sid:100002045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.46"; classtype:trojan-activity; sid:100002046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.47"; classtype:trojan-activity; sid:100002047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.71"; classtype:trojan-activity; sid:100002048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.118"; classtype:trojan-activity; sid:100002049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.198"; classtype:trojan-activity; sid:100002050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.243"; classtype:trojan-activity; sid:100002051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.46"; classtype:trojan-activity; sid:100002052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.97"; classtype:trojan-activity; sid:100002053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.17"; classtype:trojan-activity; sid:100002054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.244"; classtype:trojan-activity; sid:100002055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.247"; classtype:trojan-activity; sid:100002056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.69"; classtype:trojan-activity; sid:100002057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.100"; classtype:trojan-activity; sid:100002058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.100"; classtype:trojan-activity; sid:100002059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.114"; classtype:trojan-activity; sid:100002060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.129"; classtype:trojan-activity; sid:100002061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.17"; classtype:trojan-activity; sid:100002062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.20"; classtype:trojan-activity; sid:100002063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.35"; classtype:trojan-activity; sid:100002064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.41"; classtype:trojan-activity; sid:100002065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.61"; classtype:trojan-activity; sid:100002066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.79"; classtype:trojan-activity; sid:100002067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.86"; classtype:trojan-activity; sid:100002068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.17"; classtype:trojan-activity; sid:100002069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.192"; classtype:trojan-activity; sid:100002070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.226"; classtype:trojan-activity; sid:100002071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.232"; classtype:trojan-activity; sid:100002072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.244"; classtype:trojan-activity; sid:100002073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.253"; classtype:trojan-activity; sid:100002074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.50"; classtype:trojan-activity; sid:100002075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.82.137"; classtype:trojan-activity; sid:100002076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.82.32"; classtype:trojan-activity; sid:100002077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.2"; classtype:trojan-activity; sid:100002078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.247"; classtype:trojan-activity; sid:100002079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.102"; classtype:trojan-activity; sid:100002080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.109"; classtype:trojan-activity; sid:100002081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.159"; classtype:trojan-activity; sid:100002082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.215"; classtype:trojan-activity; sid:100002083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.42"; classtype:trojan-activity; sid:100002084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.153"; classtype:trojan-activity; sid:100002085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.183"; classtype:trojan-activity; sid:100002086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.23"; classtype:trojan-activity; sid:100002087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.55"; classtype:trojan-activity; sid:100002088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.57"; classtype:trojan-activity; sid:100002089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.119"; classtype:trojan-activity; sid:100002090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.36"; classtype:trojan-activity; sid:100002091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.59"; classtype:trojan-activity; sid:100002092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.126"; classtype:trojan-activity; sid:100002093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.139"; classtype:trojan-activity; sid:100002094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.144"; classtype:trojan-activity; sid:100002095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.253"; classtype:trojan-activity; sid:100002096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.68"; classtype:trojan-activity; sid:100002097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.127"; classtype:trojan-activity; sid:100002098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.140"; classtype:trojan-activity; sid:100002099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.166"; classtype:trojan-activity; sid:100002100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.181"; classtype:trojan-activity; sid:100002101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.182"; classtype:trojan-activity; sid:100002102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.69"; classtype:trojan-activity; sid:100002103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.157"; classtype:trojan-activity; sid:100002104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.169"; classtype:trojan-activity; sid:100002105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.24"; classtype:trojan-activity; sid:100002106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.125"; classtype:trojan-activity; sid:100002107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.139"; classtype:trojan-activity; sid:100002108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.175"; classtype:trojan-activity; sid:100002109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.179"; classtype:trojan-activity; sid:100002110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.183"; classtype:trojan-activity; sid:100002111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.198"; classtype:trojan-activity; sid:100002112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.210"; classtype:trojan-activity; sid:100002113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.215"; classtype:trojan-activity; sid:100002114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.225"; classtype:trojan-activity; sid:100002115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.84"; classtype:trojan-activity; sid:100002116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.95"; classtype:trojan-activity; sid:100002117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.122"; classtype:trojan-activity; sid:100002118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.167"; classtype:trojan-activity; sid:100002119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.172"; classtype:trojan-activity; sid:100002120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.21"; classtype:trojan-activity; sid:100002121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.212"; classtype:trojan-activity; sid:100002122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.244"; classtype:trojan-activity; sid:100002123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.4"; classtype:trojan-activity; sid:100002124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.74"; classtype:trojan-activity; sid:100002125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.108"; classtype:trojan-activity; sid:100002126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.13"; classtype:trojan-activity; sid:100002127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.15"; classtype:trojan-activity; sid:100002128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.244"; classtype:trojan-activity; sid:100002129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.253"; classtype:trojan-activity; sid:100002130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.40"; classtype:trojan-activity; sid:100002131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.96"; classtype:trojan-activity; sid:100002132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.128"; classtype:trojan-activity; sid:100002133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.132"; classtype:trojan-activity; sid:100002134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.141"; classtype:trojan-activity; sid:100002135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.186"; classtype:trojan-activity; sid:100002136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.215"; classtype:trojan-activity; sid:100002137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.231"; classtype:trojan-activity; sid:100002138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.253"; classtype:trojan-activity; sid:100002139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.45"; classtype:trojan-activity; sid:100002140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.12"; classtype:trojan-activity; sid:100002141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.143"; classtype:trojan-activity; sid:100002142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.150"; classtype:trojan-activity; sid:100002143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.159"; classtype:trojan-activity; sid:100002144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.34"; classtype:trojan-activity; sid:100002145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.45"; classtype:trojan-activity; sid:100002146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.62"; classtype:trojan-activity; sid:100002147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.93"; classtype:trojan-activity; sid:100002148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.195"; classtype:trojan-activity; sid:100002149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.200"; classtype:trojan-activity; sid:100002150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.40"; classtype:trojan-activity; sid:100002151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.55"; classtype:trojan-activity; sid:100002152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.141"; classtype:trojan-activity; sid:100002153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.17"; classtype:trojan-activity; sid:100002154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.227"; classtype:trojan-activity; sid:100002155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.237"; classtype:trojan-activity; sid:100002156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.4"; classtype:trojan-activity; sid:100002157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.56"; classtype:trojan-activity; sid:100002158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.169"; classtype:trojan-activity; sid:100002159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.192"; classtype:trojan-activity; sid:100002160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.1"; classtype:trojan-activity; sid:100002161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.128"; classtype:trojan-activity; sid:100002162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.135"; classtype:trojan-activity; sid:100002163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.143"; classtype:trojan-activity; sid:100002164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.78"; classtype:trojan-activity; sid:100002165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.228"; classtype:trojan-activity; sid:100002166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.254"; classtype:trojan-activity; sid:100002167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.29"; classtype:trojan-activity; sid:100002168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.36"; classtype:trojan-activity; sid:100002169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.68"; classtype:trojan-activity; sid:100002170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.123"; classtype:trojan-activity; sid:100002171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.130"; classtype:trojan-activity; sid:100002172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.22"; classtype:trojan-activity; sid:100002173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.45"; classtype:trojan-activity; sid:100002174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.88"; classtype:trojan-activity; sid:100002175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.91"; classtype:trojan-activity; sid:100002176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.19.183.14"; classtype:trojan-activity; sid:100002177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.205.101.33"; classtype:trojan-activity; sid:100002178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.21.164.68"; classtype:trojan-activity; sid:100002179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.217.8.194"; classtype:trojan-activity; sid:100002180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.22.117.102"; classtype:trojan-activity; sid:100002181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.222.252.130"; classtype:trojan-activity; sid:100002182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.34.183.30"; classtype:trojan-activity; sid:100002183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.48.235.59"; classtype:trojan-activity; sid:100002184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.92.246.246"; classtype:trojan-activity; sid:100002185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.95.115.33"; classtype:trojan-activity; sid:100002186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.95.136.35"; classtype:trojan-activity; sid:100002187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.159.58.134"; classtype:trojan-activity; sid:100002188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.4.187.39"; classtype:trojan-activity; sid:100002189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.43.157.173"; classtype:trojan-activity; sid:100002190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.60.84.7"; classtype:trojan-activity; sid:100002191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.99.210.161"; classtype:trojan-activity; sid:100002192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.109.36.244"; classtype:trojan-activity; sid:100002193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.111.101.141"; classtype:trojan-activity; sid:100002194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.114.111.153"; classtype:trojan-activity; sid:100002195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.116.203.220"; classtype:trojan-activity; sid:100002196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.120.149.106"; classtype:trojan-activity; sid:100002197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.122.13.227"; classtype:trojan-activity; sid:100002198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.125.44.194"; classtype:trojan-activity; sid:100002199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.157.66.204"; classtype:trojan-activity; sid:100002200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.175.236.209"; classtype:trojan-activity; sid:100002201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.175.93.52"; classtype:trojan-activity; sid:100002202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.105.41"; classtype:trojan-activity; sid:100002203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.110.243"; classtype:trojan-activity; sid:100002204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.165.230"; classtype:trojan-activity; sid:100002205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.214.171"; classtype:trojan-activity; sid:100002206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.34.51"; classtype:trojan-activity; sid:100002207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.96.248"; classtype:trojan-activity; sid:100002208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.104.65"; classtype:trojan-activity; sid:100002209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.242.73"; classtype:trojan-activity; sid:100002210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.218.5.171"; classtype:trojan-activity; sid:100002211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.248.80.38"; classtype:trojan-activity; sid:100002212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.111.36"; classtype:trojan-activity; sid:100002213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.53.93"; classtype:trojan-activity; sid:100002214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.94.170.166"; classtype:trojan-activity; sid:100002215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.138.154"; classtype:trojan-activity; sid:100002216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.238"; classtype:trojan-activity; sid:100002217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.6"; classtype:trojan-activity; sid:100002218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.143.60.163"; classtype:trojan-activity; sid:100002219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.193.107.10"; classtype:trojan-activity; sid:100002220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.222"; classtype:trojan-activity; sid:100002221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.230"; classtype:trojan-activity; sid:100002222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.240"; classtype:trojan-activity; sid:100002223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.210.45.42"; classtype:trojan-activity; sid:100002224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.215.47.82"; classtype:trojan-activity; sid:100002225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.224.242.131"; classtype:trojan-activity; sid:100002226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.236.4"; classtype:trojan-activity; sid:100002227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.59.162"; classtype:trojan-activity; sid:100002228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.43.249"; classtype:trojan-activity; sid:100002229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.52.131"; classtype:trojan-activity; sid:100002230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.111.64"; classtype:trojan-activity; sid:100002231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.24.20"; classtype:trojan-activity; sid:100002232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.49.104"; classtype:trojan-activity; sid:100002233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.64.27"; classtype:trojan-activity; sid:100002234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.79.103"; classtype:trojan-activity; sid:100002235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.83.88"; classtype:trojan-activity; sid:100002236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.92.90"; classtype:trojan-activity; sid:100002237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.93.96"; classtype:trojan-activity; sid:100002238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.101.82"; classtype:trojan-activity; sid:100002239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.103.234"; classtype:trojan-activity; sid:100002240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.104.106"; classtype:trojan-activity; sid:100002241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.108.180"; classtype:trojan-activity; sid:100002242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.108.244"; classtype:trojan-activity; sid:100002243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.118.250"; classtype:trojan-activity; sid:100002244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.60.73"; classtype:trojan-activity; sid:100002245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.61.252"; classtype:trojan-activity; sid:100002246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.80.107"; classtype:trojan-activity; sid:100002247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.94.196"; classtype:trojan-activity; sid:100002248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.99.150"; classtype:trojan-activity; sid:100002249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.15.172"; classtype:trojan-activity; sid:100002250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.25.120"; classtype:trojan-activity; sid:100002251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.26.235"; classtype:trojan-activity; sid:100002252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.29.220"; classtype:trojan-activity; sid:100002253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.39.51"; classtype:trojan-activity; sid:100002254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.43.27"; classtype:trojan-activity; sid:100002255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.118.146.181"; classtype:trojan-activity; sid:100002256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.100.135"; classtype:trojan-activity; sid:100002257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.109.173"; classtype:trojan-activity; sid:100002258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.118.218"; classtype:trojan-activity; sid:100002259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.14.252"; classtype:trojan-activity; sid:100002260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.166.208"; classtype:trojan-activity; sid:100002261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.176.209"; classtype:trojan-activity; sid:100002262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.211.69"; classtype:trojan-activity; sid:100002263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.214.120"; classtype:trojan-activity; sid:100002264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.221.141"; classtype:trojan-activity; sid:100002265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.225.30"; classtype:trojan-activity; sid:100002266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.255.115"; classtype:trojan-activity; sid:100002267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.7.54"; classtype:trojan-activity; sid:100002268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.22"; classtype:trojan-activity; sid:100002269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.46"; classtype:trojan-activity; sid:100002270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.33.117"; classtype:trojan-activity; sid:100002271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.37.251"; classtype:trojan-activity; sid:100002272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.43.0"; classtype:trojan-activity; sid:100002273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.11.43"; classtype:trojan-activity; sid:100002274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.129.163"; classtype:trojan-activity; sid:100002275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.130.67"; classtype:trojan-activity; sid:100002276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.133.46"; classtype:trojan-activity; sid:100002277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.134.70"; classtype:trojan-activity; sid:100002278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.158.141"; classtype:trojan-activity; sid:100002279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.205.201"; classtype:trojan-activity; sid:100002280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.205.237"; classtype:trojan-activity; sid:100002281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.207.195"; classtype:trojan-activity; sid:100002282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.40.234"; classtype:trojan-activity; sid:100002283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.50.111"; classtype:trojan-activity; sid:100002284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.66.189"; classtype:trojan-activity; sid:100002285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.9.117"; classtype:trojan-activity; sid:100002286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.94.13"; classtype:trojan-activity; sid:100002287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.181.105"; classtype:trojan-activity; sid:100002288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.202.18"; classtype:trojan-activity; sid:100002289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.123.203.21"; classtype:trojan-activity; sid:100002290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.123.211.239"; classtype:trojan-activity; sid:100002291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.123.107"; classtype:trojan-activity; sid:100002292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.177.48"; classtype:trojan-activity; sid:100002293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.19.87"; classtype:trojan-activity; sid:100002294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.88.122"; classtype:trojan-activity; sid:100002295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.113.127"; classtype:trojan-activity; sid:100002296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.120.66"; classtype:trojan-activity; sid:100002297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.126.203"; classtype:trojan-activity; sid:100002298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.127.254"; classtype:trojan-activity; sid:100002299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.181.121"; classtype:trojan-activity; sid:100002300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.52.233"; classtype:trojan-activity; sid:100002301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.67.24"; classtype:trojan-activity; sid:100002302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.80.108"; classtype:trojan-activity; sid:100002303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.83.79"; classtype:trojan-activity; sid:100002304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.88.138"; classtype:trojan-activity; sid:100002305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.103.79"; classtype:trojan-activity; sid:100002306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.104.235"; classtype:trojan-activity; sid:100002307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.110.147"; classtype:trojan-activity; sid:100002308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.152.3"; classtype:trojan-activity; sid:100002309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.155.157"; classtype:trojan-activity; sid:100002310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.209.26"; classtype:trojan-activity; sid:100002311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.221.243"; classtype:trojan-activity; sid:100002312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.160.98.250"; classtype:trojan-activity; sid:100002313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.172.36.164"; classtype:trojan-activity; sid:100002314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.233.0.252"; classtype:trojan-activity; sid:100002315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.235.252.31"; classtype:trojan-activity; sid:100002316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.53.197.62"; classtype:trojan-activity; sid:100002317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.58.219.8"; classtype:trojan-activity; sid:100002318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.104.83"; classtype:trojan-activity; sid:100002319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.225.154"; classtype:trojan-activity; sid:100002320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.109.169.45"; classtype:trojan-activity; sid:100002321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.11.238.228"; classtype:trojan-activity; sid:100002322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.136.252.233"; classtype:trojan-activity; sid:100002323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.150.138.131"; classtype:trojan-activity; sid:100002324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.150.244.122"; classtype:trojan-activity; sid:100002325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.16.208.30"; classtype:trojan-activity; sid:100002326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.185.112.19"; classtype:trojan-activity; sid:100002327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.187.163.176"; classtype:trojan-activity; sid:100002328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.151.225"; classtype:trojan-activity; sid:100002329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.180.116"; classtype:trojan-activity; sid:100002330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.188.186"; classtype:trojan-activity; sid:100002331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.228.38"; classtype:trojan-activity; sid:100002332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.105.21"; classtype:trojan-activity; sid:100002333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.125.235"; classtype:trojan-activity; sid:100002334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.127.89"; classtype:trojan-activity; sid:100002335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.26.115"; classtype:trojan-activity; sid:100002336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.99.87"; classtype:trojan-activity; sid:100002337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.92.195.140"; classtype:trojan-activity; sid:100002338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.95.147.102"; classtype:trojan-activity; sid:100002339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.97.22.14"; classtype:trojan-activity; sid:100002340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.164.185.41"; classtype:trojan-activity; sid:100002341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.175.115.10"; classtype:trojan-activity; sid:100002342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.74.149.230"; classtype:trojan-activity; sid:100002343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.106.209.68"; classtype:trojan-activity; sid:100002344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.107.3.8"; classtype:trojan-activity; sid:100002345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.172.110.235"; classtype:trojan-activity; sid:100002346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.181.10.234"; classtype:trojan-activity; sid:100002347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.112"; classtype:trojan-activity; sid:100002348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.54"; classtype:trojan-activity; sid:100002349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.77"; classtype:trojan-activity; sid:100002350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.93"; classtype:trojan-activity; sid:100002351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.219.133.122"; classtype:trojan-activity; sid:100002352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.221.3.244"; classtype:trojan-activity; sid:100002353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.228.141.74"; classtype:trojan-activity; sid:100002354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.239.243.77"; classtype:trojan-activity; sid:100002355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.245.96.94"; classtype:trojan-activity; sid:100002356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.26.113.95"; classtype:trojan-activity; sid:100002357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.34.16.231"; classtype:trojan-activity; sid:100002358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.43.19.151"; classtype:trojan-activity; sid:100002359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.45.103.212"; classtype:trojan-activity; sid:100002360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.55.1.182"; classtype:trojan-activity; sid:100002361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.68.230.207"; classtype:trojan-activity; sid:100002362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.81.157.186"; classtype:trojan-activity; sid:100002363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.185"; classtype:trojan-activity; sid:100002364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.213"; classtype:trojan-activity; sid:100002365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.160"; classtype:trojan-activity; sid:100002366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.161"; classtype:trojan-activity; sid:100002367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.219"; classtype:trojan-activity; sid:100002368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.80"; classtype:trojan-activity; sid:100002369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.90.166.56"; classtype:trojan-activity; sid:100002370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.151.144.85"; classtype:trojan-activity; sid:100002371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.219.164"; classtype:trojan-activity; sid:100002372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.112"; classtype:trojan-activity; sid:100002373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.77"; classtype:trojan-activity; sid:100002374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.91"; classtype:trojan-activity; sid:100002375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.253.150"; classtype:trojan-activity; sid:100002376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.183.131.37"; classtype:trojan-activity; sid:100002377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.225.120.173"; classtype:trojan-activity; sid:100002378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.232.44.86"; classtype:trojan-activity; sid:100002379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.28.60.184"; classtype:trojan-activity; sid:100002380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.33.112.218"; classtype:trojan-activity; sid:100002381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.33.112.228"; classtype:trojan-activity; sid:100002382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.33.112.66"; classtype:trojan-activity; sid:100002383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.33.113.241"; classtype:trojan-activity; sid:100002384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.33.113.77"; classtype:trojan-activity; sid:100002385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.4.125.48"; classtype:trojan-activity; sid:100002386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.73.188.132"; classtype:trojan-activity; sid:100002387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.12.10.98"; classtype:trojan-activity; sid:100002388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.212.200.162"; classtype:trojan-activity; sid:100002389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.233.208.103"; classtype:trojan-activity; sid:100002390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.33.71.68"; classtype:trojan-activity; sid:100002391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.21.14"; classtype:trojan-activity; sid:100002392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.231.246"; classtype:trojan-activity; sid:100002393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.113.102.18"; classtype:trojan-activity; sid:100002394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.113.81.17"; classtype:trojan-activity; sid:100002395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.13.179.87"; classtype:trojan-activity; sid:100002396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.138.200.32"; classtype:trojan-activity; sid:100002397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.152.41.141"; classtype:trojan-activity; sid:100002398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.178.50"; classtype:trojan-activity; sid:100002399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.199.59"; classtype:trojan-activity; sid:100002400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.36.163"; classtype:trojan-activity; sid:100002401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.45.140"; classtype:trojan-activity; sid:100002402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.167.159"; classtype:trojan-activity; sid:100002403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.242.144"; classtype:trojan-activity; sid:100002404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.81.100.83"; classtype:trojan-activity; sid:100002405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.83.202.25"; classtype:trojan-activity; sid:100002406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"189.222.157.241"; classtype:trojan-activity; sid:100002407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"19.dbstrony.pl"; classtype:trojan-activity; sid:100002408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.0.42.106"; classtype:trojan-activity; sid:100002409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.109.178.139"; classtype:trojan-activity; sid:100002410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.110.161.252"; classtype:trojan-activity; sid:100002411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.111.151.164"; classtype:trojan-activity; sid:100002412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.119.207.58"; classtype:trojan-activity; sid:100002413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.12.99.194"; classtype:trojan-activity; sid:100002414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.121.194.18"; classtype:trojan-activity; sid:100002415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.160"; classtype:trojan-activity; sid:100002416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.3"; classtype:trojan-activity; sid:100002417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.37"; classtype:trojan-activity; sid:100002418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.41"; classtype:trojan-activity; sid:100002419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.42"; classtype:trojan-activity; sid:100002420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.15.212"; classtype:trojan-activity; sid:100002421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.20.14"; classtype:trojan-activity; sid:100002422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.141.117.41"; classtype:trojan-activity; sid:100002423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.147.16.184"; classtype:trojan-activity; sid:100002424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.159.240.9"; classtype:trojan-activity; sid:100002425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.187.55.150"; classtype:trojan-activity; sid:100002426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.210.214.130"; classtype:trojan-activity; sid:100002427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.177.39"; classtype:trojan-activity; sid:100002428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.226.63"; classtype:trojan-activity; sid:100002429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.49.207"; classtype:trojan-activity; sid:100002430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.214.24.194"; classtype:trojan-activity; sid:100002431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.216.140.123"; classtype:trojan-activity; sid:100002432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.35.225.36"; classtype:trojan-activity; sid:100002433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.65.206.162"; classtype:trojan-activity; sid:100002434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.92.4.231"; classtype:trojan-activity; sid:100002435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.135"; classtype:trojan-activity; sid:100002436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.200"; classtype:trojan-activity; sid:100002437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.41.33"; classtype:trojan-activity; sid:100002438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"191.255.248.220"; classtype:trojan-activity; sid:100002439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.175.130"; classtype:trojan-activity; sid:100002440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.241.200"; classtype:trojan-activity; sid:100002441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.185.106"; classtype:trojan-activity; sid:100002442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.209.27"; classtype:trojan-activity; sid:100002443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.220.55"; classtype:trojan-activity; sid:100002444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.228.67"; classtype:trojan-activity; sid:100002445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.3.152.166"; classtype:trojan-activity; sid:100002446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.3.73.205"; classtype:trojan-activity; sid:100002447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.99.240.77"; classtype:trojan-activity; sid:100002448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.142.146.25"; classtype:trojan-activity; sid:100002449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.228.135.144"; classtype:trojan-activity; sid:100002450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.91.131.237"; classtype:trojan-activity; sid:100002451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.147.142.230"; classtype:trojan-activity; sid:100002452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.15.36.167"; classtype:trojan-activity; sid:100002453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.152.35.139"; classtype:trojan-activity; sid:100002454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.38.20.199"; classtype:trojan-activity; sid:100002455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.139.126.51"; classtype:trojan-activity; sid:100002456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.228.231.218"; classtype:trojan-activity; sid:100002457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.24.94.187"; classtype:trojan-activity; sid:100002458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.202.26.182"; classtype:trojan-activity; sid:100002459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.218.48.82"; classtype:trojan-activity; sid:100002460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.148.90"; classtype:trojan-activity; sid:100002461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.166.203"; classtype:trojan-activity; sid:100002462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.159.2.106"; classtype:trojan-activity; sid:100002463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.50.27.115"; classtype:trojan-activity; sid:100002464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.133.218"; classtype:trojan-activity; sid:100002465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.207.121"; classtype:trojan-activity; sid:100002466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.213.57"; classtype:trojan-activity; sid:100002467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.251.105"; classtype:trojan-activity; sid:100002468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.251.72.110"; classtype:trojan-activity; sid:100002469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.201.76"; classtype:trojan-activity; sid:100002470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.202.7"; classtype:trojan-activity; sid:100002471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"199.188.101.109"; classtype:trojan-activity; sid:100002472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1am.co.nz"; classtype:trojan-activity; sid:100002473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.229.89.119"; classtype:trojan-activity; sid:100002474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.249.161.188"; classtype:trojan-activity; sid:100002475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.111.158"; classtype:trojan-activity; sid:100002476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.4.24"; classtype:trojan-activity; sid:100002477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.125.182"; classtype:trojan-activity; sid:100002478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.83.152.16"; classtype:trojan-activity; sid:100002479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"20.dbstrony.pl"; classtype:trojan-activity; sid:100002480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.105.167.98"; classtype:trojan-activity; sid:100002481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.111.189.70"; classtype:trojan-activity; sid:100002482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.194.4.24"; classtype:trojan-activity; sid:100002483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.2.161.171"; classtype:trojan-activity; sid:100002484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.30.132.50"; classtype:trojan-activity; sid:100002485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.142.147.89"; classtype:trojan-activity; sid:100002486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.163.170"; classtype:trojan-activity; sid:100002487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.248.190"; classtype:trojan-activity; sid:100002488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.187.102.73"; classtype:trojan-activity; sid:100002489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.200.254.86"; classtype:trojan-activity; sid:100002490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.203.221.20"; classtype:trojan-activity; sid:100002491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.215.84.97"; classtype:trojan-activity; sid:100002492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.218.97.142"; classtype:trojan-activity; sid:100002493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.107.233.41"; classtype:trojan-activity; sid:100002494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.164.153.80"; classtype:trojan-activity; sid:100002495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.166.217.54"; classtype:trojan-activity; sid:100002496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.22"; classtype:trojan-activity; sid:100002497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.37"; classtype:trojan-activity; sid:100002498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.47"; classtype:trojan-activity; sid:100002499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.52"; classtype:trojan-activity; sid:100002500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.55"; classtype:trojan-activity; sid:100002501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.9"; classtype:trojan-activity; sid:100002502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.29.95.12"; classtype:trojan-activity; sid:100002503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.4.124.58"; classtype:trojan-activity; sid:100002504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.176.114"; classtype:trojan-activity; sid:100002505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.191.174"; classtype:trojan-activity; sid:100002506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.74.236.9"; classtype:trojan-activity; sid:100002507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.109.201.243"; classtype:trojan-activity; sid:100002508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.130.69.205"; classtype:trojan-activity; sid:100002509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.170.115.82"; classtype:trojan-activity; sid:100002510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.189.156.107"; classtype:trojan-activity; sid:100002511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.204.232.18"; classtype:trojan-activity; sid:100002512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.229.21.56"; classtype:trojan-activity; sid:100002513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.236.190.28"; classtype:trojan-activity; sid:100002514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.238.86.202"; classtype:trojan-activity; sid:100002515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.70.166.107"; classtype:trojan-activity; sid:100002516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.77.80.159"; classtype:trojan-activity; sid:100002517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.119.166"; classtype:trojan-activity; sid:100002518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.171.138"; classtype:trojan-activity; sid:100002519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.82.36.34"; classtype:trojan-activity; sid:100002520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.82.49.122"; classtype:trojan-activity; sid:100002521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.93.6.28"; classtype:trojan-activity; sid:100002522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"204.195.116.171"; classtype:trojan-activity; sid:100002523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"205.185.115.74"; classtype:trojan-activity; sid:100002524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"205.185.123.217"; classtype:trojan-activity; sid:100002525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.248.137.132"; classtype:trojan-activity; sid:100002526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.47.41.166"; classtype:trojan-activity; sid:100002527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.5.32.6"; classtype:trojan-activity; sid:100002528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.163.58.18"; classtype:trojan-activity; sid:100002529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.39.50"; classtype:trojan-activity; sid:100002530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.190"; classtype:trojan-activity; sid:100002531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.31"; classtype:trojan-activity; sid:100002532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.145.60.38"; classtype:trojan-activity; sid:100002533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.124.149.19"; classtype:trojan-activity; sid:100002534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.152.122"; classtype:trojan-activity; sid:100002535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.153.142"; classtype:trojan-activity; sid:100002536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.234.93"; classtype:trojan-activity; sid:100002537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.237.70"; classtype:trojan-activity; sid:100002538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.245.109"; classtype:trojan-activity; sid:100002539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.68.242.114"; classtype:trojan-activity; sid:100002540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.96.116.236"; classtype:trojan-activity; sid:100002541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.116.220.37"; classtype:trojan-activity; sid:100002542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.172.11.169"; classtype:trojan-activity; sid:100002543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.179.43.109"; classtype:trojan-activity; sid:100002544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.132.204"; classtype:trojan-activity; sid:100002545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.75.220"; classtype:trojan-activity; sid:100002546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.204.215.157"; classtype:trojan-activity; sid:100002547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.66.179"; classtype:trojan-activity; sid:100002548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.93.93"; classtype:trojan-activity; sid:100002549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.216.66.105"; classtype:trojan-activity; sid:100002550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.114.96"; classtype:trojan-activity; sid:100002551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.120.13"; classtype:trojan-activity; sid:100002552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.246.137"; classtype:trojan-activity; sid:100002553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.238.83.238"; classtype:trojan-activity; sid:100002554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.113.49"; classtype:trojan-activity; sid:100002555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.5.96"; classtype:trojan-activity; sid:100002556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.36.174.137"; classtype:trojan-activity; sid:100002557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.51.174.149"; classtype:trojan-activity; sid:100002558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.122.86.105"; classtype:trojan-activity; sid:100002559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.143.227.22"; classtype:trojan-activity; sid:100002560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.156.215.178"; classtype:trojan-activity; sid:100002561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.46.197.114"; classtype:trojan-activity; sid:100002562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.56.197.230"; classtype:trojan-activity; sid:100002563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.119.74.202"; classtype:trojan-activity; sid:100002564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.123.206.197"; classtype:trojan-activity; sid:100002565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.135.178.253"; classtype:trojan-activity; sid:100002566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.14.173.117"; classtype:trojan-activity; sid:100002567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.182.113"; classtype:trojan-activity; sid:100002568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.190.193"; classtype:trojan-activity; sid:100002569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.12"; classtype:trojan-activity; sid:100002570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.138"; classtype:trojan-activity; sid:100002571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.160"; classtype:trojan-activity; sid:100002572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.99"; classtype:trojan-activity; sid:100002573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.135"; classtype:trojan-activity; sid:100002574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.225"; classtype:trojan-activity; sid:100002575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.23"; classtype:trojan-activity; sid:100002576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.237"; classtype:trojan-activity; sid:100002577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.51"; classtype:trojan-activity; sid:100002578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.155"; classtype:trojan-activity; sid:100002579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.191"; classtype:trojan-activity; sid:100002580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.80"; classtype:trojan-activity; sid:100002581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.1"; classtype:trojan-activity; sid:100002582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.11"; classtype:trojan-activity; sid:100002583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.26"; classtype:trojan-activity; sid:100002584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.33"; classtype:trojan-activity; sid:100002585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.71"; classtype:trojan-activity; sid:100002586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.132"; classtype:trojan-activity; sid:100002587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.192"; classtype:trojan-activity; sid:100002588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.203"; classtype:trojan-activity; sid:100002589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.33"; classtype:trojan-activity; sid:100002590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.85"; classtype:trojan-activity; sid:100002591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.117.122"; classtype:trojan-activity; sid:100002592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.117.151"; classtype:trojan-activity; sid:100002593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.117.97"; classtype:trojan-activity; sid:100002594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.129"; classtype:trojan-activity; sid:100002595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.144"; classtype:trojan-activity; sid:100002596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.238"; classtype:trojan-activity; sid:100002597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.65"; classtype:trojan-activity; sid:100002598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.119.24"; classtype:trojan-activity; sid:100002599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.119.240"; classtype:trojan-activity; sid:100002600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.104"; classtype:trojan-activity; sid:100002601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.20"; classtype:trojan-activity; sid:100002602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.243"; classtype:trojan-activity; sid:100002603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.60"; classtype:trojan-activity; sid:100002604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.7"; classtype:trojan-activity; sid:100002605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.84"; classtype:trojan-activity; sid:100002606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.204"; classtype:trojan-activity; sid:100002607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.217"; classtype:trojan-activity; sid:100002608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.46"; classtype:trojan-activity; sid:100002609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.189.178.163"; classtype:trojan-activity; sid:100002610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.226.140.23"; classtype:trojan-activity; sid:100002611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.240.218.15"; classtype:trojan-activity; sid:100002612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.249.156.189"; classtype:trojan-activity; sid:100002613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.27.8.6"; classtype:trojan-activity; sid:100002614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.80.44.17"; classtype:trojan-activity; sid:100002615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.87.87.173"; classtype:trojan-activity; sid:100002616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.254.52"; classtype:trojan-activity; sid:100002617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.36"; classtype:trojan-activity; sid:100002618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.84"; classtype:trojan-activity; sid:100002619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.127.185.150"; classtype:trojan-activity; sid:100002620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.170.240.98"; classtype:trojan-activity; sid:100002621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.183.54.169"; classtype:trojan-activity; sid:100002622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.36.12.98"; classtype:trojan-activity; sid:100002623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.11.75.162"; classtype:trojan-activity; sid:100002624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.127.133.214"; classtype:trojan-activity; sid:100002625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.8.228.92"; classtype:trojan-activity; sid:100002626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.12.162.39"; classtype:trojan-activity; sid:100002627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.12.181.110"; classtype:trojan-activity; sid:100002628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.2.40.34"; classtype:trojan-activity; sid:100002629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.215.243.65"; classtype:trojan-activity; sid:100002630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.238.246.3"; classtype:trojan-activity; sid:100002631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.28.160.174"; classtype:trojan-activity; sid:100002632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.207.119"; classtype:trojan-activity; sid:100002633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.227.133"; classtype:trojan-activity; sid:100002634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.68.35"; classtype:trojan-activity; sid:100002635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.81.81"; classtype:trojan-activity; sid:100002636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.48.135.50"; classtype:trojan-activity; sid:100002637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.56.93.129"; classtype:trojan-activity; sid:100002638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.57.53.55"; classtype:trojan-activity; sid:100002639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.59.116.203"; classtype:trojan-activity; sid:100002640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.72.198.15"; classtype:trojan-activity; sid:100002641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.79.103.159"; classtype:trojan-activity; sid:100002642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.63"; classtype:trojan-activity; sid:100002643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.75"; classtype:trojan-activity; sid:100002644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.103.40"; classtype:trojan-activity; sid:100002645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.114.132"; classtype:trojan-activity; sid:100002646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.114.45"; classtype:trojan-activity; sid:100002647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.115.250"; classtype:trojan-activity; sid:100002648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.126.205"; classtype:trojan-activity; sid:100002649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.147.58"; classtype:trojan-activity; sid:100002650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.148.116"; classtype:trojan-activity; sid:100002651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.173.163"; classtype:trojan-activity; sid:100002652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.102.14"; classtype:trojan-activity; sid:100002653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.113.58"; classtype:trojan-activity; sid:100002654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.14.17"; classtype:trojan-activity; sid:100002655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.170.22"; classtype:trojan-activity; sid:100002656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.24.246"; classtype:trojan-activity; sid:100002657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.243.184"; classtype:trojan-activity; sid:100002658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.26.204"; classtype:trojan-activity; sid:100002659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.26.37"; classtype:trojan-activity; sid:100002660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.29.165"; classtype:trojan-activity; sid:100002661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.31.15"; classtype:trojan-activity; sid:100002662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.31.67"; classtype:trojan-activity; sid:100002663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.42.216"; classtype:trojan-activity; sid:100002664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.98.64"; classtype:trojan-activity; sid:100002665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.131.116"; classtype:trojan-activity; sid:100002666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.167.103"; classtype:trojan-activity; sid:100002667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.17.217"; classtype:trojan-activity; sid:100002668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.23.29"; classtype:trojan-activity; sid:100002669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.60.224"; classtype:trojan-activity; sid:100002670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.88.219"; classtype:trojan-activity; sid:100002671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.9.32"; classtype:trojan-activity; sid:100002672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.11.39"; classtype:trojan-activity; sid:100002673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.146.200"; classtype:trojan-activity; sid:100002674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.147.87"; classtype:trojan-activity; sid:100002675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.150.91"; classtype:trojan-activity; sid:100002676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.178.201"; classtype:trojan-activity; sid:100002677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.178.210"; classtype:trojan-activity; sid:100002678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.183.29"; classtype:trojan-activity; sid:100002679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.223.241"; classtype:trojan-activity; sid:100002680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.223.245"; classtype:trojan-activity; sid:100002681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.42.228"; classtype:trojan-activity; sid:100002682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.67.171"; classtype:trojan-activity; sid:100002683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.241.6.180"; classtype:trojan-activity; sid:100002684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.148"; classtype:trojan-activity; sid:100002685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.84"; classtype:trojan-activity; sid:100002686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.163.7"; classtype:trojan-activity; sid:100002687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.171.144"; classtype:trojan-activity; sid:100002688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.251.32"; classtype:trojan-activity; sid:100002689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.5.140"; classtype:trojan-activity; sid:100002690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.69.71.186"; classtype:trojan-activity; sid:100002691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.80.217.209"; classtype:trojan-activity; sid:100002692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.85.145.194"; classtype:trojan-activity; sid:100002693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"21robo.com"; classtype:trojan-activity; sid:100002694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.118.168.155"; classtype:trojan-activity; sid:100002695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.126.237.74"; classtype:trojan-activity; sid:100002696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.133.30.200"; classtype:trojan-activity; sid:100002697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.200.22.163"; classtype:trojan-activity; sid:100002698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.71.239.115"; classtype:trojan-activity; sid:100002699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.1.162.82"; classtype:trojan-activity; sid:100002700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.124.78.15"; classtype:trojan-activity; sid:100002701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.11.33"; classtype:trojan-activity; sid:100002702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.122.127"; classtype:trojan-activity; sid:100002703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.165.237"; classtype:trojan-activity; sid:100002704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.47.162"; classtype:trojan-activity; sid:100002705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.58.5"; classtype:trojan-activity; sid:100002706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.108.55"; classtype:trojan-activity; sid:100002707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.125.190"; classtype:trojan-activity; sid:100002708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.127.124"; classtype:trojan-activity; sid:100002709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.147.220"; classtype:trojan-activity; sid:100002710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.21.133"; classtype:trojan-activity; sid:100002711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.212.123"; classtype:trojan-activity; sid:100002712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.234.159"; classtype:trojan-activity; sid:100002713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.236.211"; classtype:trojan-activity; sid:100002714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.237.107"; classtype:trojan-activity; sid:100002715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.250.213"; classtype:trojan-activity; sid:100002716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.253.236"; classtype:trojan-activity; sid:100002717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.54.237"; classtype:trojan-activity; sid:100002718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.55.56"; classtype:trojan-activity; sid:100002719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.157.191.178"; classtype:trojan-activity; sid:100002720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.136.213"; classtype:trojan-activity; sid:100002721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.104"; classtype:trojan-activity; sid:100002722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.107"; classtype:trojan-activity; sid:100002723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.224"; classtype:trojan-activity; sid:100002724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.196.12.96"; classtype:trojan-activity; sid:100002725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.198.167.192"; classtype:trojan-activity; sid:100002726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.2.190.22"; classtype:trojan-activity; sid:100002727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.130.147"; classtype:trojan-activity; sid:100002728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.224.184"; classtype:trojan-activity; sid:100002729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.116.167"; classtype:trojan-activity; sid:100002730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.172.207"; classtype:trojan-activity; sid:100002731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.184.31"; classtype:trojan-activity; sid:100002732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.237.220"; classtype:trojan-activity; sid:100002733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.252.64"; classtype:trojan-activity; sid:100002734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.8.64"; classtype:trojan-activity; sid:100002735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.1.82"; classtype:trojan-activity; sid:100002736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.179.70"; classtype:trojan-activity; sid:100002737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.137.36"; classtype:trojan-activity; sid:100002738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.142.206"; classtype:trojan-activity; sid:100002739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.112.125"; classtype:trojan-activity; sid:100002740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.32.88"; classtype:trojan-activity; sid:100002741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.34.43"; classtype:trojan-activity; sid:100002742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.43.223"; classtype:trojan-activity; sid:100002743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.68.16"; classtype:trojan-activity; sid:100002744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.108.17.64"; classtype:trojan-activity; sid:100002745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.119.65.145"; classtype:trojan-activity; sid:100002746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.132.125.138"; classtype:trojan-activity; sid:100002747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.102.202"; classtype:trojan-activity; sid:100002748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.103.120"; classtype:trojan-activity; sid:100002749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.105.87"; classtype:trojan-activity; sid:100002750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.219.29"; classtype:trojan-activity; sid:100002751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.26.161"; classtype:trojan-activity; sid:100002752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.67.115"; classtype:trojan-activity; sid:100002753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.136.49.252"; classtype:trojan-activity; sid:100002754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.136.53.227"; classtype:trojan-activity; sid:100002755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.101.251"; classtype:trojan-activity; sid:100002756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.101.33"; classtype:trojan-activity; sid:100002757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.121.127"; classtype:trojan-activity; sid:100002758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.137.5"; classtype:trojan-activity; sid:100002759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.138.252"; classtype:trojan-activity; sid:100002760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.148.192"; classtype:trojan-activity; sid:100002761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.160.202"; classtype:trojan-activity; sid:100002762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.172.250"; classtype:trojan-activity; sid:100002763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.198.247"; classtype:trojan-activity; sid:100002764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.239.124"; classtype:trojan-activity; sid:100002765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.49.36"; classtype:trojan-activity; sid:100002766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.5.150"; classtype:trojan-activity; sid:100002767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.57.234"; classtype:trojan-activity; sid:100002768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.72.146"; classtype:trojan-activity; sid:100002769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.85.26"; classtype:trojan-activity; sid:100002770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.96.9"; classtype:trojan-activity; sid:100002771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.143.84"; classtype:trojan-activity; sid:100002772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.151.100"; classtype:trojan-activity; sid:100002773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.189.138"; classtype:trojan-activity; sid:100002774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.201.241"; classtype:trojan-activity; sid:100002775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.23.254"; classtype:trojan-activity; sid:100002776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.96.79"; classtype:trojan-activity; sid:100002777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.139.16.229"; classtype:trojan-activity; sid:100002778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.129.239"; classtype:trojan-activity; sid:100002779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.162.140"; classtype:trojan-activity; sid:100002780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.163.112"; classtype:trojan-activity; sid:100002781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.17.245"; classtype:trojan-activity; sid:100002782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.209.222"; classtype:trojan-activity; sid:100002783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.254.11"; classtype:trojan-activity; sid:100002784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.39.66"; classtype:trojan-activity; sid:100002785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.120.26"; classtype:trojan-activity; sid:100002786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.13.77"; classtype:trojan-activity; sid:100002787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.44.36"; classtype:trojan-activity; sid:100002788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.73.249"; classtype:trojan-activity; sid:100002789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.9.0"; classtype:trojan-activity; sid:100002790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.162.164"; classtype:trojan-activity; sid:100002791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.192.66"; classtype:trojan-activity; sid:100002792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.209.231"; classtype:trojan-activity; sid:100002793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.209.7"; classtype:trojan-activity; sid:100002794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.245.207"; classtype:trojan-activity; sid:100002795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.179.215.189"; classtype:trojan-activity; sid:100002796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.185.116.233"; classtype:trojan-activity; sid:100002797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.186.20.19"; classtype:trojan-activity; sid:100002798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.187.184.136"; classtype:trojan-activity; sid:100002799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.187.9.178"; classtype:trojan-activity; sid:100002800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.211.72.66"; classtype:trojan-activity; sid:100002801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.214.54.208"; classtype:trojan-activity; sid:100002802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.218.220.219"; classtype:trojan-activity; sid:100002803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.236.85.220"; classtype:trojan-activity; sid:100002804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.238.230.7"; classtype:trojan-activity; sid:100002805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.239.83.232"; classtype:trojan-activity; sid:100002806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.248.64.253"; classtype:trojan-activity; sid:100002807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.83.150.240"; classtype:trojan-activity; sid:100002808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.92.9.126"; classtype:trojan-activity; sid:100002809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.99.171.192"; classtype:trojan-activity; sid:100002810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.166.117.210"; classtype:trojan-activity; sid:100002811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.167.118.17"; classtype:trojan-activity; sid:100002812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.225.68"; classtype:trojan-activity; sid:100002813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.234.84"; classtype:trojan-activity; sid:100002814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.5.29"; classtype:trojan-activity; sid:100002815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.73.175"; classtype:trojan-activity; sid:100002816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.125.186.135"; classtype:trojan-activity; sid:100002817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.126.120.25"; classtype:trojan-activity; sid:100002818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.228.143.58"; classtype:trojan-activity; sid:100002819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.24.213.121"; classtype:trojan-activity; sid:100002820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.149.13"; classtype:trojan-activity; sid:100002821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.21.167"; classtype:trojan-activity; sid:100002822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.95.89.21"; classtype:trojan-activity; sid:100002823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.103.74.180"; classtype:trojan-activity; sid:100002824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.11.141.134"; classtype:trojan-activity; sid:100002825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.119.158.74"; classtype:trojan-activity; sid:100002826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.137.147.95"; classtype:trojan-activity; sid:100002827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.152.235.88"; classtype:trojan-activity; sid:100002828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.158.25.98"; classtype:trojan-activity; sid:100002829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.176.206.12"; classtype:trojan-activity; sid:100002830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.184.1.41"; classtype:trojan-activity; sid:100002831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.192.191.109"; classtype:trojan-activity; sid:100002832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.225.114.161"; classtype:trojan-activity; sid:100002833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.227.190.78"; classtype:trojan-activity; sid:100002834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.35.245.52"; classtype:trojan-activity; sid:100002835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.181.18"; classtype:trojan-activity; sid:100002836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.34.242"; classtype:trojan-activity; sid:100002837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.42.229.143"; classtype:trojan-activity; sid:100002838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.45.4.1"; classtype:trojan-activity; sid:100002839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.51.91.113"; classtype:trojan-activity; sid:100002840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.10"; classtype:trojan-activity; sid:100002841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.9"; classtype:trojan-activity; sid:100002842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.dbstrony.pl"; classtype:trojan-activity; sid:100002843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.16"; classtype:trojan-activity; sid:100002844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.7"; classtype:trojan-activity; sid:100002845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.106.201"; classtype:trojan-activity; sid:100002846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.152.107"; classtype:trojan-activity; sid:100002847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.116.84.57"; classtype:trojan-activity; sid:100002848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.12.245.238"; classtype:trojan-activity; sid:100002849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.141.218.17"; classtype:trojan-activity; sid:100002850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.29.52"; classtype:trojan-activity; sid:100002851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.40.128"; classtype:trojan-activity; sid:100002852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.153.207.1"; classtype:trojan-activity; sid:100002853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.184.244.14"; classtype:trojan-activity; sid:100002854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.184.54.199"; classtype:trojan-activity; sid:100002855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.187.248.22"; classtype:trojan-activity; sid:100002856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.187.250.192"; classtype:trojan-activity; sid:100002857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.196.190"; classtype:trojan-activity; sid:100002858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.217.210"; classtype:trojan-activity; sid:100002859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.149.142"; classtype:trojan-activity; sid:100002860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.158.229"; classtype:trojan-activity; sid:100002861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.192.66"; classtype:trojan-activity; sid:100002862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.210.20"; classtype:trojan-activity; sid:100002863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.17.88"; classtype:trojan-activity; sid:100002864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.22.217"; classtype:trojan-activity; sid:100002865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.23.215"; classtype:trojan-activity; sid:100002866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.24.175"; classtype:trojan-activity; sid:100002867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.28.84"; classtype:trojan-activity; sid:100002868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.148.189"; classtype:trojan-activity; sid:100002869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.232.65"; classtype:trojan-activity; sid:100002870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.3.194"; classtype:trojan-activity; sid:100002871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.34.48"; classtype:trojan-activity; sid:100002872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.110.211"; classtype:trojan-activity; sid:100002873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.140.229"; classtype:trojan-activity; sid:100002874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.2.163"; classtype:trojan-activity; sid:100002875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.23.62"; classtype:trojan-activity; sid:100002876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.32.146"; classtype:trojan-activity; sid:100002877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.201.183.149"; classtype:trojan-activity; sid:100002878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.182.201"; classtype:trojan-activity; sid:100002879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.66.46"; classtype:trojan-activity; sid:100002880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.102.12"; classtype:trojan-activity; sid:100002881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.126.194"; classtype:trojan-activity; sid:100002882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.154.105"; classtype:trojan-activity; sid:100002883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.165.138"; classtype:trojan-activity; sid:100002884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.175.203"; classtype:trojan-activity; sid:100002885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.185.42"; classtype:trojan-activity; sid:100002886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.185.48"; classtype:trojan-activity; sid:100002887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.213.79"; classtype:trojan-activity; sid:100002888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.246.96"; classtype:trojan-activity; sid:100002889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.255.42"; classtype:trojan-activity; sid:100002890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.28.115"; classtype:trojan-activity; sid:100002891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.4.188"; classtype:trojan-activity; sid:100002892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.54.217"; classtype:trojan-activity; sid:100002893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.68.144"; classtype:trojan-activity; sid:100002894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.87.75"; classtype:trojan-activity; sid:100002895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.94.134"; classtype:trojan-activity; sid:100002896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.204.253.74"; classtype:trojan-activity; sid:100002897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.205.178.110"; classtype:trojan-activity; sid:100002898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.136.101"; classtype:trojan-activity; sid:100002899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.148.106"; classtype:trojan-activity; sid:100002900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.154.122"; classtype:trojan-activity; sid:100002901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.26.218"; classtype:trojan-activity; sid:100002902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.80.209"; classtype:trojan-activity; sid:100002903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.81.66"; classtype:trojan-activity; sid:100002904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.83.48"; classtype:trojan-activity; sid:100002905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.97.81"; classtype:trojan-activity; sid:100002906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.151.126"; classtype:trojan-activity; sid:100002907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.155.31"; classtype:trojan-activity; sid:100002908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.170.203"; classtype:trojan-activity; sid:100002909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.54.91"; classtype:trojan-activity; sid:100002910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.144.57"; classtype:trojan-activity; sid:100002911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.152.10"; classtype:trojan-activity; sid:100002912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.160.177"; classtype:trojan-activity; sid:100002913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.164.18"; classtype:trojan-activity; sid:100002914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.166.13"; classtype:trojan-activity; sid:100002915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.201.212"; classtype:trojan-activity; sid:100002916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.214.139"; classtype:trojan-activity; sid:100002917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.247.130"; classtype:trojan-activity; sid:100002918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.25.59"; classtype:trojan-activity; sid:100002919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.34.2"; classtype:trojan-activity; sid:100002920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.46.167"; classtype:trojan-activity; sid:100002921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.92.64"; classtype:trojan-activity; sid:100002922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.160.222"; classtype:trojan-activity; sid:100002923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.231.15"; classtype:trojan-activity; sid:100002924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.60.21"; classtype:trojan-activity; sid:100002925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.107.125"; classtype:trojan-activity; sid:100002926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.127.11"; classtype:trojan-activity; sid:100002927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.172.245"; classtype:trojan-activity; sid:100002928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.234.28"; classtype:trojan-activity; sid:100002929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.236.134"; classtype:trojan-activity; sid:100002930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.63.243"; classtype:trojan-activity; sid:100002931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.211.251.162"; classtype:trojan-activity; sid:100002932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.104.201"; classtype:trojan-activity; sid:100002933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.109.105"; classtype:trojan-activity; sid:100002934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.109.58"; classtype:trojan-activity; sid:100002935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.145.221"; classtype:trojan-activity; sid:100002936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.167.175"; classtype:trojan-activity; sid:100002937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.175.208"; classtype:trojan-activity; sid:100002938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.220.5"; classtype:trojan-activity; sid:100002939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.255.202"; classtype:trojan-activity; sid:100002940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.255.6"; classtype:trojan-activity; sid:100002941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.84.74"; classtype:trojan-activity; sid:100002942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.214.37.129"; classtype:trojan-activity; sid:100002943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.139.242"; classtype:trojan-activity; sid:100002944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.190.172"; classtype:trojan-activity; sid:100002945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.212.209"; classtype:trojan-activity; sid:100002946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.212.80"; classtype:trojan-activity; sid:100002947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.253.149"; classtype:trojan-activity; sid:100002948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.34.242"; classtype:trojan-activity; sid:100002949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.38.119"; classtype:trojan-activity; sid:100002950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.38.166"; classtype:trojan-activity; sid:100002951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.71.243"; classtype:trojan-activity; sid:100002952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.98.242"; classtype:trojan-activity; sid:100002953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.131.66"; classtype:trojan-activity; sid:100002954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.144.66"; classtype:trojan-activity; sid:100002955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.193.217"; classtype:trojan-activity; sid:100002956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.197.193"; classtype:trojan-activity; sid:100002957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.223.246"; classtype:trojan-activity; sid:100002958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.225.28"; classtype:trojan-activity; sid:100002959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.227.95"; classtype:trojan-activity; sid:100002960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.234.98"; classtype:trojan-activity; sid:100002961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.46.85"; classtype:trojan-activity; sid:100002962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.58.120"; classtype:trojan-activity; sid:100002963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.95.56"; classtype:trojan-activity; sid:100002964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.120.226"; classtype:trojan-activity; sid:100002965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.133.53"; classtype:trojan-activity; sid:100002966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.191.58"; classtype:trojan-activity; sid:100002967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.76.48"; classtype:trojan-activity; sid:100002968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.180.172"; classtype:trojan-activity; sid:100002969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.219.228"; classtype:trojan-activity; sid:100002970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.240.158"; classtype:trojan-activity; sid:100002971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.248.121"; classtype:trojan-activity; sid:100002972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.119.149"; classtype:trojan-activity; sid:100002973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.132.71"; classtype:trojan-activity; sid:100002974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.151.83"; classtype:trojan-activity; sid:100002975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.160.112"; classtype:trojan-activity; sid:100002976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.172.175"; classtype:trojan-activity; sid:100002977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.173.180"; classtype:trojan-activity; sid:100002978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.176.72"; classtype:trojan-activity; sid:100002979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.184.94"; classtype:trojan-activity; sid:100002980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.192.223"; classtype:trojan-activity; sid:100002981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.83.244"; classtype:trojan-activity; sid:100002982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.40.189"; classtype:trojan-activity; sid:100002983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.80.93"; classtype:trojan-activity; sid:100002984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.85.168"; classtype:trojan-activity; sid:100002985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.221.239.223"; classtype:trojan-activity; sid:100002986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.241.223"; classtype:trojan-activity; sid:100002987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.249.210"; classtype:trojan-activity; sid:100002988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.42.189"; classtype:trojan-activity; sid:100002989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.50.170"; classtype:trojan-activity; sid:100002990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.223.242.164"; classtype:trojan-activity; sid:100002991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.24.28.134"; classtype:trojan-activity; sid:100002992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.107.66"; classtype:trojan-activity; sid:100002993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.129.198"; classtype:trojan-activity; sid:100002994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.154.13"; classtype:trojan-activity; sid:100002995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.212.124"; classtype:trojan-activity; sid:100002996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.58.5"; classtype:trojan-activity; sid:100002997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.143.46"; classtype:trojan-activity; sid:100002998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.9.44"; classtype:trojan-activity; sid:100002999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.44.130"; classtype:trojan-activity; sid:100003000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.44.161"; classtype:trojan-activity; sid:100003001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.46.100"; classtype:trojan-activity; sid:100003002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.46.252"; classtype:trojan-activity; sid:100003003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.23.215"; classtype:trojan-activity; sid:100003004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.34.254"; classtype:trojan-activity; sid:100003005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.46.18"; classtype:trojan-activity; sid:100003006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.6.195.65"; classtype:trojan-activity; sid:100003007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.6.240.125"; classtype:trojan-activity; sid:100003008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.6.242.65"; classtype:trojan-activity; sid:100003009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.0.98.131"; classtype:trojan-activity; sid:100003010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.11.51.57"; classtype:trojan-activity; sid:100003011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.13.23.180"; classtype:trojan-activity; sid:100003012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.154.234.3"; classtype:trojan-activity; sid:100003013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.163.191.11"; classtype:trojan-activity; sid:100003014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.179.83"; classtype:trojan-activity; sid:100003015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.184.59"; classtype:trojan-activity; sid:100003016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.191.243"; classtype:trojan-activity; sid:100003017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.194.67"; classtype:trojan-activity; sid:100003018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.216.132"; classtype:trojan-activity; sid:100003019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.219.28"; classtype:trojan-activity; sid:100003020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.24.115"; classtype:trojan-activity; sid:100003021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.30.65"; classtype:trojan-activity; sid:100003022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.60.234"; classtype:trojan-activity; sid:100003023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.63.203"; classtype:trojan-activity; sid:100003024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.65.233"; classtype:trojan-activity; sid:100003025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.94.16"; classtype:trojan-activity; sid:100003026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.179.201.26"; classtype:trojan-activity; sid:100003027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.195.84.250"; classtype:trojan-activity; sid:100003028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.177"; classtype:trojan-activity; sid:100003029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.69"; classtype:trojan-activity; sid:100003030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.28.7.159"; classtype:trojan-activity; sid:100003031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.30.119.23"; classtype:trojan-activity; sid:100003032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32.208.157.193"; classtype:trojan-activity; sid:100003033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32.218.180.9"; classtype:trojan-activity; sid:100003034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"35.184.169.169"; classtype:trojan-activity; sid:100003035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.108.231.218"; classtype:trojan-activity; sid:100003036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.250.203.246"; classtype:trojan-activity; sid:100003037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.157.225"; classtype:trojan-activity; sid:100003038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.18.18"; classtype:trojan-activity; sid:100003039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.19.88"; classtype:trojan-activity; sid:100003040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.51.244"; classtype:trojan-activity; sid:100003041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.255.90.219"; classtype:trojan-activity; sid:100003042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.128.60"; classtype:trojan-activity; sid:100003043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.160.167"; classtype:trojan-activity; sid:100003044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.34.150.236"; classtype:trojan-activity; sid:100003045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.36.243.67"; classtype:trojan-activity; sid:100003046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.105.159"; classtype:trojan-activity; sid:100003047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.111.203"; classtype:trojan-activity; sid:100003048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.133.125"; classtype:trojan-activity; sid:100003049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.139.36"; classtype:trojan-activity; sid:100003050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.89.18.133"; classtype:trojan-activity; sid:100003051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.96.187.93"; classtype:trojan-activity; sid:100003052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360.lcy2zzx.pw"; classtype:trojan-activity; sid:100003053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360down7.miiyun.cn"; classtype:trojan-activity; sid:100003054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.222.98.51"; classtype:trojan-activity; sid:100003055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.233.60.68"; classtype:trojan-activity; sid:100003056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.179.221"; classtype:trojan-activity; sid:100003057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.180.172"; classtype:trojan-activity; sid:100003058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.44.238.35"; classtype:trojan-activity; sid:100003059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.49.229.154"; classtype:trojan-activity; sid:100003060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.49.230.152"; classtype:trojan-activity; sid:100003061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.52.117.132"; classtype:trojan-activity; sid:100003062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.14.36"; classtype:trojan-activity; sid:100003063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"38.77.14.237"; classtype:trojan-activity; sid:100003064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.245.254"; classtype:trojan-activity; sid:100003065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.98.136"; classtype:trojan-activity; sid:100003066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.114.137.102"; classtype:trojan-activity; sid:100003067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.117.31.162"; classtype:trojan-activity; sid:100003068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.162.104.119"; classtype:trojan-activity; sid:100003069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.64.28.214"; classtype:trojan-activity; sid:100003070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.196.34"; classtype:trojan-activity; sid:100003071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.59.160"; classtype:trojan-activity; sid:100003072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.115.94"; classtype:trojan-activity; sid:100003073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.129.163"; classtype:trojan-activity; sid:100003074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.44.109"; classtype:trojan-activity; sid:100003075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.104.83"; classtype:trojan-activity; sid:100003076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.125.186"; classtype:trojan-activity; sid:100003077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.146.60"; classtype:trojan-activity; sid:100003078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.148.163"; classtype:trojan-activity; sid:100003079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.124.76"; classtype:trojan-activity; sid:100003080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.171.125"; classtype:trojan-activity; sid:100003081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.249.255"; classtype:trojan-activity; sid:100003082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.60.61"; classtype:trojan-activity; sid:100003083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.167.202"; classtype:trojan-activity; sid:100003084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.5.175"; classtype:trojan-activity; sid:100003085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.67.64"; classtype:trojan-activity; sid:100003086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.10.198"; classtype:trojan-activity; sid:100003087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.163.231"; classtype:trojan-activity; sid:100003088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.203.225"; classtype:trojan-activity; sid:100003089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.104.228"; classtype:trojan-activity; sid:100003090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.184.222"; classtype:trojan-activity; sid:100003091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.31.192"; classtype:trojan-activity; sid:100003092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.68.182"; classtype:trojan-activity; sid:100003093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.194.65"; classtype:trojan-activity; sid:100003094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.33.191"; classtype:trojan-activity; sid:100003095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.79.43"; classtype:trojan-activity; sid:100003096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.97.16"; classtype:trojan-activity; sid:100003097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.113.201"; classtype:trojan-activity; sid:100003098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.114.45"; classtype:trojan-activity; sid:100003099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.136.47"; classtype:trojan-activity; sid:100003100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.14.27"; classtype:trojan-activity; sid:100003101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.150.203"; classtype:trojan-activity; sid:100003102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.197.81"; classtype:trojan-activity; sid:100003103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.209.209"; classtype:trojan-activity; sid:100003104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.94.189"; classtype:trojan-activity; sid:100003105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.95.50"; classtype:trojan-activity; sid:100003106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.146.67"; classtype:trojan-activity; sid:100003107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.166.31"; classtype:trojan-activity; sid:100003108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.218.46"; classtype:trojan-activity; sid:100003109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.62.43"; classtype:trojan-activity; sid:100003110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.91.244"; classtype:trojan-activity; sid:100003111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.93.171"; classtype:trojan-activity; sid:100003112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.127.214"; classtype:trojan-activity; sid:100003113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.18.140"; classtype:trojan-activity; sid:100003114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.191.137"; classtype:trojan-activity; sid:100003115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.205.255"; classtype:trojan-activity; sid:100003116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.24.54"; classtype:trojan-activity; sid:100003117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.36.151"; classtype:trojan-activity; sid:100003118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.251.0"; classtype:trojan-activity; sid:100003119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.27.15"; classtype:trojan-activity; sid:100003120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.29.231"; classtype:trojan-activity; sid:100003121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.82.86.105"; classtype:trojan-activity; sid:100003122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.83.94.11"; classtype:trojan-activity; sid:100003123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.115.152"; classtype:trojan-activity; sid:100003124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.157.52"; classtype:trojan-activity; sid:100003125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.34.217"; classtype:trojan-activity; sid:100003126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.95.200"; classtype:trojan-activity; sid:100003127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.191"; classtype:trojan-activity; sid:100003128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.4"; classtype:trojan-activity; sid:100003129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.129.233"; classtype:trojan-activity; sid:100003130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.13.0"; classtype:trojan-activity; sid:100003131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.170.209"; classtype:trojan-activity; sid:100003132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.184.164"; classtype:trojan-activity; sid:100003133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.211.20"; classtype:trojan-activity; sid:100003134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.216.144"; classtype:trojan-activity; sid:100003135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.234.187"; classtype:trojan-activity; sid:100003136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.248.91"; classtype:trojan-activity; sid:100003137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.60.98"; classtype:trojan-activity; sid:100003138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.66.24"; classtype:trojan-activity; sid:100003139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.73.100"; classtype:trojan-activity; sid:100003140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.78.228"; classtype:trojan-activity; sid:100003141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.63.58"; classtype:trojan-activity; sid:100003142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.90.210"; classtype:trojan-activity; sid:100003143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.93.109"; classtype:trojan-activity; sid:100003144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.141.172"; classtype:trojan-activity; sid:100003145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.155.96"; classtype:trojan-activity; sid:100003146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.233.131"; classtype:trojan-activity; sid:100003147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.41.73"; classtype:trojan-activity; sid:100003148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.67.238"; classtype:trojan-activity; sid:100003149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.72.9"; classtype:trojan-activity; sid:100003150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.198"; classtype:trojan-activity; sid:100003151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.36"; classtype:trojan-activity; sid:100003152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.157.140"; classtype:trojan-activity; sid:100003153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.63.23"; classtype:trojan-activity; sid:100003154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.90.86.212"; classtype:trojan-activity; sid:100003155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"40.88.2.151"; classtype:trojan-activity; sid:100003156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.139.209.46"; classtype:trojan-activity; sid:100003157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.165.130.43"; classtype:trojan-activity; sid:100003158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.193.192.100"; classtype:trojan-activity; sid:100003159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.219.185.171"; classtype:trojan-activity; sid:100003160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.230.31.58"; classtype:trojan-activity; sid:100003161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.72.203.82"; classtype:trojan-activity; sid:100003162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.148"; classtype:trojan-activity; sid:100003163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.200"; classtype:trojan-activity; sid:100003164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.71"; classtype:trojan-activity; sid:100003165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.23"; classtype:trojan-activity; sid:100003166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.233"; classtype:trojan-activity; sid:100003167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.236"; classtype:trojan-activity; sid:100003168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.176.112.72"; classtype:trojan-activity; sid:100003169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.177.164.171"; classtype:trojan-activity; sid:100003170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.179.162.208"; classtype:trojan-activity; sid:100003171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.179.163.177"; classtype:trojan-activity; sid:100003172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.202.101.147"; classtype:trojan-activity; sid:100003173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.172.72"; classtype:trojan-activity; sid:100000574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.53.200.130"; classtype:trojan-activity; sid:100000575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.53.224.134"; classtype:trojan-activity; sid:100000576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.53.234.210"; classtype:trojan-activity; sid:100000577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.53.58.228"; classtype:trojan-activity; sid:100000578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.113.49"; classtype:trojan-activity; sid:100000579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.123.147"; classtype:trojan-activity; sid:100000580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.158.251"; classtype:trojan-activity; sid:100000581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.127.0"; classtype:trojan-activity; sid:100000582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.144.42"; classtype:trojan-activity; sid:100000583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.145.147"; classtype:trojan-activity; sid:100000584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.157.96"; classtype:trojan-activity; sid:100000585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.158.230"; classtype:trojan-activity; sid:100000586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.158.250"; classtype:trojan-activity; sid:100000587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.161.38"; classtype:trojan-activity; sid:100000588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.179.168"; classtype:trojan-activity; sid:100000589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.198.105"; classtype:trojan-activity; sid:100000590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.206.35"; classtype:trojan-activity; sid:100000591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.206.78"; classtype:trojan-activity; sid:100000592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.26.94"; classtype:trojan-activity; sid:100000593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.42.200"; classtype:trojan-activity; sid:100000594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.52.17"; classtype:trojan-activity; sid:100000595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.111.63"; classtype:trojan-activity; sid:100000596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.114.17"; classtype:trojan-activity; sid:100000597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.131.150"; classtype:trojan-activity; sid:100000598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.133.96"; classtype:trojan-activity; sid:100000599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.134.79"; classtype:trojan-activity; sid:100000600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.135.255"; classtype:trojan-activity; sid:100000601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.137.48"; classtype:trojan-activity; sid:100000602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.139.122"; classtype:trojan-activity; sid:100000603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.142.45"; classtype:trojan-activity; sid:100000604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.145.102"; classtype:trojan-activity; sid:100000605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.148.22"; classtype:trojan-activity; sid:100000606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.150.149"; classtype:trojan-activity; sid:100000607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.151.65"; classtype:trojan-activity; sid:100000608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.151.68"; classtype:trojan-activity; sid:100000609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.154.147"; classtype:trojan-activity; sid:100000610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.155.50"; classtype:trojan-activity; sid:100000611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.189.162"; classtype:trojan-activity; sid:100000612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.31.11"; classtype:trojan-activity; sid:100000613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.31.54"; classtype:trojan-activity; sid:100000614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.98.205"; classtype:trojan-activity; sid:100000615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.99.235"; classtype:trojan-activity; sid:100000616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.132.199"; classtype:trojan-activity; sid:100000617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.134.143"; classtype:trojan-activity; sid:100000618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.86.217"; classtype:trojan-activity; sid:100000619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.90.143"; classtype:trojan-activity; sid:100000620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.91.65"; classtype:trojan-activity; sid:100000621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.198.69"; classtype:trojan-activity; sid:100000622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.212.193"; classtype:trojan-activity; sid:100000623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.214.107"; classtype:trojan-activity; sid:100000624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.228.237"; classtype:trojan-activity; sid:100000625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.253.202"; classtype:trojan-activity; sid:100000626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.57.171"; classtype:trojan-activity; sid:100000627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.82.123"; classtype:trojan-activity; sid:100000628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.103.197"; classtype:trojan-activity; sid:100000629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.112.159"; classtype:trojan-activity; sid:100000630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.118.201"; classtype:trojan-activity; sid:100000631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.118.90"; classtype:trojan-activity; sid:100000632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.158.98"; classtype:trojan-activity; sid:100000633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.155.83"; classtype:trojan-activity; sid:100000634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.171.143"; classtype:trojan-activity; sid:100000635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.26.39"; classtype:trojan-activity; sid:100000636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.131.173"; classtype:trojan-activity; sid:100000637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.139.175"; classtype:trojan-activity; sid:100000638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.141.147"; classtype:trojan-activity; sid:100000639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.180.149"; classtype:trojan-activity; sid:100000640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.189.77"; classtype:trojan-activity; sid:100000641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.21.130"; classtype:trojan-activity; sid:100000642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.53.188"; classtype:trojan-activity; sid:100000643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.73.3.11"; classtype:trojan-activity; sid:100000644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.75.217.79"; classtype:trojan-activity; sid:100000645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.78.133.146"; classtype:trojan-activity; sid:100000646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.92.174.231"; classtype:trojan-activity; sid:100000647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.97.139.32"; classtype:trojan-activity; sid:100000648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.124.219.2"; classtype:trojan-activity; sid:100000649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.149.243.14"; classtype:trojan-activity; sid:100000650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.206.164.46"; classtype:trojan-activity; sid:100000651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.207.71.237"; classtype:trojan-activity; sid:100000652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.211.100.26"; classtype:trojan-activity; sid:100000653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.212.132.119"; classtype:trojan-activity; sid:100000654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.212.142.215"; classtype:trojan-activity; sid:100000655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.30.4.2"; classtype:trojan-activity; sid:100000656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.30.95.156"; classtype:trojan-activity; sid:100000657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.72.28.239"; classtype:trojan-activity; sid:100000658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.73.52.125"; classtype:trojan-activity; sid:100000659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.74.101.150"; classtype:trojan-activity; sid:100000660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.74.17.122"; classtype:trojan-activity; sid:100000661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.75.193.33"; classtype:trojan-activity; sid:100000662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.75.198.85"; classtype:trojan-activity; sid:100000663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.75.212.81"; classtype:trojan-activity; sid:100000664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.76.114.71"; classtype:trojan-activity; sid:100000665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.9.43.220"; classtype:trojan-activity; sid:100000666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.11.234.35"; classtype:trojan-activity; sid:100000667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.12.48.157"; classtype:trojan-activity; sid:100000668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.156.69.22"; classtype:trojan-activity; sid:100000669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.148.198"; classtype:trojan-activity; sid:100000670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.160.203"; classtype:trojan-activity; sid:100000671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.164.123"; classtype:trojan-activity; sid:100000672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.167.131"; classtype:trojan-activity; sid:100000673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.196.48.148"; classtype:trojan-activity; sid:100000674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.196.48.181"; classtype:trojan-activity; sid:100000675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.196.50.154"; classtype:trojan-activity; sid:100000676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.196.50.239"; classtype:trojan-activity; sid:100000677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.196.50.76"; classtype:trojan-activity; sid:100000678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.138"; classtype:trojan-activity; sid:100000679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.5"; classtype:trojan-activity; sid:100000680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.210.52"; classtype:trojan-activity; sid:100000681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.236.14"; classtype:trojan-activity; sid:100000682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.243.40"; classtype:trojan-activity; sid:100000683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.200.76.54"; classtype:trojan-activity; sid:100000684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.200.76.60"; classtype:trojan-activity; sid:100000685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.67.92"; classtype:trojan-activity; sid:100000686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.208.132.10"; classtype:trojan-activity; sid:100000687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.208.132.45"; classtype:trojan-activity; sid:100000688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.44.102"; classtype:trojan-activity; sid:100000689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.161.42"; classtype:trojan-activity; sid:100000690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.164.100"; classtype:trojan-activity; sid:100000691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.164.189"; classtype:trojan-activity; sid:100000692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.173.218"; classtype:trojan-activity; sid:100000693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.175.120"; classtype:trojan-activity; sid:100000694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.241.64.105"; classtype:trojan-activity; sid:100000695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.248.62.29"; classtype:trojan-activity; sid:100000696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.26.235.164"; classtype:trojan-activity; sid:100000697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.27.10.73"; classtype:trojan-activity; sid:100000698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.60.204.190"; classtype:trojan-activity; sid:100000699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.113.146"; classtype:trojan-activity; sid:100000700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.195.140"; classtype:trojan-activity; sid:100000701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.252.82"; classtype:trojan-activity; sid:100000702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.53.15"; classtype:trojan-activity; sid:100000703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.86.105.110"; classtype:trojan-activity; sid:100000704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.91.240.50"; classtype:trojan-activity; sid:100000705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.93.115.242"; classtype:trojan-activity; sid:100000706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.93.79.40"; classtype:trojan-activity; sid:100000707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.114.84.237"; classtype:trojan-activity; sid:100000708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.172.176.41"; classtype:trojan-activity; sid:100000709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.104.35"; classtype:trojan-activity; sid:100000710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.157.64"; classtype:trojan-activity; sid:100000711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.7.132"; classtype:trojan-activity; sid:100000712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.211.38.112"; classtype:trojan-activity; sid:100000713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.32.74"; classtype:trojan-activity; sid:100000714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.5.149"; classtype:trojan-activity; sid:100000715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.72.141"; classtype:trojan-activity; sid:100000716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.12.130"; classtype:trojan-activity; sid:100000717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.128.147"; classtype:trojan-activity; sid:100000718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.208.215"; classtype:trojan-activity; sid:100000719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.209.108"; classtype:trojan-activity; sid:100000720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.214.72"; classtype:trojan-activity; sid:100000721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.88.146"; classtype:trojan-activity; sid:100000722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.150"; classtype:trojan-activity; sid:100000723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.6"; classtype:trojan-activity; sid:100000724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.221.162"; classtype:trojan-activity; sid:100000725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.63.194"; classtype:trojan-activity; sid:100000726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.65.93"; classtype:trojan-activity; sid:100000727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.250.51.192"; classtype:trojan-activity; sid:100000728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.42.125.246"; classtype:trojan-activity; sid:100000729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.43.180.33"; classtype:trojan-activity; sid:100000730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.70.83.140"; classtype:trojan-activity; sid:100000731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.120.136"; classtype:trojan-activity; sid:100000732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.240.136"; classtype:trojan-activity; sid:100000733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.240.239"; classtype:trojan-activity; sid:100000734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.50.253"; classtype:trojan-activity; sid:100000735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.70.70"; classtype:trojan-activity; sid:100000736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.125.92"; classtype:trojan-activity; sid:100000737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.161.110"; classtype:trojan-activity; sid:100000738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.164.102"; classtype:trojan-activity; sid:100000739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.218.157"; classtype:trojan-activity; sid:100000740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.50.203"; classtype:trojan-activity; sid:100000741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.58.82"; classtype:trojan-activity; sid:100000742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.96.11"; classtype:trojan-activity; sid:100000743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.83.79.43"; classtype:trojan-activity; sid:100000744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.91.41.135"; classtype:trojan-activity; sid:100000745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.179.164"; classtype:trojan-activity; sid:100000746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.183.235"; classtype:trojan-activity; sid:100000747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.239.217"; classtype:trojan-activity; sid:100000748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.100.40.250"; classtype:trojan-activity; sid:100000749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.108.251.176"; classtype:trojan-activity; sid:100000750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.112.22.58"; classtype:trojan-activity; sid:100000751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.115.247.23"; classtype:trojan-activity; sid:100000752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.118.150.84"; classtype:trojan-activity; sid:100000753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.119.176.198"; classtype:trojan-activity; sid:100000754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.119.52.202"; classtype:trojan-activity; sid:100000755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.123.173.95"; classtype:trojan-activity; sid:100000756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.123.175.210"; classtype:trojan-activity; sid:100000757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.14.143.145"; classtype:trojan-activity; sid:100000758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.147.213.57"; classtype:trojan-activity; sid:100000759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.162.109.111"; classtype:trojan-activity; sid:100000760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.144.208"; classtype:trojan-activity; sid:100000761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.207.197"; classtype:trojan-activity; sid:100000762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.93.191"; classtype:trojan-activity; sid:100000763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.18.235"; classtype:trojan-activity; sid:100000764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.31.76"; classtype:trojan-activity; sid:100000765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.107.93"; classtype:trojan-activity; sid:100000766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.163.220"; classtype:trojan-activity; sid:100000767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.174.63"; classtype:trojan-activity; sid:100000768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.241.222"; classtype:trojan-activity; sid:100000769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.27.77"; classtype:trojan-activity; sid:100000770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.68.145"; classtype:trojan-activity; sid:100000771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.170.241"; classtype:trojan-activity; sid:100000772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.19.254"; classtype:trojan-activity; sid:100000773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.97.6"; classtype:trojan-activity; sid:100000774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.1.13"; classtype:trojan-activity; sid:100000775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.2.214"; classtype:trojan-activity; sid:100000776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.26.33"; classtype:trojan-activity; sid:100000777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.63.195"; classtype:trojan-activity; sid:100000778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.201.188"; classtype:trojan-activity; sid:100000779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.248.123"; classtype:trojan-activity; sid:100000780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.249.140"; classtype:trojan-activity; sid:100000781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.120.180"; classtype:trojan-activity; sid:100000782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.157.219"; classtype:trojan-activity; sid:100000783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.16.149"; classtype:trojan-activity; sid:100000784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.170.212"; classtype:trojan-activity; sid:100000785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.190.180"; classtype:trojan-activity; sid:100000786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.43.1"; classtype:trojan-activity; sid:100000787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.75.8"; classtype:trojan-activity; sid:100000788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.18.38.144"; classtype:trojan-activity; sid:100000789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.101.151"; classtype:trojan-activity; sid:100000790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.106.217"; classtype:trojan-activity; sid:100000791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.227"; classtype:trojan-activity; sid:100000792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.79"; classtype:trojan-activity; sid:100000793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.11.29"; classtype:trojan-activity; sid:100000794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.231.79"; classtype:trojan-activity; sid:100000795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.33.161"; classtype:trojan-activity; sid:100000796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.9.35"; classtype:trojan-activity; sid:100000797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.94.80"; classtype:trojan-activity; sid:100000798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.119.21"; classtype:trojan-activity; sid:100000799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.124.203"; classtype:trojan-activity; sid:100000800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.115.103"; classtype:trojan-activity; sid:100000801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.9.82"; classtype:trojan-activity; sid:100000802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.14.112"; classtype:trojan-activity; sid:100000803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.172.199"; classtype:trojan-activity; sid:100000804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.237.89"; classtype:trojan-activity; sid:100000805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.43.193"; classtype:trojan-activity; sid:100000806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.186.140.160"; classtype:trojan-activity; sid:100000807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.186.22.245"; classtype:trojan-activity; sid:100000808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.195.161"; classtype:trojan-activity; sid:100000809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.220.115"; classtype:trojan-activity; sid:100000810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.137.195"; classtype:trojan-activity; sid:100000811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.227.244"; classtype:trojan-activity; sid:100000812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.190.211.99"; classtype:trojan-activity; sid:100000813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.190.234.181"; classtype:trojan-activity; sid:100000814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.150.85"; classtype:trojan-activity; sid:100000815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.187.206"; classtype:trojan-activity; sid:100000816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.215.221"; classtype:trojan-activity; sid:100000817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.240.20"; classtype:trojan-activity; sid:100000818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.253.206"; classtype:trojan-activity; sid:100000819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.204.30.144"; classtype:trojan-activity; sid:100000820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.250.129.231"; classtype:trojan-activity; sid:100000821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.105.221"; classtype:trojan-activity; sid:100000822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.12.85"; classtype:trojan-activity; sid:100000823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.14.251"; classtype:trojan-activity; sid:100000824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.131.155"; classtype:trojan-activity; sid:100000825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.140.73"; classtype:trojan-activity; sid:100000826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.46"; classtype:trojan-activity; sid:100000827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.71"; classtype:trojan-activity; sid:100000828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.148.115"; classtype:trojan-activity; sid:100000829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.155.57"; classtype:trojan-activity; sid:100000830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.172.28"; classtype:trojan-activity; sid:100000831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.96.37.55"; classtype:trojan-activity; sid:100000832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.96.70.116"; classtype:trojan-activity; sid:100000833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.188.187"; classtype:trojan-activity; sid:100000834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.190.152"; classtype:trojan-activity; sid:100000835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.232.62"; classtype:trojan-activity; sid:100000836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.132.113.2"; classtype:trojan-activity; sid:100000837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.15.69.83"; classtype:trojan-activity; sid:100000838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.6"; classtype:trojan-activity; sid:100000839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.7"; classtype:trojan-activity; sid:100000840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.8"; classtype:trojan-activity; sid:100000841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.9"; classtype:trojan-activity; sid:100000842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.207.39.227"; classtype:trojan-activity; sid:100000843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.153.54"; classtype:trojan-activity; sid:100000844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.212.5"; classtype:trojan-activity; sid:100000845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.231.61"; classtype:trojan-activity; sid:100000846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.142.222.22"; classtype:trojan-activity; sid:100000847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.150.213.110"; classtype:trojan-activity; sid:100000848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.151.248.134"; classtype:trojan-activity; sid:100000849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.177"; classtype:trojan-activity; sid:100000850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.178"; classtype:trojan-activity; sid:100000851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.180"; classtype:trojan-activity; sid:100000852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.181"; classtype:trojan-activity; sid:100000853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.183"; classtype:trojan-activity; sid:100000854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.184"; classtype:trojan-activity; sid:100000855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.185"; classtype:trojan-activity; sid:100000856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.186"; classtype:trojan-activity; sid:100000857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.188"; classtype:trojan-activity; sid:100000858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.191"; classtype:trojan-activity; sid:100000859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.193"; classtype:trojan-activity; sid:100000860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.196"; classtype:trojan-activity; sid:100000861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.197"; classtype:trojan-activity; sid:100000862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.198"; classtype:trojan-activity; sid:100000863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.199"; classtype:trojan-activity; sid:100000864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.200"; classtype:trojan-activity; sid:100000865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.201"; classtype:trojan-activity; sid:100000866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.202"; classtype:trojan-activity; sid:100000867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.204"; classtype:trojan-activity; sid:100000868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.205"; classtype:trojan-activity; sid:100000869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.207"; classtype:trojan-activity; sid:100000870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.208"; classtype:trojan-activity; sid:100000871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.212"; classtype:trojan-activity; sid:100000872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.213"; classtype:trojan-activity; sid:100000873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.215"; classtype:trojan-activity; sid:100000874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.233"; classtype:trojan-activity; sid:100000875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.93.227"; classtype:trojan-activity; sid:100000876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.121.243"; classtype:trojan-activity; sid:100000877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.206"; classtype:trojan-activity; sid:100000878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.225"; classtype:trojan-activity; sid:100000879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.235"; classtype:trojan-activity; sid:100000880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.240"; classtype:trojan-activity; sid:100000881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.243"; classtype:trojan-activity; sid:100000882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.60"; classtype:trojan-activity; sid:100000883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.127.187"; classtype:trojan-activity; sid:100000884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.99.127"; classtype:trojan-activity; sid:100000885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.210.89.79"; classtype:trojan-activity; sid:100000886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.43.34.242"; classtype:trojan-activity; sid:100000887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.5.15.95"; classtype:trojan-activity; sid:100000888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.66.60"; classtype:trojan-activity; sid:100000889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.93.115"; classtype:trojan-activity; sid:100000890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.57.214.228"; classtype:trojan-activity; sid:100000891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.57.98.208"; classtype:trojan-activity; sid:100000892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.141.142"; classtype:trojan-activity; sid:100000893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.241.130"; classtype:trojan-activity; sid:100000894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.8.11"; classtype:trojan-activity; sid:100000895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.69.131.51"; classtype:trojan-activity; sid:100000896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.7.75.99"; classtype:trojan-activity; sid:100000897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.7.90.104"; classtype:trojan-activity; sid:100000898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.83.189.232"; classtype:trojan-activity; sid:100000899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.165.112"; classtype:trojan-activity; sid:100000900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.185.141"; classtype:trojan-activity; sid:100000901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.196.211"; classtype:trojan-activity; sid:100000902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.208.107"; classtype:trojan-activity; sid:100000903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.238.10"; classtype:trojan-activity; sid:100000904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.9.32.51"; classtype:trojan-activity; sid:100000905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.114.164"; classtype:trojan-activity; sid:100000906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.96.8"; classtype:trojan-activity; sid:100000907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.121.44.222"; classtype:trojan-activity; sid:100000908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.123.53.25"; classtype:trojan-activity; sid:100000909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.127.155.220"; classtype:trojan-activity; sid:100000910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.141.11.56"; classtype:trojan-activity; sid:100000911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.15.142.137"; classtype:trojan-activity; sid:100000912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.159.22.144"; classtype:trojan-activity; sid:100000913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.17.103.176"; classtype:trojan-activity; sid:100000914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.170.234.142"; classtype:trojan-activity; sid:100000915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.185.31.2"; classtype:trojan-activity; sid:100000916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.190.36.8"; classtype:trojan-activity; sid:100000917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.225.11.163"; classtype:trojan-activity; sid:100000918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.226.82.202"; classtype:trojan-activity; sid:100000919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.23.57.130"; classtype:trojan-activity; sid:100000920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.230.171.198"; classtype:trojan-activity; sid:100000921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.231.103.95"; classtype:trojan-activity; sid:100000922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.233.18.172"; classtype:trojan-activity; sid:100000923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.238.175.87"; classtype:trojan-activity; sid:100000924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.239.15.74"; classtype:trojan-activity; sid:100000925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.24.116.173"; classtype:trojan-activity; sid:100000926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.25.101.86"; classtype:trojan-activity; sid:100000927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.254.43.215"; classtype:trojan-activity; sid:100000928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.254.76.17"; classtype:trojan-activity; sid:100000929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.102.1"; classtype:trojan-activity; sid:100000930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.107.189"; classtype:trojan-activity; sid:100000931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.97.195"; classtype:trojan-activity; sid:100000932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.98.151"; classtype:trojan-activity; sid:100000933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.88.99.236"; classtype:trojan-activity; sid:100000934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.100.150.204"; classtype:trojan-activity; sid:100000935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.160.147.53"; classtype:trojan-activity; sid:100000936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.176.44.34"; classtype:trojan-activity; sid:100000937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.188.86.225"; classtype:trojan-activity; sid:100000938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.66.28"; classtype:trojan-activity; sid:100000939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.72.23"; classtype:trojan-activity; sid:100000940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.79.27"; classtype:trojan-activity; sid:100000941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.37.85"; classtype:trojan-activity; sid:100000942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.41.23"; classtype:trojan-activity; sid:100000943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.252.199.3"; classtype:trojan-activity; sid:100000944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.183.207"; classtype:trojan-activity; sid:100000945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.29.37"; classtype:trojan-activity; sid:100000946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.33.214"; classtype:trojan-activity; sid:100000947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.0.240.58"; classtype:trojan-activity; sid:100000948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.83.136"; classtype:trojan-activity; sid:100000949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.11.207"; classtype:trojan-activity; sid:100000950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.4.168"; classtype:trojan-activity; sid:100000951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.7.1"; classtype:trojan-activity; sid:100000952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.71.166"; classtype:trojan-activity; sid:100000953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.238"; classtype:trojan-activity; sid:100000954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.244"; classtype:trojan-activity; sid:100000955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.170.237"; classtype:trojan-activity; sid:100000956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.182.187"; classtype:trojan-activity; sid:100000957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.19.248"; classtype:trojan-activity; sid:100000958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.200.98"; classtype:trojan-activity; sid:100000959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.238.188"; classtype:trojan-activity; sid:100000960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.12.189.247"; classtype:trojan-activity; sid:100000961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.12.225.70"; classtype:trojan-activity; sid:100000962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.12.235.159"; classtype:trojan-activity; sid:100000963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.12.243.85"; classtype:trojan-activity; sid:100000964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.128.205"; classtype:trojan-activity; sid:100000965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.133.91"; classtype:trojan-activity; sid:100000966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.177.161"; classtype:trojan-activity; sid:100000967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.84.36"; classtype:trojan-activity; sid:100000968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.88.123"; classtype:trojan-activity; sid:100000969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.202.8"; classtype:trojan-activity; sid:100000970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.208.52"; classtype:trojan-activity; sid:100000971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.23.110"; classtype:trojan-activity; sid:100000972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.27.19"; classtype:trojan-activity; sid:100000973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.37.182"; classtype:trojan-activity; sid:100000974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.61.210"; classtype:trojan-activity; sid:100000975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.77.225"; classtype:trojan-activity; sid:100000976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.131.186.250"; classtype:trojan-activity; sid:100000977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.132.219.147"; classtype:trojan-activity; sid:100000978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.125.77"; classtype:trojan-activity; sid:100000979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.144.138"; classtype:trojan-activity; sid:100000980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.184.77"; classtype:trojan-activity; sid:100000981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.98.135"; classtype:trojan-activity; sid:100000982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.14.130"; classtype:trojan-activity; sid:100000983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.50.186"; classtype:trojan-activity; sid:100000984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.39.36"; classtype:trojan-activity; sid:100000985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.71.150"; classtype:trojan-activity; sid:100000986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.127.238"; classtype:trojan-activity; sid:100000987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.173.199"; classtype:trojan-activity; sid:100000988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.249.33"; classtype:trojan-activity; sid:100000989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.34.240"; classtype:trojan-activity; sid:100000990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.37.32"; classtype:trojan-activity; sid:100000991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.50.214"; classtype:trojan-activity; sid:100000992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.93.154"; classtype:trojan-activity; sid:100000993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.144.211.86"; classtype:trojan-activity; sid:100000994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.152.42.4"; classtype:trojan-activity; sid:100000995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.153.80.178"; classtype:trojan-activity; sid:100000996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.116.116"; classtype:trojan-activity; sid:100000997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.236.114"; classtype:trojan-activity; sid:100000998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.94.1"; classtype:trojan-activity; sid:100000999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.155.118.36"; classtype:trojan-activity; sid:100001000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.156.136.21"; classtype:trojan-activity; sid:100001001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.137.101"; classtype:trojan-activity; sid:100001002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.31.110"; classtype:trojan-activity; sid:100001003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.8.100"; classtype:trojan-activity; sid:100001004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.101.163"; classtype:trojan-activity; sid:100001005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.194.233"; classtype:trojan-activity; sid:100001006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.149.235"; classtype:trojan-activity; sid:100001007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.53.237"; classtype:trojan-activity; sid:100001008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.235.37"; classtype:trojan-activity; sid:100001009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.35.146"; classtype:trojan-activity; sid:100001010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.52.79"; classtype:trojan-activity; sid:100001011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.60.238"; classtype:trojan-activity; sid:100001012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.112.240"; classtype:trojan-activity; sid:100001013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.184.191"; classtype:trojan-activity; sid:100001014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.98.141"; classtype:trojan-activity; sid:100001015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.212.29.154"; classtype:trojan-activity; sid:100001016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.213.225.130"; classtype:trojan-activity; sid:100001017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.130.162"; classtype:trojan-activity; sid:100001018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.152.249"; classtype:trojan-activity; sid:100001019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.100.219"; classtype:trojan-activity; sid:100001020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.116.110"; classtype:trojan-activity; sid:100001021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.184.57"; classtype:trojan-activity; sid:100001022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.246.103"; classtype:trojan-activity; sid:100001023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.235.226.3"; classtype:trojan-activity; sid:100001024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.103.89"; classtype:trojan-activity; sid:100001025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.181.57"; classtype:trojan-activity; sid:100001026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.79.61"; classtype:trojan-activity; sid:100001027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.148.58"; classtype:trojan-activity; sid:100001028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.184.124"; classtype:trojan-activity; sid:100001029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.27.44.219"; classtype:trojan-activity; sid:100001030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.28.217.23"; classtype:trojan-activity; sid:100001031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.11.40"; classtype:trojan-activity; sid:100001032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.166.2"; classtype:trojan-activity; sid:100001033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.177.93"; classtype:trojan-activity; sid:100001034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.194.152"; classtype:trojan-activity; sid:100001035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.209.154"; classtype:trojan-activity; sid:100001036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.241.118"; classtype:trojan-activity; sid:100001037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.45.31"; classtype:trojan-activity; sid:100001038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.76.117"; classtype:trojan-activity; sid:100001039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.83.66"; classtype:trojan-activity; sid:100001040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.85.149"; classtype:trojan-activity; sid:100001041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.143.203"; classtype:trojan-activity; sid:100001042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.146.238"; classtype:trojan-activity; sid:100001043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.190.167"; classtype:trojan-activity; sid:100001044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.5.242"; classtype:trojan-activity; sid:100001045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.8.211"; classtype:trojan-activity; sid:100001046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.56.94"; classtype:trojan-activity; sid:100001047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.71.27"; classtype:trojan-activity; sid:100001048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.194.169"; classtype:trojan-activity; sid:100001049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.240.115"; classtype:trojan-activity; sid:100001050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.245.207"; classtype:trojan-activity; sid:100001051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.105.105.222"; classtype:trojan-activity; sid:100001052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.162.169"; classtype:trojan-activity; sid:100001053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.221.150"; classtype:trojan-activity; sid:100001054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.76.230"; classtype:trojan-activity; sid:100001055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.167.20"; classtype:trojan-activity; sid:100001056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.40.31"; classtype:trojan-activity; sid:100001057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.104.82"; classtype:trojan-activity; sid:100001058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.130.95"; classtype:trojan-activity; sid:100001059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.131.71"; classtype:trojan-activity; sid:100001060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.136.75"; classtype:trojan-activity; sid:100001061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.137.147"; classtype:trojan-activity; sid:100001062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.151.135"; classtype:trojan-activity; sid:100001063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.24.185"; classtype:trojan-activity; sid:100001064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.26.243"; classtype:trojan-activity; sid:100001065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.26.78"; classtype:trojan-activity; sid:100001066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.41.48"; classtype:trojan-activity; sid:100001067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.54.33"; classtype:trojan-activity; sid:100001068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.72.208"; classtype:trojan-activity; sid:100001069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.132.110.150"; classtype:trojan-activity; sid:100001070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.135.34.157"; classtype:trojan-activity; sid:100001071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.135.34.49"; classtype:trojan-activity; sid:100001072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.136.175"; classtype:trojan-activity; sid:100001073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.236.6"; classtype:trojan-activity; sid:100001074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.160.126.238"; classtype:trojan-activity; sid:100001075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.154.237"; classtype:trojan-activity; sid:100001076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.65.64"; classtype:trojan-activity; sid:100001077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.65.98"; classtype:trojan-activity; sid:100001078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.72.102"; classtype:trojan-activity; sid:100001079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.77.191"; classtype:trojan-activity; sid:100001080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.89.212"; classtype:trojan-activity; sid:100001081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.90.243"; classtype:trojan-activity; sid:100001082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.165.123.7"; classtype:trojan-activity; sid:100001083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.187.111.160"; classtype:trojan-activity; sid:100001084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.199.56.198"; classtype:trojan-activity; sid:100001085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.226.24.117"; classtype:trojan-activity; sid:100001086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.230.174.233"; classtype:trojan-activity; sid:100001087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.254.254.61"; classtype:trojan-activity; sid:100001088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.5.92.20"; classtype:trojan-activity; sid:100001089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.6.0.4"; classtype:trojan-activity; sid:100001090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.67.89.28"; classtype:trojan-activity; sid:100001091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.7.254.85"; classtype:trojan-activity; sid:100001092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.80.46.73"; classtype:trojan-activity; sid:100001093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.91.237.147"; classtype:trojan-activity; sid:100001094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.92.135.37"; classtype:trojan-activity; sid:100001095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.93.94.207"; classtype:trojan-activity; sid:100001096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.105.219.169"; classtype:trojan-activity; sid:100001097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.126.69.95"; classtype:trojan-activity; sid:100001098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.128.28.161"; classtype:trojan-activity; sid:100001099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.142.93.34"; classtype:trojan-activity; sid:100001100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.168.10.234"; classtype:trojan-activity; sid:100001101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.191.113.212"; classtype:trojan-activity; sid:100001102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.209.71.6"; classtype:trojan-activity; sid:100001103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.36.148.42"; classtype:trojan-activity; sid:100001104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.1.127"; classtype:trojan-activity; sid:100001105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.113.66"; classtype:trojan-activity; sid:100001106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.25.140"; classtype:trojan-activity; sid:100001107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.65.120"; classtype:trojan-activity; sid:100001108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.73.6"; classtype:trojan-activity; sid:100001109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.74.153"; classtype:trojan-activity; sid:100001110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.75.22"; classtype:trojan-activity; sid:100001111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.141.41"; classtype:trojan-activity; sid:100001112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.164.60"; classtype:trojan-activity; sid:100001113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.185.186"; classtype:trojan-activity; sid:100001114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.196.114"; classtype:trojan-activity; sid:100001115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.208.139"; classtype:trojan-activity; sid:100001116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.6.192"; classtype:trojan-activity; sid:100001117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.7.204"; classtype:trojan-activity; sid:100001118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.74.22"; classtype:trojan-activity; sid:100001119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.96.238"; classtype:trojan-activity; sid:100001120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.96.33"; classtype:trojan-activity; sid:100001121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.97.231"; classtype:trojan-activity; sid:100001122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.97.81"; classtype:trojan-activity; sid:100001123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.107.136"; classtype:trojan-activity; sid:100001124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.124.114"; classtype:trojan-activity; sid:100001125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.112.123"; classtype:trojan-activity; sid:100001126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.112.182"; classtype:trojan-activity; sid:100001127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.133.130"; classtype:trojan-activity; sid:100001128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.167.192"; classtype:trojan-activity; sid:100001129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.215.244"; classtype:trojan-activity; sid:100001130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.33.20"; classtype:trojan-activity; sid:100001131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.53.50"; classtype:trojan-activity; sid:100001132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.53.9"; classtype:trojan-activity; sid:100001133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.6.186"; classtype:trojan-activity; sid:100001134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.60.218"; classtype:trojan-activity; sid:100001135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.63.47"; classtype:trojan-activity; sid:100001136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.10.125"; classtype:trojan-activity; sid:100001137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.107.182"; classtype:trojan-activity; sid:100001138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.175.118"; classtype:trojan-activity; sid:100001139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.198.62"; classtype:trojan-activity; sid:100001140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.208.152"; classtype:trojan-activity; sid:100001141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.212.131"; classtype:trojan-activity; sid:100001142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.227.51"; classtype:trojan-activity; sid:100001143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.70.64"; classtype:trojan-activity; sid:100001144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.8.227"; classtype:trojan-activity; sid:100001145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.153.91"; classtype:trojan-activity; sid:100001146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.43.63"; classtype:trojan-activity; sid:100001147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.55.146"; classtype:trojan-activity; sid:100001148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.166.112"; classtype:trojan-activity; sid:100001149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.166.125"; classtype:trojan-activity; sid:100001150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.205.88"; classtype:trojan-activity; sid:100001151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.206.160"; classtype:trojan-activity; sid:100001152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.217.52"; classtype:trojan-activity; sid:100001153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.241.237"; classtype:trojan-activity; sid:100001154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.125.16"; classtype:trojan-activity; sid:100001155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.241.188"; classtype:trojan-activity; sid:100001156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.245.200"; classtype:trojan-activity; sid:100001157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.248.131"; classtype:trojan-activity; sid:100001158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.250.98"; classtype:trojan-activity; sid:100001159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.254.44"; classtype:trojan-activity; sid:100001160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.28.18"; classtype:trojan-activity; sid:100001161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.38.142"; classtype:trojan-activity; sid:100001162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.45.218"; classtype:trojan-activity; sid:100001163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.47.212"; classtype:trojan-activity; sid:100001164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.57.80"; classtype:trojan-activity; sid:100001165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.91.51"; classtype:trojan-activity; sid:100001166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.79.192.197"; classtype:trojan-activity; sid:100001167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"128.116.133.92"; classtype:trojan-activity; sid:100001168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"130.255.159.133"; classtype:trojan-activity; sid:100001169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"134.195.139.4"; classtype:trojan-activity; sid:100001170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"134.255.93.203"; classtype:trojan-activity; sid:100001171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"135.181.192.170"; classtype:trojan-activity; sid:100001172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"138.99.204.224"; classtype:trojan-activity; sid:100001173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.159.226.180"; classtype:trojan-activity; sid:100001174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.173.198"; classtype:trojan-activity; sid:100001175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.174.162"; classtype:trojan-activity; sid:100001176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.213.97.191"; classtype:trojan-activity; sid:100001177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.216.102.151"; classtype:trojan-activity; sid:100001178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.227.46.137"; classtype:trojan-activity; sid:100001179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.102.17.222"; classtype:trojan-activity; sid:100001180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.102.97.204"; classtype:trojan-activity; sid:100001181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.109.126.96"; classtype:trojan-activity; sid:100001182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.136.80.242"; classtype:trojan-activity; sid:100001183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.109.26"; classtype:trojan-activity; sid:100001184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.215"; classtype:trojan-activity; sid:100001185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.51"; classtype:trojan-activity; sid:100001186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.155.220.240"; classtype:trojan-activity; sid:100001187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.160.24.71"; classtype:trojan-activity; sid:100001188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.169.164.77"; classtype:trojan-activity; sid:100001189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.181.64.108"; classtype:trojan-activity; sid:100001190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.189.247.118"; classtype:trojan-activity; sid:100001191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.205.201.192"; classtype:trojan-activity; sid:100001192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.248.187.0"; classtype:trojan-activity; sid:100001193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.37.222.190"; classtype:trojan-activity; sid:100001194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.45.127.110"; classtype:trojan-activity; sid:100001195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.25.17"; classtype:trojan-activity; sid:100001196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.98.241"; classtype:trojan-activity; sid:100001197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.55.29.2"; classtype:trojan-activity; sid:100001198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.98.184.178"; classtype:trojan-activity; sid:100001199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"140.237.30.113"; classtype:trojan-activity; sid:100001200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"140.237.30.172"; classtype:trojan-activity; sid:100001201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"140.237.5.43"; classtype:trojan-activity; sid:100001202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"140.240.151.177"; classtype:trojan-activity; sid:100001203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.11.216.5"; classtype:trojan-activity; sid:100001204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.177.56.127"; classtype:trojan-activity; sid:100001205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"146.71.79.230"; classtype:trojan-activity; sid:100001206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"148.69.108.177"; classtype:trojan-activity; sid:100001207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.20.176.179"; classtype:trojan-activity; sid:100001208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.134"; classtype:trojan-activity; sid:100001209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.172"; classtype:trojan-activity; sid:100001210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.180"; classtype:trojan-activity; sid:100001211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.182"; classtype:trojan-activity; sid:100001212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.184"; classtype:trojan-activity; sid:100001213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.213"; classtype:trojan-activity; sid:100001214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.43"; classtype:trojan-activity; sid:100001215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.87"; classtype:trojan-activity; sid:100001216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.99"; classtype:trojan-activity; sid:100001217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.124.194"; classtype:trojan-activity; sid:100001218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.73.210"; classtype:trojan-activity; sid:100001219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"150.116.207.99"; classtype:trojan-activity; sid:100001220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.177.163.87"; classtype:trojan-activity; sid:100001221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.33.230.191"; classtype:trojan-activity; sid:100001222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.73.124.231"; classtype:trojan-activity; sid:100001223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.225.96"; classtype:trojan-activity; sid:100001224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.234.167"; classtype:trojan-activity; sid:100001225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.40.207"; classtype:trojan-activity; sid:100001226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.43.136"; classtype:trojan-activity; sid:100001227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.44.44"; classtype:trojan-activity; sid:100001228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.135.92"; classtype:trojan-activity; sid:100001229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.23.76"; classtype:trojan-activity; sid:100001230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.29.28"; classtype:trojan-activity; sid:100001231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.35.27.49"; classtype:trojan-activity; sid:100001232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.36.126.35"; classtype:trojan-activity; sid:100001233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.101.165.14"; classtype:trojan-activity; sid:100001234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.174.213.128"; classtype:trojan-activity; sid:100001235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.51.125.115"; classtype:trojan-activity; sid:100001236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"159.224.74.112"; classtype:trojan-activity; sid:100001237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.165.238"; classtype:trojan-activity; sid:100001238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.205.175"; classtype:trojan-activity; sid:100001239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.194.28.60"; classtype:trojan-activity; sid:100001240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.209.98.174"; classtype:trojan-activity; sid:100001241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.212.203.250"; classtype:trojan-activity; sid:100001242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.18.93"; classtype:trojan-activity; sid:100001243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.193.148"; classtype:trojan-activity; sid:100001244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.200.118"; classtype:trojan-activity; sid:100001245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.200.242"; classtype:trojan-activity; sid:100001246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.202.193"; classtype:trojan-activity; sid:100001247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.202.255"; classtype:trojan-activity; sid:100001248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.202.87"; classtype:trojan-activity; sid:100001249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.203.198"; classtype:trojan-activity; sid:100001250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.203.236"; classtype:trojan-activity; sid:100001251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.204.156"; classtype:trojan-activity; sid:100001252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.204.34"; classtype:trojan-activity; sid:100001253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.206.16"; classtype:trojan-activity; sid:100001254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.255.165"; classtype:trojan-activity; sid:100001255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.204.208.169"; classtype:trojan-activity; sid:100001256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.204.211.136"; classtype:trojan-activity; sid:100001257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.204.211.228"; classtype:trojan-activity; sid:100001258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.204.211.58"; classtype:trojan-activity; sid:100001259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.53.206.228"; classtype:trojan-activity; sid:100001260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"165.90.16.5"; classtype:trojan-activity; sid:100001261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"168.194.146.145"; classtype:trojan-activity; sid:100001262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"168.205.223.254"; classtype:trojan-activity; sid:100001263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"168.90.204.207"; classtype:trojan-activity; sid:100001264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"170.81.238.178"; classtype:trojan-activity; sid:100001265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.113.36.216"; classtype:trojan-activity; sid:100001266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.118.18.184"; classtype:trojan-activity; sid:100001267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.118.210.67"; classtype:trojan-activity; sid:100001268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.217.149"; classtype:trojan-activity; sid:100001269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.218.208"; classtype:trojan-activity; sid:100001270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.219.150"; classtype:trojan-activity; sid:100001271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.248.222"; classtype:trojan-activity; sid:100001272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.255.96"; classtype:trojan-activity; sid:100001273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.120.125.147"; classtype:trojan-activity; sid:100001274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.121.6.162"; classtype:trojan-activity; sid:100001275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.123.134.239"; classtype:trojan-activity; sid:100001276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.122.91"; classtype:trojan-activity; sid:100001277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.242.71"; classtype:trojan-activity; sid:100001278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.30.233"; classtype:trojan-activity; sid:100001279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.30.93"; classtype:trojan-activity; sid:100001280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.64.223"; classtype:trojan-activity; sid:100001281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.65.22"; classtype:trojan-activity; sid:100001282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.65.89"; classtype:trojan-activity; sid:100001283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.75.68"; classtype:trojan-activity; sid:100001284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.126.70.133"; classtype:trojan-activity; sid:100001285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.223.72.123"; classtype:trojan-activity; sid:100001286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.112.42"; classtype:trojan-activity; sid:100001287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.114.181"; classtype:trojan-activity; sid:100001288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.179.178"; classtype:trojan-activity; sid:100001289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.160.138"; classtype:trojan-activity; sid:100001290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.161.234"; classtype:trojan-activity; sid:100001291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.162.156"; classtype:trojan-activity; sid:100001292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.174.198"; classtype:trojan-activity; sid:100001293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.36.249.91"; classtype:trojan-activity; sid:100001294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.145.146"; classtype:trojan-activity; sid:100001295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.148.69"; classtype:trojan-activity; sid:100001296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.219.189"; classtype:trojan-activity; sid:100001297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.223.110"; classtype:trojan-activity; sid:100001298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.223.213"; classtype:trojan-activity; sid:100001299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.105.36.168"; classtype:trojan-activity; sid:100001300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.114.244.127"; classtype:trojan-activity; sid:100001301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.185"; classtype:trojan-activity; sid:100001302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.190"; classtype:trojan-activity; sid:100001303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.81.19"; classtype:trojan-activity; sid:100001304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.167.85.89"; classtype:trojan-activity; sid:100001305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.169.46.85"; classtype:trojan-activity; sid:100001306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.19.58.108"; classtype:trojan-activity; sid:100001307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.233.85.171"; classtype:trojan-activity; sid:100001308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.235.209.70"; classtype:trojan-activity; sid:100001309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.25.113.8"; classtype:trojan-activity; sid:100001310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.95.134"; classtype:trojan-activity; sid:100001311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.97.25"; classtype:trojan-activity; sid:100001312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.119.108"; classtype:trojan-activity; sid:100001313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.92.166"; classtype:trojan-activity; sid:100001314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.106.33.85"; classtype:trojan-activity; sid:100001315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.48.181.23"; classtype:trojan-activity; sid:100001316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.61.3.149"; classtype:trojan-activity; sid:100001317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.73.246.193"; classtype:trojan-activity; sid:100001318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.81.78.7"; classtype:trojan-activity; sid:100001319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.83.73.163"; classtype:trojan-activity; sid:100001320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.10.147.167"; classtype:trojan-activity; sid:100001321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.11.193.66"; classtype:trojan-activity; sid:100001322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.115.241.87"; classtype:trojan-activity; sid:100001323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.117.66.74"; classtype:trojan-activity; sid:100001324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.145.200.216"; classtype:trojan-activity; sid:100001325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.146.17.227"; classtype:trojan-activity; sid:100001326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.150.168.92"; classtype:trojan-activity; sid:100001327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.162.137.166"; classtype:trojan-activity; sid:100001328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.162.195.27"; classtype:trojan-activity; sid:100001329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.162.69.13"; classtype:trojan-activity; sid:100001330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.164.61.215"; classtype:trojan-activity; sid:100001331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.165.90.198"; classtype:trojan-activity; sid:100001332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.168.139.182"; classtype:trojan-activity; sid:100001333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.169.13.182"; classtype:trojan-activity; sid:100001334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.17.90.14"; classtype:trojan-activity; sid:100001335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.174.93.57"; classtype:trojan-activity; sid:100001336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.199.33.139"; classtype:trojan-activity; sid:100001337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.201.104.192"; classtype:trojan-activity; sid:100001338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.208.230.8"; classtype:trojan-activity; sid:100001339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.212.6.169"; classtype:trojan-activity; sid:100001340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.42.46.118"; classtype:trojan-activity; sid:100001341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.8.113.55"; classtype:trojan-activity; sid:100001342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.9.24.110"; classtype:trojan-activity; sid:100001343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.14"; classtype:trojan-activity; sid:100001344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.35"; classtype:trojan-activity; sid:100001345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.63"; classtype:trojan-activity; sid:100001346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.66"; classtype:trojan-activity; sid:100001347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.67"; classtype:trojan-activity; sid:100001348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.104"; classtype:trojan-activity; sid:100001349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.113"; classtype:trojan-activity; sid:100001350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.128"; classtype:trojan-activity; sid:100001351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.60"; classtype:trojan-activity; sid:100001352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.65"; classtype:trojan-activity; sid:100001353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.66"; classtype:trojan-activity; sid:100001354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.76"; classtype:trojan-activity; sid:100001355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.84"; classtype:trojan-activity; sid:100001356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.88"; classtype:trojan-activity; sid:100001357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.93"; classtype:trojan-activity; sid:100001358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.174.139"; classtype:trojan-activity; sid:100001359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.12.117.70"; classtype:trojan-activity; sid:100001360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.4.115"; classtype:trojan-activity; sid:100001361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.115"; classtype:trojan-activity; sid:100001362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.127"; classtype:trojan-activity; sid:100001363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.9.243"; classtype:trojan-activity; sid:100001364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.124.7.225"; classtype:trojan-activity; sid:100001365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.221.251.238"; classtype:trojan-activity; sid:100001366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.40.142"; classtype:trojan-activity; sid:100001367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.84.106"; classtype:trojan-activity; sid:100001368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.11.92.78"; classtype:trojan-activity; sid:100001369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.131.226.235"; classtype:trojan-activity; sid:100001370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.229.64.218"; classtype:trojan-activity; sid:100001371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.54.82.154"; classtype:trojan-activity; sid:100001372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.124.182.187"; classtype:trojan-activity; sid:100001373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.134.185.112"; classtype:trojan-activity; sid:100001374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.25.82"; classtype:trojan-activity; sid:100001375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.44.152"; classtype:trojan-activity; sid:100001376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.45.2"; classtype:trojan-activity; sid:100001377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.57.166"; classtype:trojan-activity; sid:100001378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.150.174.65"; classtype:trojan-activity; sid:100001379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.151.143.2"; classtype:trojan-activity; sid:100001380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.165.122.141"; classtype:trojan-activity; sid:100001381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.0.140"; classtype:trojan-activity; sid:100001382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.139"; classtype:trojan-activity; sid:100001383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.153"; classtype:trojan-activity; sid:100001384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.176"; classtype:trojan-activity; sid:100001385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.182"; classtype:trojan-activity; sid:100001386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.244"; classtype:trojan-activity; sid:100001387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.249"; classtype:trojan-activity; sid:100001388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.250"; classtype:trojan-activity; sid:100001389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.252"; classtype:trojan-activity; sid:100001390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.44"; classtype:trojan-activity; sid:100001391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.80"; classtype:trojan-activity; sid:100001392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.104"; classtype:trojan-activity; sid:100001393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.121"; classtype:trojan-activity; sid:100001394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.178"; classtype:trojan-activity; sid:100001395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.34"; classtype:trojan-activity; sid:100001396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.42"; classtype:trojan-activity; sid:100001397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.71"; classtype:trojan-activity; sid:100001398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.78"; classtype:trojan-activity; sid:100001399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.110"; classtype:trojan-activity; sid:100001400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.129"; classtype:trojan-activity; sid:100001401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.180"; classtype:trojan-activity; sid:100001402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.191"; classtype:trojan-activity; sid:100001403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.218"; classtype:trojan-activity; sid:100001404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.34"; classtype:trojan-activity; sid:100001405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.4"; classtype:trojan-activity; sid:100001406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.52"; classtype:trojan-activity; sid:100001407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.110"; classtype:trojan-activity; sid:100001408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.173"; classtype:trojan-activity; sid:100001409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.191"; classtype:trojan-activity; sid:100001410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.134"; classtype:trojan-activity; sid:100001411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.14"; classtype:trojan-activity; sid:100001412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.221"; classtype:trojan-activity; sid:100001413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.245"; classtype:trojan-activity; sid:100001414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.35"; classtype:trojan-activity; sid:100001415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.53"; classtype:trojan-activity; sid:100001416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.172"; classtype:trojan-activity; sid:100001417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.24"; classtype:trojan-activity; sid:100001418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.246"; classtype:trojan-activity; sid:100001419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.27"; classtype:trojan-activity; sid:100001420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.106"; classtype:trojan-activity; sid:100001421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.110"; classtype:trojan-activity; sid:100001422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.120"; classtype:trojan-activity; sid:100001423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.140"; classtype:trojan-activity; sid:100001424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.151"; classtype:trojan-activity; sid:100001425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.155"; classtype:trojan-activity; sid:100001426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.16"; classtype:trojan-activity; sid:100001427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.199"; classtype:trojan-activity; sid:100001428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.206"; classtype:trojan-activity; sid:100001429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.239"; classtype:trojan-activity; sid:100001430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.49"; classtype:trojan-activity; sid:100001431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.122"; classtype:trojan-activity; sid:100001432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.125"; classtype:trojan-activity; sid:100001433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.146"; classtype:trojan-activity; sid:100001434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.197"; classtype:trojan-activity; sid:100001435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.217"; classtype:trojan-activity; sid:100001436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.240"; classtype:trojan-activity; sid:100001437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.245"; classtype:trojan-activity; sid:100001438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.248"; classtype:trojan-activity; sid:100001439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.104"; classtype:trojan-activity; sid:100001440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.106"; classtype:trojan-activity; sid:100001441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.118"; classtype:trojan-activity; sid:100001442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.149"; classtype:trojan-activity; sid:100001443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.18"; classtype:trojan-activity; sid:100001444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.193"; classtype:trojan-activity; sid:100001445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.36"; classtype:trojan-activity; sid:100001446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.37"; classtype:trojan-activity; sid:100001447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.77"; classtype:trojan-activity; sid:100001448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.83"; classtype:trojan-activity; sid:100001449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.0"; classtype:trojan-activity; sid:100001450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.133"; classtype:trojan-activity; sid:100001451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.149"; classtype:trojan-activity; sid:100001452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.240"; classtype:trojan-activity; sid:100001453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.245"; classtype:trojan-activity; sid:100001454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.83"; classtype:trojan-activity; sid:100001455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.65"; classtype:trojan-activity; sid:100001456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.87"; classtype:trojan-activity; sid:100001457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.94"; classtype:trojan-activity; sid:100001458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.132"; classtype:trojan-activity; sid:100001459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.140"; classtype:trojan-activity; sid:100001460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.227"; classtype:trojan-activity; sid:100001461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.37"; classtype:trojan-activity; sid:100001462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.77"; classtype:trojan-activity; sid:100001463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.155"; classtype:trojan-activity; sid:100001464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.165"; classtype:trojan-activity; sid:100001465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.176"; classtype:trojan-activity; sid:100001466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.204"; classtype:trojan-activity; sid:100001467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.241"; classtype:trojan-activity; sid:100001468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.57"; classtype:trojan-activity; sid:100001469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.6"; classtype:trojan-activity; sid:100001470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.155"; classtype:trojan-activity; sid:100001471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.169"; classtype:trojan-activity; sid:100001472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.194"; classtype:trojan-activity; sid:100001473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.197"; classtype:trojan-activity; sid:100001474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.198"; classtype:trojan-activity; sid:100001475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.221"; classtype:trojan-activity; sid:100001476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.105"; classtype:trojan-activity; sid:100001477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.159"; classtype:trojan-activity; sid:100001478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.187"; classtype:trojan-activity; sid:100001479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.190"; classtype:trojan-activity; sid:100001480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.195"; classtype:trojan-activity; sid:100001481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.206"; classtype:trojan-activity; sid:100001482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.98"; classtype:trojan-activity; sid:100001483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.139"; classtype:trojan-activity; sid:100001484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.147"; classtype:trojan-activity; sid:100001485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.159"; classtype:trojan-activity; sid:100001486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.4"; classtype:trojan-activity; sid:100001487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.46"; classtype:trojan-activity; sid:100001488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.85"; classtype:trojan-activity; sid:100001489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.200"; classtype:trojan-activity; sid:100001490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.254"; classtype:trojan-activity; sid:100001491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.55"; classtype:trojan-activity; sid:100001492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.63"; classtype:trojan-activity; sid:100001493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.90"; classtype:trojan-activity; sid:100001494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.99"; classtype:trojan-activity; sid:100001495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.147"; classtype:trojan-activity; sid:100001496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.175"; classtype:trojan-activity; sid:100001497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.206"; classtype:trojan-activity; sid:100001498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.208"; classtype:trojan-activity; sid:100001499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.88"; classtype:trojan-activity; sid:100001500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.101"; classtype:trojan-activity; sid:100001501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.170"; classtype:trojan-activity; sid:100001502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.188"; classtype:trojan-activity; sid:100001503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.227"; classtype:trojan-activity; sid:100001504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.48"; classtype:trojan-activity; sid:100001505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.64"; classtype:trojan-activity; sid:100001506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.12"; classtype:trojan-activity; sid:100001507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.39"; classtype:trojan-activity; sid:100001508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.112"; classtype:trojan-activity; sid:100001509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.113"; classtype:trojan-activity; sid:100001510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.192"; classtype:trojan-activity; sid:100001511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.198"; classtype:trojan-activity; sid:100001512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.47"; classtype:trojan-activity; sid:100001513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.215"; classtype:trojan-activity; sid:100001514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.237"; classtype:trojan-activity; sid:100001515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.26"; classtype:trojan-activity; sid:100001516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.56"; classtype:trojan-activity; sid:100001517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.73"; classtype:trojan-activity; sid:100001518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.86"; classtype:trojan-activity; sid:100001519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.138"; classtype:trojan-activity; sid:100001520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.151"; classtype:trojan-activity; sid:100001521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.40"; classtype:trojan-activity; sid:100001522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.53"; classtype:trojan-activity; sid:100001523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.70"; classtype:trojan-activity; sid:100001524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.93"; classtype:trojan-activity; sid:100001525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.97"; classtype:trojan-activity; sid:100001526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.184"; classtype:trojan-activity; sid:100001527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.203"; classtype:trojan-activity; sid:100001528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.231"; classtype:trojan-activity; sid:100001529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.4"; classtype:trojan-activity; sid:100001530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.5"; classtype:trojan-activity; sid:100001531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.104"; classtype:trojan-activity; sid:100001532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.116"; classtype:trojan-activity; sid:100001533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.123"; classtype:trojan-activity; sid:100001534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.155"; classtype:trojan-activity; sid:100001535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.19"; classtype:trojan-activity; sid:100001536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.192"; classtype:trojan-activity; sid:100001537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.193"; classtype:trojan-activity; sid:100001538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.229"; classtype:trojan-activity; sid:100001539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.199"; classtype:trojan-activity; sid:100001540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.201"; classtype:trojan-activity; sid:100001541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.208"; classtype:trojan-activity; sid:100001542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.217"; classtype:trojan-activity; sid:100001543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.245"; classtype:trojan-activity; sid:100001544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.26"; classtype:trojan-activity; sid:100001545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.28"; classtype:trojan-activity; sid:100001546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.191"; classtype:trojan-activity; sid:100001547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.2"; classtype:trojan-activity; sid:100001548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.26"; classtype:trojan-activity; sid:100001549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.30"; classtype:trojan-activity; sid:100001550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.56"; classtype:trojan-activity; sid:100001551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.7"; classtype:trojan-activity; sid:100001552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.90"; classtype:trojan-activity; sid:100001553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.109"; classtype:trojan-activity; sid:100001554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.122"; classtype:trojan-activity; sid:100001555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.197"; classtype:trojan-activity; sid:100001556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.4"; classtype:trojan-activity; sid:100001557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.79"; classtype:trojan-activity; sid:100001558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.89"; classtype:trojan-activity; sid:100001559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.14"; classtype:trojan-activity; sid:100001560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.153"; classtype:trojan-activity; sid:100001561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.56"; classtype:trojan-activity; sid:100001562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.167"; classtype:trojan-activity; sid:100001563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.220"; classtype:trojan-activity; sid:100001564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.222"; classtype:trojan-activity; sid:100001565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.237"; classtype:trojan-activity; sid:100001566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.61"; classtype:trojan-activity; sid:100001567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.62"; classtype:trojan-activity; sid:100001568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.83"; classtype:trojan-activity; sid:100001569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.93"; classtype:trojan-activity; sid:100001570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.10"; classtype:trojan-activity; sid:100001571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.122"; classtype:trojan-activity; sid:100001572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.15"; classtype:trojan-activity; sid:100001573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.159"; classtype:trojan-activity; sid:100001574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.166"; classtype:trojan-activity; sid:100001575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.168"; classtype:trojan-activity; sid:100001576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.176"; classtype:trojan-activity; sid:100001577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.219"; classtype:trojan-activity; sid:100001578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.230"; classtype:trojan-activity; sid:100001579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.231"; classtype:trojan-activity; sid:100001580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.236"; classtype:trojan-activity; sid:100001581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.43"; classtype:trojan-activity; sid:100001582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.63"; classtype:trojan-activity; sid:100001583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.64"; classtype:trojan-activity; sid:100001584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.75"; classtype:trojan-activity; sid:100001585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.97"; classtype:trojan-activity; sid:100001586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.19"; classtype:trojan-activity; sid:100001587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.220"; classtype:trojan-activity; sid:100001588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.237"; classtype:trojan-activity; sid:100001589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.131"; classtype:trojan-activity; sid:100001590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.178"; classtype:trojan-activity; sid:100001591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.230"; classtype:trojan-activity; sid:100001592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.60"; classtype:trojan-activity; sid:100001593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.69"; classtype:trojan-activity; sid:100001594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.166"; classtype:trojan-activity; sid:100001595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.199"; classtype:trojan-activity; sid:100001596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.215"; classtype:trojan-activity; sid:100001597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.217"; classtype:trojan-activity; sid:100001598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.35"; classtype:trojan-activity; sid:100001599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.45"; classtype:trojan-activity; sid:100001600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.5"; classtype:trojan-activity; sid:100001601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.1"; classtype:trojan-activity; sid:100001602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.108"; classtype:trojan-activity; sid:100001603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.114"; classtype:trojan-activity; sid:100001604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.123"; classtype:trojan-activity; sid:100001605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.179"; classtype:trojan-activity; sid:100001606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.221"; classtype:trojan-activity; sid:100001607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.49"; classtype:trojan-activity; sid:100001608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.73"; classtype:trojan-activity; sid:100001609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.97"; classtype:trojan-activity; sid:100001610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.118"; classtype:trojan-activity; sid:100001611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.245"; classtype:trojan-activity; sid:100001612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.66"; classtype:trojan-activity; sid:100001613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.163"; classtype:trojan-activity; sid:100001614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.174"; classtype:trojan-activity; sid:100001615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.229"; classtype:trojan-activity; sid:100001616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.44"; classtype:trojan-activity; sid:100001617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.108"; classtype:trojan-activity; sid:100001618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.110"; classtype:trojan-activity; sid:100001619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.123"; classtype:trojan-activity; sid:100001620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.186"; classtype:trojan-activity; sid:100001621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.188"; classtype:trojan-activity; sid:100001622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.237"; classtype:trojan-activity; sid:100001623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.41"; classtype:trojan-activity; sid:100001624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.47"; classtype:trojan-activity; sid:100001625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.5"; classtype:trojan-activity; sid:100001626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.54"; classtype:trojan-activity; sid:100001627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.117"; classtype:trojan-activity; sid:100001628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.170"; classtype:trojan-activity; sid:100001629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.237"; classtype:trojan-activity; sid:100001630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.24"; classtype:trojan-activity; sid:100001631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.70"; classtype:trojan-activity; sid:100001632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.97"; classtype:trojan-activity; sid:100001633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.149"; classtype:trojan-activity; sid:100001634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.184"; classtype:trojan-activity; sid:100001635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.233"; classtype:trojan-activity; sid:100001636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.238"; classtype:trojan-activity; sid:100001637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.28"; classtype:trojan-activity; sid:100001638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.76"; classtype:trojan-activity; sid:100001639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.8"; classtype:trojan-activity; sid:100001640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.110"; classtype:trojan-activity; sid:100001641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.147"; classtype:trojan-activity; sid:100001642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.237"; classtype:trojan-activity; sid:100001643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.247"; classtype:trojan-activity; sid:100001644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.156"; classtype:trojan-activity; sid:100001645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.228"; classtype:trojan-activity; sid:100001646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.250"; classtype:trojan-activity; sid:100001647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.36"; classtype:trojan-activity; sid:100001648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.138"; classtype:trojan-activity; sid:100001649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.170"; classtype:trojan-activity; sid:100001650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.171"; classtype:trojan-activity; sid:100001651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.172"; classtype:trojan-activity; sid:100001652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.177"; classtype:trojan-activity; sid:100001653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.198"; classtype:trojan-activity; sid:100001654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.218"; classtype:trojan-activity; sid:100001655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.238"; classtype:trojan-activity; sid:100001656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.243"; classtype:trojan-activity; sid:100001657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.77"; classtype:trojan-activity; sid:100001658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.113"; classtype:trojan-activity; sid:100001659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.117"; classtype:trojan-activity; sid:100001660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.148"; classtype:trojan-activity; sid:100001661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.177"; classtype:trojan-activity; sid:100001662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.28"; classtype:trojan-activity; sid:100001663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.46"; classtype:trojan-activity; sid:100001664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.56"; classtype:trojan-activity; sid:100001665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.75"; classtype:trojan-activity; sid:100001666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.77"; classtype:trojan-activity; sid:100001667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.112"; classtype:trojan-activity; sid:100001668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.116"; classtype:trojan-activity; sid:100001669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.165"; classtype:trojan-activity; sid:100001670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.209"; classtype:trojan-activity; sid:100001671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.215"; classtype:trojan-activity; sid:100001672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.219"; classtype:trojan-activity; sid:100001673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.224"; classtype:trojan-activity; sid:100001674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.246"; classtype:trojan-activity; sid:100001675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.34"; classtype:trojan-activity; sid:100001676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.106"; classtype:trojan-activity; sid:100001677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.137"; classtype:trojan-activity; sid:100001678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.138"; classtype:trojan-activity; sid:100001679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.14"; classtype:trojan-activity; sid:100001680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.167"; classtype:trojan-activity; sid:100001681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.171"; classtype:trojan-activity; sid:100001682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.177"; classtype:trojan-activity; sid:100001683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.179"; classtype:trojan-activity; sid:100001684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.199"; classtype:trojan-activity; sid:100001685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.215"; classtype:trojan-activity; sid:100001686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.225"; classtype:trojan-activity; sid:100001687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.233"; classtype:trojan-activity; sid:100001688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.239"; classtype:trojan-activity; sid:100001689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.244"; classtype:trojan-activity; sid:100001690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.32"; classtype:trojan-activity; sid:100001691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.37"; classtype:trojan-activity; sid:100001692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.46"; classtype:trojan-activity; sid:100001693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.48"; classtype:trojan-activity; sid:100001694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.69"; classtype:trojan-activity; sid:100001695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.102"; classtype:trojan-activity; sid:100001696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.199"; classtype:trojan-activity; sid:100001697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.200"; classtype:trojan-activity; sid:100001698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.51"; classtype:trojan-activity; sid:100001699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.69"; classtype:trojan-activity; sid:100001700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.16"; classtype:trojan-activity; sid:100001701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.173"; classtype:trojan-activity; sid:100001702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.174"; classtype:trojan-activity; sid:100001703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.2"; classtype:trojan-activity; sid:100001704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.201"; classtype:trojan-activity; sid:100001705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.207"; classtype:trojan-activity; sid:100001706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.208"; classtype:trojan-activity; sid:100001707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.220"; classtype:trojan-activity; sid:100001708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.7"; classtype:trojan-activity; sid:100001709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.116"; classtype:trojan-activity; sid:100001710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.166"; classtype:trojan-activity; sid:100001711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.172"; classtype:trojan-activity; sid:100001712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.190"; classtype:trojan-activity; sid:100001713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.196"; classtype:trojan-activity; sid:100001714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.214"; classtype:trojan-activity; sid:100001715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.66"; classtype:trojan-activity; sid:100001716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.87"; classtype:trojan-activity; sid:100001717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.0"; classtype:trojan-activity; sid:100001718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.135"; classtype:trojan-activity; sid:100001719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.213"; classtype:trojan-activity; sid:100001720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.70"; classtype:trojan-activity; sid:100001721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.93"; classtype:trojan-activity; sid:100001722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.96"; classtype:trojan-activity; sid:100001723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.171"; classtype:trojan-activity; sid:100001724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.251"; classtype:trojan-activity; sid:100001725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.252"; classtype:trojan-activity; sid:100001726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.6"; classtype:trojan-activity; sid:100001727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.99"; classtype:trojan-activity; sid:100001728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.14"; classtype:trojan-activity; sid:100001729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.197"; classtype:trojan-activity; sid:100001730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.198"; classtype:trojan-activity; sid:100001731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.2"; classtype:trojan-activity; sid:100001732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.20"; classtype:trojan-activity; sid:100001733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.211"; classtype:trojan-activity; sid:100001734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.229"; classtype:trojan-activity; sid:100001735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.243"; classtype:trojan-activity; sid:100001736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.244"; classtype:trojan-activity; sid:100001737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.89"; classtype:trojan-activity; sid:100001738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.112"; classtype:trojan-activity; sid:100001739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.141"; classtype:trojan-activity; sid:100001740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.162"; classtype:trojan-activity; sid:100001741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.173"; classtype:trojan-activity; sid:100001742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.181"; classtype:trojan-activity; sid:100001743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.196"; classtype:trojan-activity; sid:100001744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.208"; classtype:trojan-activity; sid:100001745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.21"; classtype:trojan-activity; sid:100001746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.215"; classtype:trojan-activity; sid:100001747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.228"; classtype:trojan-activity; sid:100001748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.234"; classtype:trojan-activity; sid:100001749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.245"; classtype:trojan-activity; sid:100001750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.26"; classtype:trojan-activity; sid:100001751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.1"; classtype:trojan-activity; sid:100001752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.2"; classtype:trojan-activity; sid:100001753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.200"; classtype:trojan-activity; sid:100001754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.53"; classtype:trojan-activity; sid:100001755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.21"; classtype:trojan-activity; sid:100001756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.38"; classtype:trojan-activity; sid:100001757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.83"; classtype:trojan-activity; sid:100001758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.91"; classtype:trojan-activity; sid:100001759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.0"; classtype:trojan-activity; sid:100001760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.127"; classtype:trojan-activity; sid:100001761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.129"; classtype:trojan-activity; sid:100001762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.184"; classtype:trojan-activity; sid:100001763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.218"; classtype:trojan-activity; sid:100001764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.231"; classtype:trojan-activity; sid:100001765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.245"; classtype:trojan-activity; sid:100001766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.33"; classtype:trojan-activity; sid:100001767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.5"; classtype:trojan-activity; sid:100001768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.107"; classtype:trojan-activity; sid:100001769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.135"; classtype:trojan-activity; sid:100001770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.153"; classtype:trojan-activity; sid:100001771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.223"; classtype:trojan-activity; sid:100001772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.26"; classtype:trojan-activity; sid:100001773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.38"; classtype:trojan-activity; sid:100001774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.56"; classtype:trojan-activity; sid:100001775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.6"; classtype:trojan-activity; sid:100001776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.71"; classtype:trojan-activity; sid:100001777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.81"; classtype:trojan-activity; sid:100001778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.83"; classtype:trojan-activity; sid:100001779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.1"; classtype:trojan-activity; sid:100001780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.132"; classtype:trojan-activity; sid:100001781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.165"; classtype:trojan-activity; sid:100001782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.98"; classtype:trojan-activity; sid:100001783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.110"; classtype:trojan-activity; sid:100001784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.129"; classtype:trojan-activity; sid:100001785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.158"; classtype:trojan-activity; sid:100001786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.245"; classtype:trojan-activity; sid:100001787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.57"; classtype:trojan-activity; sid:100001788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.63"; classtype:trojan-activity; sid:100001789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.144"; classtype:trojan-activity; sid:100001790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.192"; classtype:trojan-activity; sid:100001791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.219"; classtype:trojan-activity; sid:100001792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.231"; classtype:trojan-activity; sid:100001793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.233"; classtype:trojan-activity; sid:100001794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.95"; classtype:trojan-activity; sid:100001795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.155"; classtype:trojan-activity; sid:100001796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.226"; classtype:trojan-activity; sid:100001797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.228"; classtype:trojan-activity; sid:100001798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.41"; classtype:trojan-activity; sid:100001799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.56"; classtype:trojan-activity; sid:100001800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.67"; classtype:trojan-activity; sid:100001801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.82"; classtype:trojan-activity; sid:100001802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.203"; classtype:trojan-activity; sid:100001803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.34"; classtype:trojan-activity; sid:100001804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.171"; classtype:trojan-activity; sid:100001805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.228"; classtype:trojan-activity; sid:100001806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.240"; classtype:trojan-activity; sid:100001807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.25"; classtype:trojan-activity; sid:100001808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.1"; classtype:trojan-activity; sid:100001809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.106"; classtype:trojan-activity; sid:100001810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.121"; classtype:trojan-activity; sid:100001811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.138"; classtype:trojan-activity; sid:100001812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.147"; classtype:trojan-activity; sid:100001813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.30"; classtype:trojan-activity; sid:100001814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.33"; classtype:trojan-activity; sid:100001815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.69"; classtype:trojan-activity; sid:100001816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.0"; classtype:trojan-activity; sid:100001817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.134"; classtype:trojan-activity; sid:100001818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.143"; classtype:trojan-activity; sid:100001819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.155"; classtype:trojan-activity; sid:100001820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.197"; classtype:trojan-activity; sid:100001821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.217"; classtype:trojan-activity; sid:100001822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.22"; classtype:trojan-activity; sid:100001823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.241"; classtype:trojan-activity; sid:100001824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.70"; classtype:trojan-activity; sid:100001825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.89"; classtype:trojan-activity; sid:100001826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.90"; classtype:trojan-activity; sid:100001827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.95"; classtype:trojan-activity; sid:100001828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.205"; classtype:trojan-activity; sid:100001829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.25"; classtype:trojan-activity; sid:100001830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.6"; classtype:trojan-activity; sid:100001831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.119"; classtype:trojan-activity; sid:100001832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.187"; classtype:trojan-activity; sid:100001833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.224"; classtype:trojan-activity; sid:100001834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.42"; classtype:trojan-activity; sid:100001835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.11"; classtype:trojan-activity; sid:100001836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.141"; classtype:trojan-activity; sid:100001837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.151"; classtype:trojan-activity; sid:100001838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.16"; classtype:trojan-activity; sid:100001839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.168"; classtype:trojan-activity; sid:100001840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.245"; classtype:trojan-activity; sid:100001841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.110"; classtype:trojan-activity; sid:100001842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.168"; classtype:trojan-activity; sid:100001843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.139"; classtype:trojan-activity; sid:100001844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.214"; classtype:trojan-activity; sid:100001845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.247"; classtype:trojan-activity; sid:100001846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.252"; classtype:trojan-activity; sid:100001847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.3"; classtype:trojan-activity; sid:100001848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.17"; classtype:trojan-activity; sid:100001849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.51"; classtype:trojan-activity; sid:100001850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.79"; classtype:trojan-activity; sid:100001851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.131"; classtype:trojan-activity; sid:100001852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.168"; classtype:trojan-activity; sid:100001853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.177"; classtype:trojan-activity; sid:100001854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.22"; classtype:trojan-activity; sid:100001855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.236"; classtype:trojan-activity; sid:100001856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.237"; classtype:trojan-activity; sid:100001857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.32"; classtype:trojan-activity; sid:100001858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.137"; classtype:trojan-activity; sid:100001859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.160"; classtype:trojan-activity; sid:100001860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.202"; classtype:trojan-activity; sid:100001861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.66"; classtype:trojan-activity; sid:100001862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.146"; classtype:trojan-activity; sid:100001863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.161"; classtype:trojan-activity; sid:100001864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.21"; classtype:trojan-activity; sid:100001865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.212"; classtype:trojan-activity; sid:100001866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.94"; classtype:trojan-activity; sid:100001867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.135"; classtype:trojan-activity; sid:100001868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.151"; classtype:trojan-activity; sid:100001869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.186"; classtype:trojan-activity; sid:100001870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.217"; classtype:trojan-activity; sid:100001871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.4"; classtype:trojan-activity; sid:100001872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.5"; classtype:trojan-activity; sid:100001873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.56"; classtype:trojan-activity; sid:100001874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.58"; classtype:trojan-activity; sid:100001875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.79"; classtype:trojan-activity; sid:100001876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.15"; classtype:trojan-activity; sid:100001877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.158"; classtype:trojan-activity; sid:100001878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.163"; classtype:trojan-activity; sid:100001879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.167"; classtype:trojan-activity; sid:100001880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.205"; classtype:trojan-activity; sid:100001881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.225"; classtype:trojan-activity; sid:100001882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.64"; classtype:trojan-activity; sid:100001883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.103"; classtype:trojan-activity; sid:100001884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.14"; classtype:trojan-activity; sid:100001885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.163"; classtype:trojan-activity; sid:100001886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.25"; classtype:trojan-activity; sid:100001887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.29"; classtype:trojan-activity; sid:100001888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.38"; classtype:trojan-activity; sid:100001889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.41"; classtype:trojan-activity; sid:100001890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.47"; classtype:trojan-activity; sid:100001891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.77"; classtype:trojan-activity; sid:100001892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.103"; classtype:trojan-activity; sid:100001893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.11"; classtype:trojan-activity; sid:100001894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.120"; classtype:trojan-activity; sid:100001895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.24"; classtype:trojan-activity; sid:100001896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.252"; classtype:trojan-activity; sid:100001897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.33"; classtype:trojan-activity; sid:100001898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.37"; classtype:trojan-activity; sid:100001899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.50"; classtype:trojan-activity; sid:100001900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.52"; classtype:trojan-activity; sid:100001901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.54"; classtype:trojan-activity; sid:100001902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.72"; classtype:trojan-activity; sid:100001903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.75"; classtype:trojan-activity; sid:100001904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.10"; classtype:trojan-activity; sid:100001905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.141"; classtype:trojan-activity; sid:100001906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.179"; classtype:trojan-activity; sid:100001907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.99"; classtype:trojan-activity; sid:100001908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.28"; classtype:trojan-activity; sid:100001909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.74"; classtype:trojan-activity; sid:100001910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.79"; classtype:trojan-activity; sid:100001911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.161"; classtype:trojan-activity; sid:100001912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.241"; classtype:trojan-activity; sid:100001913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.33"; classtype:trojan-activity; sid:100001914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.54"; classtype:trojan-activity; sid:100001915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.134"; classtype:trojan-activity; sid:100001916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.157"; classtype:trojan-activity; sid:100001917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.189"; classtype:trojan-activity; sid:100001918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.89"; classtype:trojan-activity; sid:100001919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.209"; classtype:trojan-activity; sid:100001920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.212"; classtype:trojan-activity; sid:100001921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.76"; classtype:trojan-activity; sid:100001922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.156"; classtype:trojan-activity; sid:100001923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.163"; classtype:trojan-activity; sid:100001924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.17"; classtype:trojan-activity; sid:100001925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.171"; classtype:trojan-activity; sid:100001926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.178"; classtype:trojan-activity; sid:100001927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.219"; classtype:trojan-activity; sid:100001928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.237"; classtype:trojan-activity; sid:100001929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.95"; classtype:trojan-activity; sid:100001930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.111"; classtype:trojan-activity; sid:100001931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.115"; classtype:trojan-activity; sid:100001932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.141"; classtype:trojan-activity; sid:100001933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.166"; classtype:trojan-activity; sid:100001934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.168"; classtype:trojan-activity; sid:100001935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.42"; classtype:trojan-activity; sid:100001936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.43"; classtype:trojan-activity; sid:100001937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.70"; classtype:trojan-activity; sid:100001938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.8"; classtype:trojan-activity; sid:100001939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.84"; classtype:trojan-activity; sid:100001940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.192"; classtype:trojan-activity; sid:100001941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.21"; classtype:trojan-activity; sid:100001942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.230"; classtype:trojan-activity; sid:100001943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.78"; classtype:trojan-activity; sid:100001944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.96"; classtype:trojan-activity; sid:100001945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.12"; classtype:trojan-activity; sid:100001946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.155"; classtype:trojan-activity; sid:100001947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.156"; classtype:trojan-activity; sid:100001948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.158"; classtype:trojan-activity; sid:100001949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.187"; classtype:trojan-activity; sid:100001950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.190"; classtype:trojan-activity; sid:100001951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.22"; classtype:trojan-activity; sid:100001952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.231"; classtype:trojan-activity; sid:100001953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.19"; classtype:trojan-activity; sid:100001954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.202"; classtype:trojan-activity; sid:100001955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.236"; classtype:trojan-activity; sid:100001956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.186"; classtype:trojan-activity; sid:100001957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.192"; classtype:trojan-activity; sid:100001958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.199"; classtype:trojan-activity; sid:100001959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.211"; classtype:trojan-activity; sid:100001960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.228"; classtype:trojan-activity; sid:100001961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.54"; classtype:trojan-activity; sid:100001962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.93"; classtype:trojan-activity; sid:100001963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.0"; classtype:trojan-activity; sid:100001964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.36"; classtype:trojan-activity; sid:100001965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.51"; classtype:trojan-activity; sid:100001966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.55"; classtype:trojan-activity; sid:100001967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.81"; classtype:trojan-activity; sid:100001968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.83"; classtype:trojan-activity; sid:100001969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.89"; classtype:trojan-activity; sid:100001970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.116"; classtype:trojan-activity; sid:100001971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.44"; classtype:trojan-activity; sid:100001972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.66"; classtype:trojan-activity; sid:100001973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.85"; classtype:trojan-activity; sid:100001974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.111"; classtype:trojan-activity; sid:100001975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.119"; classtype:trojan-activity; sid:100001976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.128"; classtype:trojan-activity; sid:100001977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.18"; classtype:trojan-activity; sid:100001978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.6"; classtype:trojan-activity; sid:100001979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.60"; classtype:trojan-activity; sid:100001980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.71"; classtype:trojan-activity; sid:100001981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.10"; classtype:trojan-activity; sid:100001982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.109"; classtype:trojan-activity; sid:100001983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.196"; classtype:trojan-activity; sid:100001984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.218"; classtype:trojan-activity; sid:100001985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.246"; classtype:trojan-activity; sid:100001986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.5"; classtype:trojan-activity; sid:100001987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.50"; classtype:trojan-activity; sid:100001988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.71"; classtype:trojan-activity; sid:100001989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.83"; classtype:trojan-activity; sid:100001990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.93"; classtype:trojan-activity; sid:100001991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.160"; classtype:trojan-activity; sid:100001992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.45"; classtype:trojan-activity; sid:100001993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.84"; classtype:trojan-activity; sid:100001994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.108"; classtype:trojan-activity; sid:100001995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.222"; classtype:trojan-activity; sid:100001996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.30"; classtype:trojan-activity; sid:100001997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.37"; classtype:trojan-activity; sid:100001998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.47"; classtype:trojan-activity; sid:100001999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.73.96"; classtype:trojan-activity; sid:100002000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.182"; classtype:trojan-activity; sid:100002001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.205"; classtype:trojan-activity; sid:100002002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.48"; classtype:trojan-activity; sid:100002003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.181"; classtype:trojan-activity; sid:100002004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.19"; classtype:trojan-activity; sid:100002005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.84"; classtype:trojan-activity; sid:100002006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.87"; classtype:trojan-activity; sid:100002007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.103"; classtype:trojan-activity; sid:100002008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.109"; classtype:trojan-activity; sid:100002009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.209"; classtype:trojan-activity; sid:100002010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.21"; classtype:trojan-activity; sid:100002011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.217"; classtype:trojan-activity; sid:100002012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.83"; classtype:trojan-activity; sid:100002013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.9"; classtype:trojan-activity; sid:100002014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.248"; classtype:trojan-activity; sid:100002015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.34"; classtype:trojan-activity; sid:100002016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.46"; classtype:trojan-activity; sid:100002017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.47"; classtype:trojan-activity; sid:100002018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.198"; classtype:trojan-activity; sid:100002019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.243"; classtype:trojan-activity; sid:100002020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.57"; classtype:trojan-activity; sid:100002021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.97"; classtype:trojan-activity; sid:100002022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.17"; classtype:trojan-activity; sid:100002023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.244"; classtype:trojan-activity; sid:100002024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.247"; classtype:trojan-activity; sid:100002025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.69"; classtype:trojan-activity; sid:100002026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.100"; classtype:trojan-activity; sid:100002027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.227"; classtype:trojan-activity; sid:100002028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.64"; classtype:trojan-activity; sid:100002029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.100"; classtype:trojan-activity; sid:100002030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.129"; classtype:trojan-activity; sid:100002031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.197"; classtype:trojan-activity; sid:100002032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.20"; classtype:trojan-activity; sid:100002033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.41"; classtype:trojan-activity; sid:100002034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.61"; classtype:trojan-activity; sid:100002035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.68"; classtype:trojan-activity; sid:100002036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.79"; classtype:trojan-activity; sid:100002037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.86"; classtype:trojan-activity; sid:100002038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.89"; classtype:trojan-activity; sid:100002039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.19"; classtype:trojan-activity; sid:100002040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.192"; classtype:trojan-activity; sid:100002041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.226"; classtype:trojan-activity; sid:100002042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.232"; classtype:trojan-activity; sid:100002043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.244"; classtype:trojan-activity; sid:100002044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.253"; classtype:trojan-activity; sid:100002045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.82.23"; classtype:trojan-activity; sid:100002046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.82.73"; classtype:trojan-activity; sid:100002047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.144"; classtype:trojan-activity; sid:100002048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.2"; classtype:trojan-activity; sid:100002049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.20"; classtype:trojan-activity; sid:100002050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.247"; classtype:trojan-activity; sid:100002051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.102"; classtype:trojan-activity; sid:100002052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.159"; classtype:trojan-activity; sid:100002053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.17"; classtype:trojan-activity; sid:100002054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.215"; classtype:trojan-activity; sid:100002055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.28"; classtype:trojan-activity; sid:100002056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.42"; classtype:trojan-activity; sid:100002057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.153"; classtype:trojan-activity; sid:100002058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.183"; classtype:trojan-activity; sid:100002059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.23"; classtype:trojan-activity; sid:100002060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.230"; classtype:trojan-activity; sid:100002061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.57"; classtype:trojan-activity; sid:100002062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.119"; classtype:trojan-activity; sid:100002063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.122"; classtype:trojan-activity; sid:100002064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.36"; classtype:trojan-activity; sid:100002065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.59"; classtype:trojan-activity; sid:100002066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.126"; classtype:trojan-activity; sid:100002067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.139"; classtype:trojan-activity; sid:100002068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.144"; classtype:trojan-activity; sid:100002069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.253"; classtype:trojan-activity; sid:100002070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.160"; classtype:trojan-activity; sid:100002071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.166"; classtype:trojan-activity; sid:100002072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.181"; classtype:trojan-activity; sid:100002073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.182"; classtype:trojan-activity; sid:100002074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.24"; classtype:trojan-activity; sid:100002075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.248"; classtype:trojan-activity; sid:100002076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.69"; classtype:trojan-activity; sid:100002077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.157"; classtype:trojan-activity; sid:100002078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.169"; classtype:trojan-activity; sid:100002079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.30"; classtype:trojan-activity; sid:100002080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.125"; classtype:trojan-activity; sid:100002081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.139"; classtype:trojan-activity; sid:100002082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.175"; classtype:trojan-activity; sid:100002083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.179"; classtype:trojan-activity; sid:100002084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.198"; classtype:trojan-activity; sid:100002085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.210"; classtype:trojan-activity; sid:100002086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.215"; classtype:trojan-activity; sid:100002087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.225"; classtype:trojan-activity; sid:100002088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.64"; classtype:trojan-activity; sid:100002089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.84"; classtype:trojan-activity; sid:100002090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.95"; classtype:trojan-activity; sid:100002091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.122"; classtype:trojan-activity; sid:100002092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.167"; classtype:trojan-activity; sid:100002093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.172"; classtype:trojan-activity; sid:100002094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.185"; classtype:trojan-activity; sid:100002095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.21"; classtype:trojan-activity; sid:100002096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.4"; classtype:trojan-activity; sid:100002097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.74"; classtype:trojan-activity; sid:100002098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.81"; classtype:trojan-activity; sid:100002099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.90"; classtype:trojan-activity; sid:100002100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.108"; classtype:trojan-activity; sid:100002101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.13"; classtype:trojan-activity; sid:100002102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.15"; classtype:trojan-activity; sid:100002103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.244"; classtype:trojan-activity; sid:100002104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.253"; classtype:trojan-activity; sid:100002105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.96"; classtype:trojan-activity; sid:100002106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.132"; classtype:trojan-activity; sid:100002107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.186"; classtype:trojan-activity; sid:100002108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.200"; classtype:trojan-activity; sid:100002109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.215"; classtype:trojan-activity; sid:100002110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.231"; classtype:trojan-activity; sid:100002111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.253"; classtype:trojan-activity; sid:100002112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.45"; classtype:trojan-activity; sid:100002113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.12"; classtype:trojan-activity; sid:100002114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.143"; classtype:trojan-activity; sid:100002115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.150"; classtype:trojan-activity; sid:100002116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.159"; classtype:trojan-activity; sid:100002117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.199"; classtype:trojan-activity; sid:100002118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.44"; classtype:trojan-activity; sid:100002119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.62"; classtype:trojan-activity; sid:100002120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.195"; classtype:trojan-activity; sid:100002121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.200"; classtype:trojan-activity; sid:100002122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.27"; classtype:trojan-activity; sid:100002123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.40"; classtype:trojan-activity; sid:100002124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.55"; classtype:trojan-activity; sid:100002125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.116"; classtype:trojan-activity; sid:100002126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.141"; classtype:trojan-activity; sid:100002127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.163"; classtype:trojan-activity; sid:100002128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.17"; classtype:trojan-activity; sid:100002129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.227"; classtype:trojan-activity; sid:100002130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.4"; classtype:trojan-activity; sid:100002131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.56"; classtype:trojan-activity; sid:100002132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.81"; classtype:trojan-activity; sid:100002133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.128"; classtype:trojan-activity; sid:100002134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.135"; classtype:trojan-activity; sid:100002135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.216"; classtype:trojan-activity; sid:100002136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.228"; classtype:trojan-activity; sid:100002137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.254"; classtype:trojan-activity; sid:100002138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.29"; classtype:trojan-activity; sid:100002139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.44"; classtype:trojan-activity; sid:100002140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.68"; classtype:trojan-activity; sid:100002141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.123"; classtype:trojan-activity; sid:100002142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.130"; classtype:trojan-activity; sid:100002143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.91"; classtype:trojan-activity; sid:100002144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.19.183.14"; classtype:trojan-activity; sid:100002145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.205.101.33"; classtype:trojan-activity; sid:100002146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.21.164.68"; classtype:trojan-activity; sid:100002147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.217.8.194"; classtype:trojan-activity; sid:100002148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.22.117.102"; classtype:trojan-activity; sid:100002149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.222.252.130"; classtype:trojan-activity; sid:100002150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.34.183.30"; classtype:trojan-activity; sid:100002151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.48.235.59"; classtype:trojan-activity; sid:100002152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.92.246.246"; classtype:trojan-activity; sid:100002153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.95.115.33"; classtype:trojan-activity; sid:100002154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.95.136.35"; classtype:trojan-activity; sid:100002155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.159.58.134"; classtype:trojan-activity; sid:100002156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.4.187.39"; classtype:trojan-activity; sid:100002157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.42.107.139"; classtype:trojan-activity; sid:100002158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.43.157.173"; classtype:trojan-activity; sid:100002159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.60.84.7"; classtype:trojan-activity; sid:100002160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.99.210.161"; classtype:trojan-activity; sid:100002161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.109.36.244"; classtype:trojan-activity; sid:100002162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.111.101.141"; classtype:trojan-activity; sid:100002163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.114.111.153"; classtype:trojan-activity; sid:100002164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.116.203.220"; classtype:trojan-activity; sid:100002165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.120.149.106"; classtype:trojan-activity; sid:100002166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.122.13.227"; classtype:trojan-activity; sid:100002167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.125.44.194"; classtype:trojan-activity; sid:100002168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.157.66.204"; classtype:trojan-activity; sid:100002169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.175.236.209"; classtype:trojan-activity; sid:100002170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.105.41"; classtype:trojan-activity; sid:100002171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.110.243"; classtype:trojan-activity; sid:100002172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.165.230"; classtype:trojan-activity; sid:100002173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.214.171"; classtype:trojan-activity; sid:100002174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.34.51"; classtype:trojan-activity; sid:100002175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.96.248"; classtype:trojan-activity; sid:100002176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.104.65"; classtype:trojan-activity; sid:100002177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.242.73"; classtype:trojan-activity; sid:100002178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.218.5.171"; classtype:trojan-activity; sid:100002179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.248.80.38"; classtype:trojan-activity; sid:100002180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.253.99.109"; classtype:trojan-activity; sid:100002181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.111.36"; classtype:trojan-activity; sid:100002182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.53.93"; classtype:trojan-activity; sid:100002183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.94.170.166"; classtype:trojan-activity; sid:100002184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.138.154"; classtype:trojan-activity; sid:100002185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.238"; classtype:trojan-activity; sid:100002186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.6"; classtype:trojan-activity; sid:100002187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.143.60.163"; classtype:trojan-activity; sid:100002188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.193.107.10"; classtype:trojan-activity; sid:100002189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.222"; classtype:trojan-activity; sid:100002190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.230"; classtype:trojan-activity; sid:100002191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.210.45.42"; classtype:trojan-activity; sid:100002192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.215.47.82"; classtype:trojan-activity; sid:100002193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.224.242.131"; classtype:trojan-activity; sid:100002194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.236.4"; classtype:trojan-activity; sid:100002195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.59.162"; classtype:trojan-activity; sid:100002196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.28.118"; classtype:trojan-activity; sid:100002197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.34.220"; classtype:trojan-activity; sid:100002198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.43.249"; classtype:trojan-activity; sid:100002199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.52.131"; classtype:trojan-activity; sid:100002200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.238.197"; classtype:trojan-activity; sid:100002201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.29.28"; classtype:trojan-activity; sid:100002202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.105.40"; classtype:trojan-activity; sid:100002203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.111.64"; classtype:trojan-activity; sid:100002204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.64.27"; classtype:trojan-activity; sid:100002205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.76.42"; classtype:trojan-activity; sid:100002206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.79.103"; classtype:trojan-activity; sid:100002207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.83.88"; classtype:trojan-activity; sid:100002208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.92.90"; classtype:trojan-activity; sid:100002209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.93.96"; classtype:trojan-activity; sid:100002210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.104.106"; classtype:trojan-activity; sid:100002211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.105.208"; classtype:trojan-activity; sid:100002212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.108.244"; classtype:trojan-activity; sid:100002213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.116.70"; classtype:trojan-activity; sid:100002214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.118.250"; classtype:trojan-activity; sid:100002215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.119.66"; classtype:trojan-activity; sid:100002216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.36.175"; classtype:trojan-activity; sid:100002217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.60.73"; classtype:trojan-activity; sid:100002218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.61.252"; classtype:trojan-activity; sid:100002219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.80.107"; classtype:trojan-activity; sid:100002220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.94.196"; classtype:trojan-activity; sid:100002221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.99.150"; classtype:trojan-activity; sid:100002222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.13.57"; classtype:trojan-activity; sid:100002223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.15.172"; classtype:trojan-activity; sid:100002224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.25.120"; classtype:trojan-activity; sid:100002225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.26.235"; classtype:trojan-activity; sid:100002226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.29.220"; classtype:trojan-activity; sid:100002227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.39.51"; classtype:trojan-activity; sid:100002228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.43.27"; classtype:trojan-activity; sid:100002229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.49.127"; classtype:trojan-activity; sid:100002230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.118.146.181"; classtype:trojan-activity; sid:100002231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.118.166.128"; classtype:trojan-activity; sid:100002232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.100.135"; classtype:trojan-activity; sid:100002233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.109.173"; classtype:trojan-activity; sid:100002234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.118.218"; classtype:trojan-activity; sid:100002235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.14.252"; classtype:trojan-activity; sid:100002236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.15.78"; classtype:trojan-activity; sid:100002237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.166.208"; classtype:trojan-activity; sid:100002238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.166.76"; classtype:trojan-activity; sid:100002239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.179.193"; classtype:trojan-activity; sid:100002240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.197.123"; classtype:trojan-activity; sid:100002241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.202.180"; classtype:trojan-activity; sid:100002242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.21.68"; classtype:trojan-activity; sid:100002243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.211.69"; classtype:trojan-activity; sid:100002244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.214.120"; classtype:trojan-activity; sid:100002245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.221.141"; classtype:trojan-activity; sid:100002246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.226.84"; classtype:trojan-activity; sid:100002247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.255.115"; classtype:trojan-activity; sid:100002248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.7.54"; classtype:trojan-activity; sid:100002249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.89.107"; classtype:trojan-activity; sid:100002250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.22"; classtype:trojan-activity; sid:100002251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.46"; classtype:trojan-activity; sid:100002252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.37.251"; classtype:trojan-activity; sid:100002253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.43.0"; classtype:trojan-activity; sid:100002254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.129.163"; classtype:trojan-activity; sid:100002255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.134.70"; classtype:trojan-activity; sid:100002256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.15.223"; classtype:trojan-activity; sid:100002257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.157.35"; classtype:trojan-activity; sid:100002258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.205.201"; classtype:trojan-activity; sid:100002259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.205.237"; classtype:trojan-activity; sid:100002260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.207.195"; classtype:trojan-activity; sid:100002261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.254.147"; classtype:trojan-activity; sid:100002262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.55.106"; classtype:trojan-activity; sid:100002263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.66.189"; classtype:trojan-activity; sid:100002264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.9.117"; classtype:trojan-activity; sid:100002265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.94.13"; classtype:trojan-activity; sid:100002266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.202.18"; classtype:trojan-activity; sid:100002267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.123.203.21"; classtype:trojan-activity; sid:100002268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.123.211.239"; classtype:trojan-activity; sid:100002269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.123.241.195"; classtype:trojan-activity; sid:100002270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.123.107"; classtype:trojan-activity; sid:100002271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.177.48"; classtype:trojan-activity; sid:100002272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.19.87"; classtype:trojan-activity; sid:100002273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.201.207"; classtype:trojan-activity; sid:100002274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.88.122"; classtype:trojan-activity; sid:100002275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.113.127"; classtype:trojan-activity; sid:100002276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.123.19"; classtype:trojan-activity; sid:100002277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.126.203"; classtype:trojan-activity; sid:100002278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.127.254"; classtype:trojan-activity; sid:100002279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.67.24"; classtype:trojan-activity; sid:100002280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.83.79"; classtype:trojan-activity; sid:100002281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.88.138"; classtype:trojan-activity; sid:100002282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.0.16"; classtype:trojan-activity; sid:100002283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.103.79"; classtype:trojan-activity; sid:100002284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.104.235"; classtype:trojan-activity; sid:100002285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.106.43"; classtype:trojan-activity; sid:100002286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.152.3"; classtype:trojan-activity; sid:100002287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.155.157"; classtype:trojan-activity; sid:100002288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.221.243"; classtype:trojan-activity; sid:100002289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.93.38"; classtype:trojan-activity; sid:100002290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.160.98.250"; classtype:trojan-activity; sid:100002291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.172.36.164"; classtype:trojan-activity; sid:100002292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.233.0.252"; classtype:trojan-activity; sid:100002293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.235.252.31"; classtype:trojan-activity; sid:100002294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.53.197.62"; classtype:trojan-activity; sid:100002295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.56.193.251"; classtype:trojan-activity; sid:100002296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.59.235.150"; classtype:trojan-activity; sid:100002297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.104.83"; classtype:trojan-activity; sid:100002298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.225.154"; classtype:trojan-activity; sid:100002299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.109.169.45"; classtype:trojan-activity; sid:100002300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.11.238.228"; classtype:trojan-activity; sid:100002301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.136.252.233"; classtype:trojan-activity; sid:100002302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.150.244.122"; classtype:trojan-activity; sid:100002303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.16.208.30"; classtype:trojan-activity; sid:100002304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.185.112.19"; classtype:trojan-activity; sid:100002305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.185.162.225"; classtype:trojan-activity; sid:100002306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.187.163.176"; classtype:trojan-activity; sid:100002307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.151.225"; classtype:trojan-activity; sid:100002308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.180.116"; classtype:trojan-activity; sid:100002309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.188.186"; classtype:trojan-activity; sid:100002310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.228.38"; classtype:trojan-activity; sid:100002311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.93.116"; classtype:trojan-activity; sid:100002312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.105.21"; classtype:trojan-activity; sid:100002313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.127.89"; classtype:trojan-activity; sid:100002314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.26.115"; classtype:trojan-activity; sid:100002315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.92.195.140"; classtype:trojan-activity; sid:100002316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.97.22.14"; classtype:trojan-activity; sid:100002317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.164.185.41"; classtype:trojan-activity; sid:100002318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.175.115.10"; classtype:trojan-activity; sid:100002319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.74.149.230"; classtype:trojan-activity; sid:100002320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.106.209.68"; classtype:trojan-activity; sid:100002321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.107.3.8"; classtype:trojan-activity; sid:100002322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.172.110.235"; classtype:trojan-activity; sid:100002323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.181.10.234"; classtype:trojan-activity; sid:100002324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.112"; classtype:trojan-activity; sid:100002325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.54"; classtype:trojan-activity; sid:100002326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.77"; classtype:trojan-activity; sid:100002327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.93"; classtype:trojan-activity; sid:100002328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.219.133.122"; classtype:trojan-activity; sid:100002329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.221.3.244"; classtype:trojan-activity; sid:100002330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.228.141.74"; classtype:trojan-activity; sid:100002331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.239.243.77"; classtype:trojan-activity; sid:100002332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.245.96.94"; classtype:trojan-activity; sid:100002333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.26.113.95"; classtype:trojan-activity; sid:100002334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.34.16.231"; classtype:trojan-activity; sid:100002335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.43.19.151"; classtype:trojan-activity; sid:100002336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.45.103.212"; classtype:trojan-activity; sid:100002337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.55.1.182"; classtype:trojan-activity; sid:100002338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.68.230.207"; classtype:trojan-activity; sid:100002339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.81.157.186"; classtype:trojan-activity; sid:100002340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.185"; classtype:trojan-activity; sid:100002341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.213"; classtype:trojan-activity; sid:100002342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.160"; classtype:trojan-activity; sid:100002343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.161"; classtype:trojan-activity; sid:100002344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.219"; classtype:trojan-activity; sid:100002345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.80"; classtype:trojan-activity; sid:100002346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.90.166.56"; classtype:trojan-activity; sid:100002347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.151.144.85"; classtype:trojan-activity; sid:100002348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.219.164"; classtype:trojan-activity; sid:100002349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.112"; classtype:trojan-activity; sid:100002350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.77"; classtype:trojan-activity; sid:100002351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.91"; classtype:trojan-activity; sid:100002352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.253.150"; classtype:trojan-activity; sid:100002353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.183.131.37"; classtype:trojan-activity; sid:100002354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.225.120.173"; classtype:trojan-activity; sid:100002355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.232.44.86"; classtype:trojan-activity; sid:100002356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.28.60.184"; classtype:trojan-activity; sid:100002357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.33.113.77"; classtype:trojan-activity; sid:100002358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.4.125.48"; classtype:trojan-activity; sid:100002359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.73.188.132"; classtype:trojan-activity; sid:100002360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.12.10.98"; classtype:trojan-activity; sid:100002361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.188.124.229"; classtype:trojan-activity; sid:100002362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.212.200.162"; classtype:trojan-activity; sid:100002363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.233.208.103"; classtype:trojan-activity; sid:100002364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.33.71.68"; classtype:trojan-activity; sid:100002365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.21.14"; classtype:trojan-activity; sid:100002366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.231.246"; classtype:trojan-activity; sid:100002367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.113.102.18"; classtype:trojan-activity; sid:100002368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.113.81.17"; classtype:trojan-activity; sid:100002369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.119.45.194"; classtype:trojan-activity; sid:100002370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.13.179.87"; classtype:trojan-activity; sid:100002371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.138.200.32"; classtype:trojan-activity; sid:100002372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.152.41.141"; classtype:trojan-activity; sid:100002373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.178.50"; classtype:trojan-activity; sid:100002374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.179.151"; classtype:trojan-activity; sid:100002375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.45.140"; classtype:trojan-activity; sid:100002376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.167.159"; classtype:trojan-activity; sid:100002377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.242.144"; classtype:trojan-activity; sid:100002378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.81.100.83"; classtype:trojan-activity; sid:100002379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.83.202.25"; classtype:trojan-activity; sid:100002380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"189.222.157.241"; classtype:trojan-activity; sid:100002381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"19.dbstrony.pl"; classtype:trojan-activity; sid:100002382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.0.42.106"; classtype:trojan-activity; sid:100002383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.109.178.139"; classtype:trojan-activity; sid:100002384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.110.161.252"; classtype:trojan-activity; sid:100002385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.111.151.164"; classtype:trojan-activity; sid:100002386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.119.207.58"; classtype:trojan-activity; sid:100002387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.12.99.194"; classtype:trojan-activity; sid:100002388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.121.194.18"; classtype:trojan-activity; sid:100002389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.160"; classtype:trojan-activity; sid:100002390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.3"; classtype:trojan-activity; sid:100002391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.37"; classtype:trojan-activity; sid:100002392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.41"; classtype:trojan-activity; sid:100002393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.42"; classtype:trojan-activity; sid:100002394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.15.212"; classtype:trojan-activity; sid:100002395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.20.14"; classtype:trojan-activity; sid:100002396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.141.117.41"; classtype:trojan-activity; sid:100002397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.147.16.184"; classtype:trojan-activity; sid:100002398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.159.240.9"; classtype:trojan-activity; sid:100002399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.187.55.150"; classtype:trojan-activity; sid:100002400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.210.214.130"; classtype:trojan-activity; sid:100002401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.177.39"; classtype:trojan-activity; sid:100002402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.226.63"; classtype:trojan-activity; sid:100002403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.49.207"; classtype:trojan-activity; sid:100002404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.214.24.194"; classtype:trojan-activity; sid:100002405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.216.140.123"; classtype:trojan-activity; sid:100002406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.35.225.36"; classtype:trojan-activity; sid:100002407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.65.206.162"; classtype:trojan-activity; sid:100002408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.73.12.149"; classtype:trojan-activity; sid:100002409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.92.4.231"; classtype:trojan-activity; sid:100002410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.135"; classtype:trojan-activity; sid:100002411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.200"; classtype:trojan-activity; sid:100002412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.41.33"; classtype:trojan-activity; sid:100002413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"191.255.248.220"; classtype:trojan-activity; sid:100002414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.175.130"; classtype:trojan-activity; sid:100002415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.241.200"; classtype:trojan-activity; sid:100002416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.209.27"; classtype:trojan-activity; sid:100002417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.220.55"; classtype:trojan-activity; sid:100002418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.228.67"; classtype:trojan-activity; sid:100002419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.3.152.166"; classtype:trojan-activity; sid:100002420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.3.73.205"; classtype:trojan-activity; sid:100002421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.99.240.77"; classtype:trojan-activity; sid:100002422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.142.146.25"; classtype:trojan-activity; sid:100002423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.228.135.144"; classtype:trojan-activity; sid:100002424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.38.55.9"; classtype:trojan-activity; sid:100002425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.91.131.237"; classtype:trojan-activity; sid:100002426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.147.142.230"; classtype:trojan-activity; sid:100002427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.15.36.167"; classtype:trojan-activity; sid:100002428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.152.35.139"; classtype:trojan-activity; sid:100002429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.38.20.199"; classtype:trojan-activity; sid:100002430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.139.126.51"; classtype:trojan-activity; sid:100002431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.228.231.218"; classtype:trojan-activity; sid:100002432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.24.94.187"; classtype:trojan-activity; sid:100002433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.202.26.182"; classtype:trojan-activity; sid:100002434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.218.48.82"; classtype:trojan-activity; sid:100002435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.148.90"; classtype:trojan-activity; sid:100002436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.166.203"; classtype:trojan-activity; sid:100002437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.159.2.106"; classtype:trojan-activity; sid:100002438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.50.27.115"; classtype:trojan-activity; sid:100002439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.133.218"; classtype:trojan-activity; sid:100002440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.207.121"; classtype:trojan-activity; sid:100002441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.251.105"; classtype:trojan-activity; sid:100002442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.251.72.110"; classtype:trojan-activity; sid:100002443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.201.76"; classtype:trojan-activity; sid:100002444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.202.7"; classtype:trojan-activity; sid:100002445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"199.188.101.109"; classtype:trojan-activity; sid:100002446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1am.co.nz"; classtype:trojan-activity; sid:100002447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.229.89.119"; classtype:trojan-activity; sid:100002448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.249.161.188"; classtype:trojan-activity; sid:100002449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.111.158"; classtype:trojan-activity; sid:100002450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.4.24"; classtype:trojan-activity; sid:100002451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.125.182"; classtype:trojan-activity; sid:100002452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.58.69.44"; classtype:trojan-activity; sid:100002453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.83.152.16"; classtype:trojan-activity; sid:100002454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"20.185.42.197"; classtype:trojan-activity; sid:100002455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"20.dbstrony.pl"; classtype:trojan-activity; sid:100002456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.105.167.98"; classtype:trojan-activity; sid:100002457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.111.189.70"; classtype:trojan-activity; sid:100002458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.194.4.24"; classtype:trojan-activity; sid:100002459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.2.161.171"; classtype:trojan-activity; sid:100002460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.30.132.50"; classtype:trojan-activity; sid:100002461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.142.147.89"; classtype:trojan-activity; sid:100002462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.163.170"; classtype:trojan-activity; sid:100002463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.248.190"; classtype:trojan-activity; sid:100002464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.187.102.73"; classtype:trojan-activity; sid:100002465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.200.254.86"; classtype:trojan-activity; sid:100002466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.203.221.20"; classtype:trojan-activity; sid:100002467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.203.27.37"; classtype:trojan-activity; sid:100002468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.215.84.97"; classtype:trojan-activity; sid:100002469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.218.97.142"; classtype:trojan-activity; sid:100002470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.107.233.41"; classtype:trojan-activity; sid:100002471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.150.176.100"; classtype:trojan-activity; sid:100002472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.164.153.80"; classtype:trojan-activity; sid:100002473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.166.217.54"; classtype:trojan-activity; sid:100002474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.22"; classtype:trojan-activity; sid:100002475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.37"; classtype:trojan-activity; sid:100002476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.52"; classtype:trojan-activity; sid:100002477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.29.95.12"; classtype:trojan-activity; sid:100002478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.4.124.58"; classtype:trojan-activity; sid:100002479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.176.114"; classtype:trojan-activity; sid:100002480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.191.174"; classtype:trojan-activity; sid:100002481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.74.236.9"; classtype:trojan-activity; sid:100002482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.109.201.243"; classtype:trojan-activity; sid:100002483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.130.69.205"; classtype:trojan-activity; sid:100002484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.189.156.107"; classtype:trojan-activity; sid:100002485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.204.232.18"; classtype:trojan-activity; sid:100002486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.229.21.56"; classtype:trojan-activity; sid:100002487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.236.190.28"; classtype:trojan-activity; sid:100002488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.70.166.107"; classtype:trojan-activity; sid:100002489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.77.80.159"; classtype:trojan-activity; sid:100002490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.119.166"; classtype:trojan-activity; sid:100002491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.171.138"; classtype:trojan-activity; sid:100002492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.82.36.34"; classtype:trojan-activity; sid:100002493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.82.49.122"; classtype:trojan-activity; sid:100002494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.93.6.28"; classtype:trojan-activity; sid:100002495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"204.195.116.171"; classtype:trojan-activity; sid:100002496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"205.185.115.74"; classtype:trojan-activity; sid:100002497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.248.137.132"; classtype:trojan-activity; sid:100002498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.47.41.166"; classtype:trojan-activity; sid:100002499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.5.32.6"; classtype:trojan-activity; sid:100002500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.163.58.18"; classtype:trojan-activity; sid:100002501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.39.50"; classtype:trojan-activity; sid:100002502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.190"; classtype:trojan-activity; sid:100002503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.31"; classtype:trojan-activity; sid:100002504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.145.60.38"; classtype:trojan-activity; sid:100002505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.124.149.19"; classtype:trojan-activity; sid:100002506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.152.122"; classtype:trojan-activity; sid:100002507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.153.142"; classtype:trojan-activity; sid:100002508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.234.131"; classtype:trojan-activity; sid:100002509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.234.93"; classtype:trojan-activity; sid:100002510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.237.70"; classtype:trojan-activity; sid:100002511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.245.109"; classtype:trojan-activity; sid:100002512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.68.242.114"; classtype:trojan-activity; sid:100002513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.96.116.236"; classtype:trojan-activity; sid:100002514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.116.220.37"; classtype:trojan-activity; sid:100002515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.172.11.169"; classtype:trojan-activity; sid:100002516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.179.43.109"; classtype:trojan-activity; sid:100002517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.132.204"; classtype:trojan-activity; sid:100002518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.75.220"; classtype:trojan-activity; sid:100002519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.204.215.157"; classtype:trojan-activity; sid:100002520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.66.179"; classtype:trojan-activity; sid:100002521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.93.93"; classtype:trojan-activity; sid:100002522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.216.66.105"; classtype:trojan-activity; sid:100002523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.114.96"; classtype:trojan-activity; sid:100002524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.120.13"; classtype:trojan-activity; sid:100002525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.246.137"; classtype:trojan-activity; sid:100002526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.238.83.238"; classtype:trojan-activity; sid:100002527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.113.49"; classtype:trojan-activity; sid:100002528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.5.96"; classtype:trojan-activity; sid:100002529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.36.174.137"; classtype:trojan-activity; sid:100002530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.47.102.51"; classtype:trojan-activity; sid:100002531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.51.174.149"; classtype:trojan-activity; sid:100002532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.122.86.105"; classtype:trojan-activity; sid:100002533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.143.227.22"; classtype:trojan-activity; sid:100002534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.156.215.178"; classtype:trojan-activity; sid:100002535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.46.197.114"; classtype:trojan-activity; sid:100002536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.56.197.230"; classtype:trojan-activity; sid:100002537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.119.74.202"; classtype:trojan-activity; sid:100002538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.123.206.197"; classtype:trojan-activity; sid:100002539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.135.178.253"; classtype:trojan-activity; sid:100002540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.14.173.117"; classtype:trojan-activity; sid:100002541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.182.113"; classtype:trojan-activity; sid:100002542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.190.193"; classtype:trojan-activity; sid:100002543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.12"; classtype:trojan-activity; sid:100002544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.138"; classtype:trojan-activity; sid:100002545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.7"; classtype:trojan-activity; sid:100002546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.99"; classtype:trojan-activity; sid:100002547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.100"; classtype:trojan-activity; sid:100002548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.135"; classtype:trojan-activity; sid:100002549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.225"; classtype:trojan-activity; sid:100002550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.237"; classtype:trojan-activity; sid:100002551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.51"; classtype:trojan-activity; sid:100002552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.155"; classtype:trojan-activity; sid:100002553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.191"; classtype:trojan-activity; sid:100002554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.80"; classtype:trojan-activity; sid:100002555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.1"; classtype:trojan-activity; sid:100002556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.11"; classtype:trojan-activity; sid:100002557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.26"; classtype:trojan-activity; sid:100002558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.33"; classtype:trojan-activity; sid:100002559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.71"; classtype:trojan-activity; sid:100002560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.132"; classtype:trojan-activity; sid:100002561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.181"; classtype:trojan-activity; sid:100002562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.192"; classtype:trojan-activity; sid:100002563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.197"; classtype:trojan-activity; sid:100002564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.203"; classtype:trojan-activity; sid:100002565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.33"; classtype:trojan-activity; sid:100002566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.85"; classtype:trojan-activity; sid:100002567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.117.122"; classtype:trojan-activity; sid:100002568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.117.151"; classtype:trojan-activity; sid:100002569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.117.97"; classtype:trojan-activity; sid:100002570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.129"; classtype:trojan-activity; sid:100002571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.144"; classtype:trojan-activity; sid:100002572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.236"; classtype:trojan-activity; sid:100002573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.238"; classtype:trojan-activity; sid:100002574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.119.24"; classtype:trojan-activity; sid:100002575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.119.240"; classtype:trojan-activity; sid:100002576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.20"; classtype:trojan-activity; sid:100002577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.243"; classtype:trojan-activity; sid:100002578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.249"; classtype:trojan-activity; sid:100002579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.60"; classtype:trojan-activity; sid:100002580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.7"; classtype:trojan-activity; sid:100002581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.84"; classtype:trojan-activity; sid:100002582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.204"; classtype:trojan-activity; sid:100002583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.217"; classtype:trojan-activity; sid:100002584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.242"; classtype:trojan-activity; sid:100002585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.46"; classtype:trojan-activity; sid:100002586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.189.178.163"; classtype:trojan-activity; sid:100002587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.240.218.15"; classtype:trojan-activity; sid:100002588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.249.156.189"; classtype:trojan-activity; sid:100002589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.27.8.6"; classtype:trojan-activity; sid:100002590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.80.44.17"; classtype:trojan-activity; sid:100002591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.87.87.173"; classtype:trojan-activity; sid:100002592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.254.52"; classtype:trojan-activity; sid:100002593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.36"; classtype:trojan-activity; sid:100002594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.84"; classtype:trojan-activity; sid:100002595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.127.185.150"; classtype:trojan-activity; sid:100002596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.170.240.98"; classtype:trojan-activity; sid:100002597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.183.54.169"; classtype:trojan-activity; sid:100002598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.36.12.98"; classtype:trojan-activity; sid:100002599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.11.75.162"; classtype:trojan-activity; sid:100002600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.127.133.214"; classtype:trojan-activity; sid:100002601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.8.228.92"; classtype:trojan-activity; sid:100002602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.12.162.39"; classtype:trojan-activity; sid:100002603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.12.181.110"; classtype:trojan-activity; sid:100002604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.2.40.34"; classtype:trojan-activity; sid:100002605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.215.243.65"; classtype:trojan-activity; sid:100002606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.238.246.3"; classtype:trojan-activity; sid:100002607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.28.160.174"; classtype:trojan-activity; sid:100002608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.207.119"; classtype:trojan-activity; sid:100002609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.227.133"; classtype:trojan-activity; sid:100002610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.68.35"; classtype:trojan-activity; sid:100002611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.81.81"; classtype:trojan-activity; sid:100002612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.48.135.50"; classtype:trojan-activity; sid:100002613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.56.93.129"; classtype:trojan-activity; sid:100002614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.57.109.48"; classtype:trojan-activity; sid:100002615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.57.53.55"; classtype:trojan-activity; sid:100002616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.59.116.203"; classtype:trojan-activity; sid:100002617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.72.198.15"; classtype:trojan-activity; sid:100002618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.79.103.159"; classtype:trojan-activity; sid:100002619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.63"; classtype:trojan-activity; sid:100002620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.75"; classtype:trojan-activity; sid:100002621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.103.40"; classtype:trojan-activity; sid:100002622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.114.45"; classtype:trojan-activity; sid:100002623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.115.250"; classtype:trojan-activity; sid:100002624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.116.168"; classtype:trojan-activity; sid:100002625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.126.205"; classtype:trojan-activity; sid:100002626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.142.35"; classtype:trojan-activity; sid:100002627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.143.132"; classtype:trojan-activity; sid:100002628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.147.58"; classtype:trojan-activity; sid:100002629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.148.116"; classtype:trojan-activity; sid:100002630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.173.163"; classtype:trojan-activity; sid:100002631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.178.138"; classtype:trojan-activity; sid:100002632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.41.36"; classtype:trojan-activity; sid:100002633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.102.14"; classtype:trojan-activity; sid:100002634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.11.252"; classtype:trojan-activity; sid:100002635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.113.58"; classtype:trojan-activity; sid:100002636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.14.17"; classtype:trojan-activity; sid:100002637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.209.253"; classtype:trojan-activity; sid:100002638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.24.246"; classtype:trojan-activity; sid:100002639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.243.184"; classtype:trojan-activity; sid:100002640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.26.204"; classtype:trojan-activity; sid:100002641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.29.165"; classtype:trojan-activity; sid:100002642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.31.15"; classtype:trojan-activity; sid:100002643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.31.67"; classtype:trojan-activity; sid:100002644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.86.156"; classtype:trojan-activity; sid:100002645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.98.64"; classtype:trojan-activity; sid:100002646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.131.116"; classtype:trojan-activity; sid:100002647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.17.217"; classtype:trojan-activity; sid:100002648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.176.153"; classtype:trojan-activity; sid:100002649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.23.29"; classtype:trojan-activity; sid:100002650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.60.224"; classtype:trojan-activity; sid:100002651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.65.47"; classtype:trojan-activity; sid:100002652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.88.219"; classtype:trojan-activity; sid:100002653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.11.39"; classtype:trojan-activity; sid:100002654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.146.200"; classtype:trojan-activity; sid:100002655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.147.87"; classtype:trojan-activity; sid:100002656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.150.91"; classtype:trojan-activity; sid:100002657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.178.201"; classtype:trojan-activity; sid:100002658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.178.210"; classtype:trojan-activity; sid:100002659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.183.29"; classtype:trojan-activity; sid:100002660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.214.235"; classtype:trojan-activity; sid:100002661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.223.241"; classtype:trojan-activity; sid:100002662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.42.228"; classtype:trojan-activity; sid:100002663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.67.171"; classtype:trojan-activity; sid:100002664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.241.6.180"; classtype:trojan-activity; sid:100002665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.148"; classtype:trojan-activity; sid:100002666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.84"; classtype:trojan-activity; sid:100002667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.163.7"; classtype:trojan-activity; sid:100002668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.171.144"; classtype:trojan-activity; sid:100002669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.245.63"; classtype:trojan-activity; sid:100002670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.251.32"; classtype:trojan-activity; sid:100002671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.5.140"; classtype:trojan-activity; sid:100002672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.69.71.186"; classtype:trojan-activity; sid:100002673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.80.217.209"; classtype:trojan-activity; sid:100002674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.85.145.194"; classtype:trojan-activity; sid:100002675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"21robo.com"; classtype:trojan-activity; sid:100002676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.118.168.155"; classtype:trojan-activity; sid:100002677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.126.237.74"; classtype:trojan-activity; sid:100002678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.133.30.200"; classtype:trojan-activity; sid:100002679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.200.22.163"; classtype:trojan-activity; sid:100002680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.71.239.115"; classtype:trojan-activity; sid:100002681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.90.159.188"; classtype:trojan-activity; sid:100002682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.1.162.82"; classtype:trojan-activity; sid:100002683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.124.78.15"; classtype:trojan-activity; sid:100002684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.122.127"; classtype:trojan-activity; sid:100002685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.165.237"; classtype:trojan-activity; sid:100002686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.185.105"; classtype:trojan-activity; sid:100002687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.47.162"; classtype:trojan-activity; sid:100002688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.47.189"; classtype:trojan-activity; sid:100002689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.57.175"; classtype:trojan-activity; sid:100002690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.108.55"; classtype:trojan-activity; sid:100002691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.112.103"; classtype:trojan-activity; sid:100002692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.125.190"; classtype:trojan-activity; sid:100002693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.155.186"; classtype:trojan-activity; sid:100002694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.190.2"; classtype:trojan-activity; sid:100002695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.234.159"; classtype:trojan-activity; sid:100002696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.237.107"; classtype:trojan-activity; sid:100002697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.250.213"; classtype:trojan-activity; sid:100002698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.253.236"; classtype:trojan-activity; sid:100002699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.54.237"; classtype:trojan-activity; sid:100002700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.55.56"; classtype:trojan-activity; sid:100002701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.157.191.178"; classtype:trojan-activity; sid:100002702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.136.213"; classtype:trojan-activity; sid:100002703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.104"; classtype:trojan-activity; sid:100002704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.107"; classtype:trojan-activity; sid:100002705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.224"; classtype:trojan-activity; sid:100002706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.196.12.96"; classtype:trojan-activity; sid:100002707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.198.167.192"; classtype:trojan-activity; sid:100002708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.2.190.22"; classtype:trojan-activity; sid:100002709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.202.232.230"; classtype:trojan-activity; sid:100002710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.130.147"; classtype:trojan-activity; sid:100002711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.224.184"; classtype:trojan-activity; sid:100002712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.251.109"; classtype:trojan-activity; sid:100002713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.116.167"; classtype:trojan-activity; sid:100002714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.172.207"; classtype:trojan-activity; sid:100002715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.184.31"; classtype:trojan-activity; sid:100002716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.237.220"; classtype:trojan-activity; sid:100002717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.252.64"; classtype:trojan-activity; sid:100002718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.8.64"; classtype:trojan-activity; sid:100002719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.1.82"; classtype:trojan-activity; sid:100002720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.179.70"; classtype:trojan-activity; sid:100002721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.137.36"; classtype:trojan-activity; sid:100002722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.142.206"; classtype:trojan-activity; sid:100002723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.112.125"; classtype:trojan-activity; sid:100002724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.32.88"; classtype:trojan-activity; sid:100002725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.34.43"; classtype:trojan-activity; sid:100002726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.43.223"; classtype:trojan-activity; sid:100002727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.68.16"; classtype:trojan-activity; sid:100002728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.108.17.64"; classtype:trojan-activity; sid:100002729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.119.65.145"; classtype:trojan-activity; sid:100002730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.132.125.138"; classtype:trojan-activity; sid:100002731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.102.202"; classtype:trojan-activity; sid:100002732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.103.120"; classtype:trojan-activity; sid:100002733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.105.87"; classtype:trojan-activity; sid:100002734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.219.29"; classtype:trojan-activity; sid:100002735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.26.161"; classtype:trojan-activity; sid:100002736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.67.115"; classtype:trojan-activity; sid:100002737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.136.53.227"; classtype:trojan-activity; sid:100002738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.136.77.190"; classtype:trojan-activity; sid:100002739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.101.251"; classtype:trojan-activity; sid:100002740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.101.33"; classtype:trojan-activity; sid:100002741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.121.127"; classtype:trojan-activity; sid:100002742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.137.5"; classtype:trojan-activity; sid:100002743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.138.252"; classtype:trojan-activity; sid:100002744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.148.192"; classtype:trojan-activity; sid:100002745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.161.88"; classtype:trojan-activity; sid:100002746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.172.250"; classtype:trojan-activity; sid:100002747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.198.247"; classtype:trojan-activity; sid:100002748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.220.215"; classtype:trojan-activity; sid:100002749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.237.203"; classtype:trojan-activity; sid:100002750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.239.124"; classtype:trojan-activity; sid:100002751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.49.36"; classtype:trojan-activity; sid:100002752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.53.193"; classtype:trojan-activity; sid:100002753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.72.146"; classtype:trojan-activity; sid:100002754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.96.9"; classtype:trojan-activity; sid:100002755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.118.192"; classtype:trojan-activity; sid:100002756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.143.84"; classtype:trojan-activity; sid:100002757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.151.100"; classtype:trojan-activity; sid:100002758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.189.138"; classtype:trojan-activity; sid:100002759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.201.241"; classtype:trojan-activity; sid:100002760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.213.235"; classtype:trojan-activity; sid:100002761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.226.142"; classtype:trojan-activity; sid:100002762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.96.79"; classtype:trojan-activity; sid:100002763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.139.106.55"; classtype:trojan-activity; sid:100002764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.162.140"; classtype:trojan-activity; sid:100002765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.163.112"; classtype:trojan-activity; sid:100002766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.17.245"; classtype:trojan-activity; sid:100002767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.179.142"; classtype:trojan-activity; sid:100002768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.208.18"; classtype:trojan-activity; sid:100002769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.209.222"; classtype:trojan-activity; sid:100002770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.39.66"; classtype:trojan-activity; sid:100002771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.101.39"; classtype:trojan-activity; sid:100002772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.120.26"; classtype:trojan-activity; sid:100002773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.13.77"; classtype:trojan-activity; sid:100002774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.40.69"; classtype:trojan-activity; sid:100002775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.46.119"; classtype:trojan-activity; sid:100002776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.9.0"; classtype:trojan-activity; sid:100002777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.192.66"; classtype:trojan-activity; sid:100002778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.209.231"; classtype:trojan-activity; sid:100002779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.179.215.189"; classtype:trojan-activity; sid:100002780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.185.116.233"; classtype:trojan-activity; sid:100002781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.187.9.178"; classtype:trojan-activity; sid:100002782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.211.72.66"; classtype:trojan-activity; sid:100002783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.214.54.208"; classtype:trojan-activity; sid:100002784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.218.220.219"; classtype:trojan-activity; sid:100002785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.236.85.220"; classtype:trojan-activity; sid:100002786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.238.230.7"; classtype:trojan-activity; sid:100002787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.239.83.232"; classtype:trojan-activity; sid:100002788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.248.64.253"; classtype:trojan-activity; sid:100002789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.81.156.229"; classtype:trojan-activity; sid:100002790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.92.9.126"; classtype:trojan-activity; sid:100002791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.99.171.192"; classtype:trojan-activity; sid:100002792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.166.117.210"; classtype:trojan-activity; sid:100002793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.167.118.17"; classtype:trojan-activity; sid:100002794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.225.68"; classtype:trojan-activity; sid:100002795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.234.84"; classtype:trojan-activity; sid:100002796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.5.29"; classtype:trojan-activity; sid:100002797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.73.175"; classtype:trojan-activity; sid:100002798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.125.186.135"; classtype:trojan-activity; sid:100002799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.126.120.25"; classtype:trojan-activity; sid:100002800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.228.143.58"; classtype:trojan-activity; sid:100002801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.24.213.121"; classtype:trojan-activity; sid:100002802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.149.13"; classtype:trojan-activity; sid:100002803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.21.167"; classtype:trojan-activity; sid:100002804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.95.89.21"; classtype:trojan-activity; sid:100002805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.103.74.180"; classtype:trojan-activity; sid:100002806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.11.141.134"; classtype:trojan-activity; sid:100002807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.119.158.74"; classtype:trojan-activity; sid:100002808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.137.147.95"; classtype:trojan-activity; sid:100002809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.152.235.88"; classtype:trojan-activity; sid:100002810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.158.25.98"; classtype:trojan-activity; sid:100002811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.176.206.12"; classtype:trojan-activity; sid:100002812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.184.1.41"; classtype:trojan-activity; sid:100002813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.192.191.109"; classtype:trojan-activity; sid:100002814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.225.114.161"; classtype:trojan-activity; sid:100002815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.227.190.78"; classtype:trojan-activity; sid:100002816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.35.245.52"; classtype:trojan-activity; sid:100002817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.181.18"; classtype:trojan-activity; sid:100002818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.34.242"; classtype:trojan-activity; sid:100002819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.42.229.143"; classtype:trojan-activity; sid:100002820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.45.4.1"; classtype:trojan-activity; sid:100002821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.51.91.113"; classtype:trojan-activity; sid:100002822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.10"; classtype:trojan-activity; sid:100002823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.9"; classtype:trojan-activity; sid:100002824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.dbstrony.pl"; classtype:trojan-activity; sid:100002825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.16"; classtype:trojan-activity; sid:100002826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.7"; classtype:trojan-activity; sid:100002827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.106.201"; classtype:trojan-activity; sid:100002828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.152.107"; classtype:trojan-activity; sid:100002829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.116.84.57"; classtype:trojan-activity; sid:100002830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.12.245.238"; classtype:trojan-activity; sid:100002831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.141.218.17"; classtype:trojan-activity; sid:100002832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.29.52"; classtype:trojan-activity; sid:100002833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.40.128"; classtype:trojan-activity; sid:100002834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.153.142.115"; classtype:trojan-activity; sid:100002835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.184.244.14"; classtype:trojan-activity; sid:100002836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.184.54.199"; classtype:trojan-activity; sid:100002837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.187.248.22"; classtype:trojan-activity; sid:100002838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.187.250.192"; classtype:trojan-activity; sid:100002839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.196.190"; classtype:trojan-activity; sid:100002840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.217.210"; classtype:trojan-activity; sid:100002841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.149.142"; classtype:trojan-activity; sid:100002842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.192.66"; classtype:trojan-activity; sid:100002843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.210.20"; classtype:trojan-activity; sid:100002844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.17.88"; classtype:trojan-activity; sid:100002845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.22.217"; classtype:trojan-activity; sid:100002846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.23.215"; classtype:trojan-activity; sid:100002847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.24.175"; classtype:trojan-activity; sid:100002848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.28.84"; classtype:trojan-activity; sid:100002849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.148.189"; classtype:trojan-activity; sid:100002850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.232.65"; classtype:trojan-activity; sid:100002851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.3.194"; classtype:trojan-activity; sid:100002852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.34.48"; classtype:trojan-activity; sid:100002853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.110.211"; classtype:trojan-activity; sid:100002854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.140.229"; classtype:trojan-activity; sid:100002855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.2.163"; classtype:trojan-activity; sid:100002856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.23.62"; classtype:trojan-activity; sid:100002857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.32.146"; classtype:trojan-activity; sid:100002858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.201.183.149"; classtype:trojan-activity; sid:100002859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.182.201"; classtype:trojan-activity; sid:100002860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.66.46"; classtype:trojan-activity; sid:100002861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.102.12"; classtype:trojan-activity; sid:100002862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.126.194"; classtype:trojan-activity; sid:100002863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.154.105"; classtype:trojan-activity; sid:100002864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.165.138"; classtype:trojan-activity; sid:100002865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.175.203"; classtype:trojan-activity; sid:100002866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.185.42"; classtype:trojan-activity; sid:100002867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.213.79"; classtype:trojan-activity; sid:100002868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.246.96"; classtype:trojan-activity; sid:100002869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.255.42"; classtype:trojan-activity; sid:100002870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.28.115"; classtype:trojan-activity; sid:100002871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.4.188"; classtype:trojan-activity; sid:100002872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.68.144"; classtype:trojan-activity; sid:100002873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.87.75"; classtype:trojan-activity; sid:100002874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.94.134"; classtype:trojan-activity; sid:100002875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.204.253.74"; classtype:trojan-activity; sid:100002876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.205.178.110"; classtype:trojan-activity; sid:100002877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.136.101"; classtype:trojan-activity; sid:100002878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.148.106"; classtype:trojan-activity; sid:100002879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.154.122"; classtype:trojan-activity; sid:100002880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.26.218"; classtype:trojan-activity; sid:100002881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.80.209"; classtype:trojan-activity; sid:100002882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.81.66"; classtype:trojan-activity; sid:100002883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.83.48"; classtype:trojan-activity; sid:100002884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.97.81"; classtype:trojan-activity; sid:100002885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.151.126"; classtype:trojan-activity; sid:100002886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.155.31"; classtype:trojan-activity; sid:100002887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.170.203"; classtype:trojan-activity; sid:100002888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.54.91"; classtype:trojan-activity; sid:100002889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.144.57"; classtype:trojan-activity; sid:100002890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.152.10"; classtype:trojan-activity; sid:100002891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.160.177"; classtype:trojan-activity; sid:100002892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.164.18"; classtype:trojan-activity; sid:100002893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.166.13"; classtype:trojan-activity; sid:100002894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.201.212"; classtype:trojan-activity; sid:100002895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.247.130"; classtype:trojan-activity; sid:100002896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.25.59"; classtype:trojan-activity; sid:100002897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.34.2"; classtype:trojan-activity; sid:100002898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.70.115"; classtype:trojan-activity; sid:100002899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.92.64"; classtype:trojan-activity; sid:100002900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.160.222"; classtype:trojan-activity; sid:100002901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.231.15"; classtype:trojan-activity; sid:100002902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.60.21"; classtype:trojan-activity; sid:100002903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.107.125"; classtype:trojan-activity; sid:100002904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.127.11"; classtype:trojan-activity; sid:100002905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.172.245"; classtype:trojan-activity; sid:100002906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.234.28"; classtype:trojan-activity; sid:100002907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.236.134"; classtype:trojan-activity; sid:100002908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.63.243"; classtype:trojan-activity; sid:100002909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.211.251.162"; classtype:trojan-activity; sid:100002910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.104.201"; classtype:trojan-activity; sid:100002911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.109.105"; classtype:trojan-activity; sid:100002912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.109.58"; classtype:trojan-activity; sid:100002913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.145.221"; classtype:trojan-activity; sid:100002914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.166.50"; classtype:trojan-activity; sid:100002915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.167.175"; classtype:trojan-activity; sid:100002916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.175.208"; classtype:trojan-activity; sid:100002917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.220.5"; classtype:trojan-activity; sid:100002918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.255.202"; classtype:trojan-activity; sid:100002919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.255.6"; classtype:trojan-activity; sid:100002920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.84.74"; classtype:trojan-activity; sid:100002921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.214.37.129"; classtype:trojan-activity; sid:100002922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.139.242"; classtype:trojan-activity; sid:100002923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.190.172"; classtype:trojan-activity; sid:100002924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.212.209"; classtype:trojan-activity; sid:100002925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.212.80"; classtype:trojan-activity; sid:100002926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.253.149"; classtype:trojan-activity; sid:100002927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.27.143"; classtype:trojan-activity; sid:100002928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.34.242"; classtype:trojan-activity; sid:100002929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.38.119"; classtype:trojan-activity; sid:100002930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.38.166"; classtype:trojan-activity; sid:100002931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.71.243"; classtype:trojan-activity; sid:100002932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.98.242"; classtype:trojan-activity; sid:100002933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.131.66"; classtype:trojan-activity; sid:100002934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.144.66"; classtype:trojan-activity; sid:100002935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.193.217"; classtype:trojan-activity; sid:100002936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.197.193"; classtype:trojan-activity; sid:100002937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.223.246"; classtype:trojan-activity; sid:100002938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.225.28"; classtype:trojan-activity; sid:100002939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.227.95"; classtype:trojan-activity; sid:100002940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.234.98"; classtype:trojan-activity; sid:100002941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.46.85"; classtype:trojan-activity; sid:100002942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.95.56"; classtype:trojan-activity; sid:100002943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.120.226"; classtype:trojan-activity; sid:100002944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.133.53"; classtype:trojan-activity; sid:100002945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.191.58"; classtype:trojan-activity; sid:100002946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.76.48"; classtype:trojan-activity; sid:100002947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.180.172"; classtype:trojan-activity; sid:100002948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.219.228"; classtype:trojan-activity; sid:100002949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.240.158"; classtype:trojan-activity; sid:100002950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.248.121"; classtype:trojan-activity; sid:100002951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.119.149"; classtype:trojan-activity; sid:100002952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.132.71"; classtype:trojan-activity; sid:100002953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.151.83"; classtype:trojan-activity; sid:100002954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.160.112"; classtype:trojan-activity; sid:100002955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.172.175"; classtype:trojan-activity; sid:100002956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.173.180"; classtype:trojan-activity; sid:100002957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.176.72"; classtype:trojan-activity; sid:100002958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.184.94"; classtype:trojan-activity; sid:100002959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.192.223"; classtype:trojan-activity; sid:100002960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.83.244"; classtype:trojan-activity; sid:100002961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.40.189"; classtype:trojan-activity; sid:100002962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.80.93"; classtype:trojan-activity; sid:100002963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.85.168"; classtype:trojan-activity; sid:100002964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.221.239.223"; classtype:trojan-activity; sid:100002965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.241.223"; classtype:trojan-activity; sid:100002966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.249.210"; classtype:trojan-activity; sid:100002967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.42.189"; classtype:trojan-activity; sid:100002968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.50.170"; classtype:trojan-activity; sid:100002969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.223.242.164"; classtype:trojan-activity; sid:100002970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.24.28.134"; classtype:trojan-activity; sid:100002971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.107.66"; classtype:trojan-activity; sid:100002972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.129.198"; classtype:trojan-activity; sid:100002973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.154.13"; classtype:trojan-activity; sid:100002974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.212.124"; classtype:trojan-activity; sid:100002975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.58.5"; classtype:trojan-activity; sid:100002976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.159.28"; classtype:trojan-activity; sid:100002977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.37.155"; classtype:trojan-activity; sid:100002978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.9.105"; classtype:trojan-activity; sid:100002979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.9.44"; classtype:trojan-activity; sid:100002980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.97.36"; classtype:trojan-activity; sid:100002981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.43.108.78"; classtype:trojan-activity; sid:100002982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.43.111.161"; classtype:trojan-activity; sid:100002983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.43.117.66"; classtype:trojan-activity; sid:100002984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.23.10"; classtype:trojan-activity; sid:100002985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.44.130"; classtype:trojan-activity; sid:100002986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.44.153"; classtype:trojan-activity; sid:100002987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.45.86"; classtype:trojan-activity; sid:100002988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.46.100"; classtype:trojan-activity; sid:100002989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.46.252"; classtype:trojan-activity; sid:100002990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.23.69"; classtype:trojan-activity; sid:100002991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.47.16"; classtype:trojan-activity; sid:100002992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.6.240.171"; classtype:trojan-activity; sid:100002993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.6.38.96"; classtype:trojan-activity; sid:100002994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.0.98.131"; classtype:trojan-activity; sid:100002995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.11.51.57"; classtype:trojan-activity; sid:100002996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.13.23.180"; classtype:trojan-activity; sid:100002997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.154.234.3"; classtype:trojan-activity; sid:100002998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.163.191.11"; classtype:trojan-activity; sid:100002999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.124.130"; classtype:trojan-activity; sid:100003000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.179.83"; classtype:trojan-activity; sid:100003001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.184.59"; classtype:trojan-activity; sid:100003002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.191.243"; classtype:trojan-activity; sid:100003003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.194.67"; classtype:trojan-activity; sid:100003004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.216.132"; classtype:trojan-activity; sid:100003005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.219.28"; classtype:trojan-activity; sid:100003006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.24.115"; classtype:trojan-activity; sid:100003007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.30.65"; classtype:trojan-activity; sid:100003008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.60.234"; classtype:trojan-activity; sid:100003009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.63.203"; classtype:trojan-activity; sid:100003010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.65.233"; classtype:trojan-activity; sid:100003011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.94.16"; classtype:trojan-activity; sid:100003012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.179.201.26"; classtype:trojan-activity; sid:100003013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.195.84.250"; classtype:trojan-activity; sid:100003014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.177"; classtype:trojan-activity; sid:100003015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.69"; classtype:trojan-activity; sid:100003016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.28.7.159"; classtype:trojan-activity; sid:100003017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.30.119.23"; classtype:trojan-activity; sid:100003018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32.208.157.193"; classtype:trojan-activity; sid:100003019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32.218.180.9"; classtype:trojan-activity; sid:100003020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32792.prolocksmithwinterpark.com"; classtype:trojan-activity; sid:100003021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"35.184.169.169"; classtype:trojan-activity; sid:100003022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.108.231.218"; classtype:trojan-activity; sid:100003023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.250.203.246"; classtype:trojan-activity; sid:100003024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.157.225"; classtype:trojan-activity; sid:100003025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.18.18"; classtype:trojan-activity; sid:100003026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.18.63"; classtype:trojan-activity; sid:100003027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.19.88"; classtype:trojan-activity; sid:100003028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.51.244"; classtype:trojan-activity; sid:100003029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.255.90.219"; classtype:trojan-activity; sid:100003030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.128.60"; classtype:trojan-activity; sid:100003031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.160.167"; classtype:trojan-activity; sid:100003032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.34.150.236"; classtype:trojan-activity; sid:100003033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.36.243.67"; classtype:trojan-activity; sid:100003034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.43.11.16"; classtype:trojan-activity; sid:100003035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.105.159"; classtype:trojan-activity; sid:100003036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.111.203"; classtype:trojan-activity; sid:100003037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.133.125"; classtype:trojan-activity; sid:100003038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.139.36"; classtype:trojan-activity; sid:100003039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.67.152.161"; classtype:trojan-activity; sid:100003040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.81.23.38"; classtype:trojan-activity; sid:100003041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.89.18.133"; classtype:trojan-activity; sid:100003042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.96.187.93"; classtype:trojan-activity; sid:100003043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360.lcy2zzx.pw"; classtype:trojan-activity; sid:100003044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360down7.miiyun.cn"; classtype:trojan-activity; sid:100003045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.222.98.51"; classtype:trojan-activity; sid:100003046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.233.60.68"; classtype:trojan-activity; sid:100003047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.179.221"; classtype:trojan-activity; sid:100003048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.180.172"; classtype:trojan-activity; sid:100003049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.44.238.35"; classtype:trojan-activity; sid:100003050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.49.229.154"; classtype:trojan-activity; sid:100003051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.49.230.152"; classtype:trojan-activity; sid:100003052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.52.117.132"; classtype:trojan-activity; sid:100003053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.14.36"; classtype:trojan-activity; sid:100003054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"38.77.14.237"; classtype:trojan-activity; sid:100003055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.245.254"; classtype:trojan-activity; sid:100003056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.98.136"; classtype:trojan-activity; sid:100003057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.114.137.102"; classtype:trojan-activity; sid:100003058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.117.31.162"; classtype:trojan-activity; sid:100003059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.162.104.119"; classtype:trojan-activity; sid:100003060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.64.28.214"; classtype:trojan-activity; sid:100003061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.196.34"; classtype:trojan-activity; sid:100003062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.59.160"; classtype:trojan-activity; sid:100003063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.115.94"; classtype:trojan-activity; sid:100003064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.129.163"; classtype:trojan-activity; sid:100003065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.44.109"; classtype:trojan-activity; sid:100003066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.104.83"; classtype:trojan-activity; sid:100003067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.125.186"; classtype:trojan-activity; sid:100003068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.146.60"; classtype:trojan-activity; sid:100003069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.148.163"; classtype:trojan-activity; sid:100003070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.124.76"; classtype:trojan-activity; sid:100003071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.171.125"; classtype:trojan-activity; sid:100003072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.249.255"; classtype:trojan-activity; sid:100003073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.60.61"; classtype:trojan-activity; sid:100003074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.167.202"; classtype:trojan-activity; sid:100003075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.5.175"; classtype:trojan-activity; sid:100003076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.67.64"; classtype:trojan-activity; sid:100003077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.10.198"; classtype:trojan-activity; sid:100003078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.163.231"; classtype:trojan-activity; sid:100003079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.203.225"; classtype:trojan-activity; sid:100003080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.104.228"; classtype:trojan-activity; sid:100003081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.184.222"; classtype:trojan-activity; sid:100003082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.31.192"; classtype:trojan-activity; sid:100003083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.68.182"; classtype:trojan-activity; sid:100003084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.194.65"; classtype:trojan-activity; sid:100003085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.33.191"; classtype:trojan-activity; sid:100003086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.79.43"; classtype:trojan-activity; sid:100003087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.97.16"; classtype:trojan-activity; sid:100003088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.113.201"; classtype:trojan-activity; sid:100003089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.114.45"; classtype:trojan-activity; sid:100003090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.136.47"; classtype:trojan-activity; sid:100003091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.14.27"; classtype:trojan-activity; sid:100003092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.150.203"; classtype:trojan-activity; sid:100003093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.197.81"; classtype:trojan-activity; sid:100003094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.209.209"; classtype:trojan-activity; sid:100003095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.48.213"; classtype:trojan-activity; sid:100003096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.94.189"; classtype:trojan-activity; sid:100003097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.95.50"; classtype:trojan-activity; sid:100003098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.146.67"; classtype:trojan-activity; sid:100003099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.163.188"; classtype:trojan-activity; sid:100003100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.166.31"; classtype:trojan-activity; sid:100003101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.218.46"; classtype:trojan-activity; sid:100003102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.62.43"; classtype:trojan-activity; sid:100003103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.91.244"; classtype:trojan-activity; sid:100003104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.93.171"; classtype:trojan-activity; sid:100003105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.127.214"; classtype:trojan-activity; sid:100003106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.18.140"; classtype:trojan-activity; sid:100003107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.191.137"; classtype:trojan-activity; sid:100003108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.205.255"; classtype:trojan-activity; sid:100003109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.24.54"; classtype:trojan-activity; sid:100003110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.36.151"; classtype:trojan-activity; sid:100003111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.37.182"; classtype:trojan-activity; sid:100003112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.251.0"; classtype:trojan-activity; sid:100003113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.27.15"; classtype:trojan-activity; sid:100003114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.29.231"; classtype:trojan-activity; sid:100003115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.82.86.105"; classtype:trojan-activity; sid:100003116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.83.94.11"; classtype:trojan-activity; sid:100003117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.115.152"; classtype:trojan-activity; sid:100003118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.157.52"; classtype:trojan-activity; sid:100003119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.34.217"; classtype:trojan-activity; sid:100003120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.95.200"; classtype:trojan-activity; sid:100003121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.191"; classtype:trojan-activity; sid:100003122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.4"; classtype:trojan-activity; sid:100003123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.129.233"; classtype:trojan-activity; sid:100003124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.13.0"; classtype:trojan-activity; sid:100003125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.170.209"; classtype:trojan-activity; sid:100003126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.184.164"; classtype:trojan-activity; sid:100003127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.211.20"; classtype:trojan-activity; sid:100003128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.216.144"; classtype:trojan-activity; sid:100003129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.234.187"; classtype:trojan-activity; sid:100003130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.248.91"; classtype:trojan-activity; sid:100003131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.66.24"; classtype:trojan-activity; sid:100003132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.73.100"; classtype:trojan-activity; sid:100003133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.63.58"; classtype:trojan-activity; sid:100003134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.90.210"; classtype:trojan-activity; sid:100003135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.93.109"; classtype:trojan-activity; sid:100003136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.141.172"; classtype:trojan-activity; sid:100003137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.155.96"; classtype:trojan-activity; sid:100003138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.233.131"; classtype:trojan-activity; sid:100003139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.67.238"; classtype:trojan-activity; sid:100003140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.72.9"; classtype:trojan-activity; sid:100003141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.198"; classtype:trojan-activity; sid:100003142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.36"; classtype:trojan-activity; sid:100003143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.157.140"; classtype:trojan-activity; sid:100003144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.63.23"; classtype:trojan-activity; sid:100003145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.90.86.212"; classtype:trojan-activity; sid:100003146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"40.88.2.151"; classtype:trojan-activity; sid:100003147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.139.209.46"; classtype:trojan-activity; sid:100003148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.165.130.43"; classtype:trojan-activity; sid:100003149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.193.192.100"; classtype:trojan-activity; sid:100003150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.219.185.171"; classtype:trojan-activity; sid:100003151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.230.31.58"; classtype:trojan-activity; sid:100003152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.72.203.82"; classtype:trojan-activity; sid:100003153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.133"; classtype:trojan-activity; sid:100003154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.148"; classtype:trojan-activity; sid:100003155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.157"; classtype:trojan-activity; sid:100003156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.164"; classtype:trojan-activity; sid:100003157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.165"; classtype:trojan-activity; sid:100003158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.71"; classtype:trojan-activity; sid:100003159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.19.206"; classtype:trojan-activity; sid:100003160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.19.80"; classtype:trojan-activity; sid:100003161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.38"; classtype:trojan-activity; sid:100003162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.44"; classtype:trojan-activity; sid:100003163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.62"; classtype:trojan-activity; sid:100003164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.142"; classtype:trojan-activity; sid:100003165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.198"; classtype:trojan-activity; sid:100003166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.206"; classtype:trojan-activity; sid:100003167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.176.112.72"; classtype:trojan-activity; sid:100003168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.177.164.171"; classtype:trojan-activity; sid:100003169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.179.162.208"; classtype:trojan-activity; sid:100003170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.179.163.177"; classtype:trojan-activity; sid:100003171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.202.101.147"; classtype:trojan-activity; sid:100003172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.122.183"; classtype:trojan-activity; sid:100003173; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.122.39"; classtype:trojan-activity; sid:100003174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.169.111"; classtype:trojan-activity; sid:100003175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.171.104"; classtype:trojan-activity; sid:100003176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.172.125"; classtype:trojan-activity; sid:100003177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.18.165"; classtype:trojan-activity; sid:100003178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.171.104"; classtype:trojan-activity; sid:100003175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.172.125"; classtype:trojan-activity; sid:100003176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.188.223"; classtype:trojan-activity; sid:100003177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.189.79"; classtype:trojan-activity; sid:100003178; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.19.55"; classtype:trojan-activity; sid:100003179; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.220.37"; classtype:trojan-activity; sid:100003180; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.233.247"; classtype:trojan-activity; sid:100003181; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.234.23"; classtype:trojan-activity; sid:100003182; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.245.91"; classtype:trojan-activity; sid:100003183; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.249.160"; classtype:trojan-activity; sid:100003184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.36.220"; classtype:trojan-activity; sid:100003185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.56.81"; classtype:trojan-activity; sid:100003186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.69.11"; classtype:trojan-activity; sid:100003187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.70.213"; classtype:trojan-activity; sid:100003188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.120.122"; classtype:trojan-activity; sid:100003189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.205.191"; classtype:trojan-activity; sid:100003190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.241.5"; classtype:trojan-activity; sid:100003191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.226.89.25"; classtype:trojan-activity; sid:100003192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.194.95"; classtype:trojan-activity; sid:100003193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.196.123"; classtype:trojan-activity; sid:100003194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.66.88"; classtype:trojan-activity; sid:100003195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.39.232"; classtype:trojan-activity; sid:100003196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.40.56"; classtype:trojan-activity; sid:100003197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.60.114"; classtype:trojan-activity; sid:100003198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.67.135"; classtype:trojan-activity; sid:100003199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.68.118"; classtype:trojan-activity; sid:100003200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.70.126"; classtype:trojan-activity; sid:100003201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.70.231"; classtype:trojan-activity; sid:100003202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.84.206"; classtype:trojan-activity; sid:100003203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.153.183"; classtype:trojan-activity; sid:100003204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.219.175"; classtype:trojan-activity; sid:100003205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.249.188"; classtype:trojan-activity; sid:100003185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.3.187"; classtype:trojan-activity; sid:100003186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.36.220"; classtype:trojan-activity; sid:100003187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.52.81"; classtype:trojan-activity; sid:100003188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.68.72"; classtype:trojan-activity; sid:100003189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.69.11"; classtype:trojan-activity; sid:100003190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.70.213"; classtype:trojan-activity; sid:100003191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.120.122"; classtype:trojan-activity; sid:100003192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.205.191"; classtype:trojan-activity; sid:100003193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.241.5"; classtype:trojan-activity; sid:100003194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.194.95"; classtype:trojan-activity; sid:100003195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.196.123"; classtype:trojan-activity; sid:100003196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.66.88"; classtype:trojan-activity; sid:100003197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.196.68"; classtype:trojan-activity; sid:100003198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.40.56"; classtype:trojan-activity; sid:100003199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.60.114"; classtype:trojan-activity; sid:100003200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.67.135"; classtype:trojan-activity; sid:100003201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.68.118"; classtype:trojan-activity; sid:100003202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.70.126"; classtype:trojan-activity; sid:100003203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.70.231"; classtype:trojan-activity; sid:100003204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.218.252"; classtype:trojan-activity; sid:100003205; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.25.164"; classtype:trojan-activity; sid:100003206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.48.162"; classtype:trojan-activity; sid:100003207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.231.95.195"; classtype:trojan-activity; sid:100003208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.232.102.163"; classtype:trojan-activity; sid:100003209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.232.23.76"; classtype:trojan-activity; sid:100003210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.233.78.236"; classtype:trojan-activity; sid:100003211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.233.90.183"; classtype:trojan-activity; sid:100003212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.234.85.184"; classtype:trojan-activity; sid:100003213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.23.163"; classtype:trojan-activity; sid:100003214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.3.187"; classtype:trojan-activity; sid:100003215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.82.129"; classtype:trojan-activity; sid:100003216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.86.211"; classtype:trojan-activity; sid:100003217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.90.32"; classtype:trojan-activity; sid:100003218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.95.254"; classtype:trojan-activity; sid:100003219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.148.201"; classtype:trojan-activity; sid:100003220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.237.252.159"; classtype:trojan-activity; sid:100003221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.21.27"; classtype:trojan-activity; sid:100003222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.98.70"; classtype:trojan-activity; sid:100003223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.242.200.90"; classtype:trojan-activity; sid:100003224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.56.15.227"; classtype:trojan-activity; sid:100003225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.61.99.155"; classtype:trojan-activity; sid:100003226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.84.37.198"; classtype:trojan-activity; sid:100003227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.87.29.162"; classtype:trojan-activity; sid:100003228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.230.156.44"; classtype:trojan-activity; sid:100003229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.241.106.183"; classtype:trojan-activity; sid:100003230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.137"; classtype:trojan-activity; sid:100003231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.139"; classtype:trojan-activity; sid:100003232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.242"; classtype:trojan-activity; sid:100003233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.203.192"; classtype:trojan-activity; sid:100003234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.135.134.228"; classtype:trojan-activity; sid:100003235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.182"; classtype:trojan-activity; sid:100003236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.204"; classtype:trojan-activity; sid:100003237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.244"; classtype:trojan-activity; sid:100003238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.66"; classtype:trojan-activity; sid:100003239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.141.84.184"; classtype:trojan-activity; sid:100003240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.142"; classtype:trojan-activity; sid:100003241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.65"; classtype:trojan-activity; sid:100003242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.47"; classtype:trojan-activity; sid:100003243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.94"; classtype:trojan-activity; sid:100003244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.116"; classtype:trojan-activity; sid:100003245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.22"; classtype:trojan-activity; sid:100003246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.248"; classtype:trojan-activity; sid:100003247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.110.99"; classtype:trojan-activity; sid:100003248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.154"; classtype:trojan-activity; sid:100003249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.16"; classtype:trojan-activity; sid:100003250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.202"; classtype:trojan-activity; sid:100003251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.84"; classtype:trojan-activity; sid:100003252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.178.101.22"; classtype:trojan-activity; sid:100003253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.179.171.252"; classtype:trojan-activity; sid:100003254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.22.209.58"; classtype:trojan-activity; sid:100003255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.23.22.186"; classtype:trojan-activity; sid:100003256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.231.210.27"; classtype:trojan-activity; sid:100003257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.27.253.137"; classtype:trojan-activity; sid:100003258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.33.112.19"; classtype:trojan-activity; sid:100003259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.51.104.59"; classtype:trojan-activity; sid:100003260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.81.235.31"; classtype:trojan-activity; sid:100003261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.9.148.37"; classtype:trojan-activity; sid:100003262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.151.155.218"; classtype:trojan-activity; sid:100003263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.172.75.231"; classtype:trojan-activity; sid:100003264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.175.184.121"; classtype:trojan-activity; sid:100003265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.182.173.246"; classtype:trojan-activity; sid:100003266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.182.173.247"; classtype:trojan-activity; sid:100003267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.20.63.218"; classtype:trojan-activity; sid:100003268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.21.153.231"; classtype:trojan-activity; sid:100003269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.214.27.4"; classtype:trojan-activity; sid:100003270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.24.130.254"; classtype:trojan-activity; sid:100003271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.243.179.115"; classtype:trojan-activity; sid:100003272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.249.33.79"; classtype:trojan-activity; sid:100003273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.25.242.211"; classtype:trojan-activity; sid:100003274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.118.86"; classtype:trojan-activity; sid:100003275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.86.128"; classtype:trojan-activity; sid:100003276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.97.76.242"; classtype:trojan-activity; sid:100003277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.145.152.26"; classtype:trojan-activity; sid:100003278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.151.23.172"; classtype:trojan-activity; sid:100003279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.157.97.71"; classtype:trojan-activity; sid:100003280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.16.131.51"; classtype:trojan-activity; sid:100003281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.197.0.119"; classtype:trojan-activity; sid:100003282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.21.202.98"; classtype:trojan-activity; sid:100003283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.46.231.38"; classtype:trojan-activity; sid:100003284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.162.113"; classtype:trojan-activity; sid:100003285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.87.36"; classtype:trojan-activity; sid:100003286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.143.32.36"; classtype:trojan-activity; sid:100003287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.143.43.93"; classtype:trojan-activity; sid:100003288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.156.35.166"; classtype:trojan-activity; sid:100003289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.158.201.200"; classtype:trojan-activity; sid:100003290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.20.121"; classtype:trojan-activity; sid:100003291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.21.3"; classtype:trojan-activity; sid:100003292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.174.182.99"; classtype:trojan-activity; sid:100003293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.170.49"; classtype:trojan-activity; sid:100003294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.178.183"; classtype:trojan-activity; sid:100003295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.179.129"; classtype:trojan-activity; sid:100003296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.68.221.252"; classtype:trojan-activity; sid:100003297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.68.249.121"; classtype:trojan-activity; sid:100003298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.70.15.16"; classtype:trojan-activity; sid:100003299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.146.202.18"; classtype:trojan-activity; sid:100003300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.181.135.114"; classtype:trojan-activity; sid:100003301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.2.70.50"; classtype:trojan-activity; sid:100003302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.53.146.179"; classtype:trojan-activity; sid:100003303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.8.10.62"; classtype:trojan-activity; sid:100003304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.102"; classtype:trojan-activity; sid:100003305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.106"; classtype:trojan-activity; sid:100003306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.121.91.255"; classtype:trojan-activity; sid:100003307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.252.47.29"; classtype:trojan-activity; sid:100003308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"51.171.146.13"; classtype:trojan-activity; sid:100003309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"51.222.56.159"; classtype:trojan-activity; sid:100003310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.114.136"; classtype:trojan-activity; sid:100003311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.180.122"; classtype:trojan-activity; sid:100003312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.114.246.26"; classtype:trojan-activity; sid:100003313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.162.92"; classtype:trojan-activity; sid:100003314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.174.4"; classtype:trojan-activity; sid:100003315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.125.191.4"; classtype:trojan-activity; sid:100003316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.126.247.118"; classtype:trojan-activity; sid:100003317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.141.122.109"; classtype:trojan-activity; sid:100003318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.166.120"; classtype:trojan-activity; sid:100003319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.200.124"; classtype:trojan-activity; sid:100003320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.143.142.142"; classtype:trojan-activity; sid:100003321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.143.189.75"; classtype:trojan-activity; sid:100003322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.18.103.109"; classtype:trojan-activity; sid:100003323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.19.249.50"; classtype:trojan-activity; sid:100003324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.218.67.253"; classtype:trojan-activity; sid:100003325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.22.212.107"; classtype:trojan-activity; sid:100003326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.226.129.29"; classtype:trojan-activity; sid:100003327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.229.194.122"; classtype:trojan-activity; sid:100003328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.23.245.24"; classtype:trojan-activity; sid:100003329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.230.89.42"; classtype:trojan-activity; sid:100003330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.238.42.192"; classtype:trojan-activity; sid:100003331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.240.147.97"; classtype:trojan-activity; sid:100003332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.57.237"; classtype:trojan-activity; sid:100003333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.78.55"; classtype:trojan-activity; sid:100003334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.243.126.133"; classtype:trojan-activity; sid:100003335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.112.254"; classtype:trojan-activity; sid:100003336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.140.46"; classtype:trojan-activity; sid:100003337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.143.240"; classtype:trojan-activity; sid:100003338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.144.122"; classtype:trojan-activity; sid:100003339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.144.88"; classtype:trojan-activity; sid:100003340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.147.235"; classtype:trojan-activity; sid:100003341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.151.128"; classtype:trojan-activity; sid:100003342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.153.224"; classtype:trojan-activity; sid:100003343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.76.23"; classtype:trojan-activity; sid:100003344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.77.38"; classtype:trojan-activity; sid:100003345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.82.34"; classtype:trojan-activity; sid:100003346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.12.80"; classtype:trojan-activity; sid:100003347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.14.53"; classtype:trojan-activity; sid:100003348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.16.173"; classtype:trojan-activity; sid:100003349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.19.127"; classtype:trojan-activity; sid:100003350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.23.58"; classtype:trojan-activity; sid:100003351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.73.182"; classtype:trojan-activity; sid:100003352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.74.197"; classtype:trojan-activity; sid:100003353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.74.245"; classtype:trojan-activity; sid:100003354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.75.107"; classtype:trojan-activity; sid:100003355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.75.158"; classtype:trojan-activity; sid:100003356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.77.88"; classtype:trojan-activity; sid:100003357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.79.62"; classtype:trojan-activity; sid:100003358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.82.35"; classtype:trojan-activity; sid:100003359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.86.11"; classtype:trojan-activity; sid:100003360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.87.54"; classtype:trojan-activity; sid:100003361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.88.218"; classtype:trojan-activity; sid:100003362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.252.176.71"; classtype:trojan-activity; sid:100003363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.253.13.50"; classtype:trojan-activity; sid:100003364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.48.154.143"; classtype:trojan-activity; sid:100003365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.50.221.148"; classtype:trojan-activity; sid:100003366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.153"; classtype:trojan-activity; sid:100003367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.39"; classtype:trojan-activity; sid:100003368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.76.151.189"; classtype:trojan-activity; sid:100003369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.97.206.33"; classtype:trojan-activity; sid:100003370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.0.211.161"; classtype:trojan-activity; sid:100003371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.102.168.189"; classtype:trojan-activity; sid:100003372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.202.3"; classtype:trojan-activity; sid:100003373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.214.4"; classtype:trojan-activity; sid:100003374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.29.133.229"; classtype:trojan-activity; sid:100003375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.32.97.190"; classtype:trojan-activity; sid:100003376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.42.62.0"; classtype:trojan-activity; sid:100003377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.45.235.176"; classtype:trojan-activity; sid:100003378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.58.104.244"; classtype:trojan-activity; sid:100003379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.58.117.226"; classtype:trojan-activity; sid:100003380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.7.124.148"; classtype:trojan-activity; sid:100003381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.8.35.22"; classtype:trojan-activity; sid:100003382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.176.186"; classtype:trojan-activity; sid:100003383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.18.43"; classtype:trojan-activity; sid:100003384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.181.100"; classtype:trojan-activity; sid:100003385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.182.21"; classtype:trojan-activity; sid:100003386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.182.84"; classtype:trojan-activity; sid:100003387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.218.209"; classtype:trojan-activity; sid:100003388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.218.254"; classtype:trojan-activity; sid:100003389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.17.66"; classtype:trojan-activity; sid:100003390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.18.37"; classtype:trojan-activity; sid:100003391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.22.45"; classtype:trojan-activity; sid:100003392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.94.180.222"; classtype:trojan-activity; sid:100003393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.94.181.124"; classtype:trojan-activity; sid:100003394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.94.183.163"; classtype:trojan-activity; sid:100003395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.95.174.230"; classtype:trojan-activity; sid:100003396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.95.175.37"; classtype:trojan-activity; sid:100003397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.96.38.154"; classtype:trojan-activity; sid:100003398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.96.38.182"; classtype:trojan-activity; sid:100003399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.168.127"; classtype:trojan-activity; sid:100003400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.169.111"; classtype:trojan-activity; sid:100003401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.169.173"; classtype:trojan-activity; sid:100003402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.171.61"; classtype:trojan-activity; sid:100003403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.172.0"; classtype:trojan-activity; sid:100003404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.173.49"; classtype:trojan-activity; sid:100003405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.174.151"; classtype:trojan-activity; sid:100003406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.175.163"; classtype:trojan-activity; sid:100003407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.136.22"; classtype:trojan-activity; sid:100003408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.136.63"; classtype:trojan-activity; sid:100003409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.138.83"; classtype:trojan-activity; sid:100003410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.139.190"; classtype:trojan-activity; sid:100003411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.141.237"; classtype:trojan-activity; sid:100003412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.40.173"; classtype:trojan-activity; sid:100003413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.40.27"; classtype:trojan-activity; sid:100003414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.41.192"; classtype:trojan-activity; sid:100003415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.44.136"; classtype:trojan-activity; sid:100003416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.44.201"; classtype:trojan-activity; sid:100003417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.44.5"; classtype:trojan-activity; sid:100003418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.47.220"; classtype:trojan-activity; sid:100003419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.47.96"; classtype:trojan-activity; sid:100003420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.93.136"; classtype:trojan-activity; sid:100003421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.94.181"; classtype:trojan-activity; sid:100003422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.13.61.12"; classtype:trojan-activity; sid:100003423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.14.48.221"; classtype:trojan-activity; sid:100003424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.16.247.78"; classtype:trojan-activity; sid:100003425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.162.122.36"; classtype:trojan-activity; sid:100003426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.164.130.220"; classtype:trojan-activity; sid:100003427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.176.249.56"; classtype:trojan-activity; sid:100003428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.184.149.169"; classtype:trojan-activity; sid:100003429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.20.217.142"; classtype:trojan-activity; sid:100003430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.208.135.42"; classtype:trojan-activity; sid:100003431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.122.57"; classtype:trojan-activity; sid:100003432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.186.185"; classtype:trojan-activity; sid:100003433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.216.23"; classtype:trojan-activity; sid:100003434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.233.94"; classtype:trojan-activity; sid:100003435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.33.5"; classtype:trojan-activity; sid:100003436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.19.63"; classtype:trojan-activity; sid:100003437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.6.112"; classtype:trojan-activity; sid:100003438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.100.83"; classtype:trojan-activity; sid:100003439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.162.152"; classtype:trojan-activity; sid:100003440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.202.218"; classtype:trojan-activity; sid:100003441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.206.246"; classtype:trojan-activity; sid:100003442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.218.31"; classtype:trojan-activity; sid:100003443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.220.167"; classtype:trojan-activity; sid:100003444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.23.84"; classtype:trojan-activity; sid:100003445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.254.178"; classtype:trojan-activity; sid:100003446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.162.59"; classtype:trojan-activity; sid:100003447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.58.188"; classtype:trojan-activity; sid:100003448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.83.55"; classtype:trojan-activity; sid:100003449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.214.73.6"; classtype:trojan-activity; sid:100003450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.214.93.166"; classtype:trojan-activity; sid:100003451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.165.64"; classtype:trojan-activity; sid:100003452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.195.111"; classtype:trojan-activity; sid:100003453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.207.11"; classtype:trojan-activity; sid:100003454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.4.239"; classtype:trojan-activity; sid:100003455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.177.196"; classtype:trojan-activity; sid:100003456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.86.208"; classtype:trojan-activity; sid:100003457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.223.84.102"; classtype:trojan-activity; sid:100003458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.25.109.240"; classtype:trojan-activity; sid:100003459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.25.115.48"; classtype:trojan-activity; sid:100003460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.25.76.224"; classtype:trojan-activity; sid:100003461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.15.104"; classtype:trojan-activity; sid:100003462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.39.88"; classtype:trojan-activity; sid:100003463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.42.72"; classtype:trojan-activity; sid:100003464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.51.127"; classtype:trojan-activity; sid:100003465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.8.81"; classtype:trojan-activity; sid:100003466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.26.17.221"; classtype:trojan-activity; sid:100003467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.10.121"; classtype:trojan-activity; sid:100003468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.8.43"; classtype:trojan-activity; sid:100003469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.99.254"; classtype:trojan-activity; sid:100003470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.102.243.124"; classtype:trojan-activity; sid:100003471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.162.169.210"; classtype:trojan-activity; sid:100003472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.162.55.42"; classtype:trojan-activity; sid:100003473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.163.142.96"; classtype:trojan-activity; sid:100003474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.164.96.98"; classtype:trojan-activity; sid:100003475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.171.60"; classtype:trojan-activity; sid:100003476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.194"; classtype:trojan-activity; sid:100003477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.230"; classtype:trojan-activity; sid:100003478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.18.112.48"; classtype:trojan-activity; sid:100003479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.192.73.253"; classtype:trojan-activity; sid:100003480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.213.118.28"; classtype:trojan-activity; sid:100003481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.247.224.66"; classtype:trojan-activity; sid:100003482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.253.94.230"; classtype:trojan-activity; sid:100003483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.124.126"; classtype:trojan-activity; sid:100003484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.124.8"; classtype:trojan-activity; sid:100003485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.127.102"; classtype:trojan-activity; sid:100003486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.149.89"; classtype:trojan-activity; sid:100003487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.47.220.169"; classtype:trojan-activity; sid:100003488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.103.144"; classtype:trojan-activity; sid:100003489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.11.87"; classtype:trojan-activity; sid:100003490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.159.231"; classtype:trojan-activity; sid:100003491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.195.226"; classtype:trojan-activity; sid:100003492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.212.191"; classtype:trojan-activity; sid:100003493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.214.11"; classtype:trojan-activity; sid:100003494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.237.212"; classtype:trojan-activity; sid:100003495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.242.56"; classtype:trojan-activity; sid:100003496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.48.40"; classtype:trojan-activity; sid:100003497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.76.72"; classtype:trojan-activity; sid:100003498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.9.166"; classtype:trojan-activity; sid:100003499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.9.62"; classtype:trojan-activity; sid:100003500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.99.161"; classtype:trojan-activity; sid:100003501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.100.87"; classtype:trojan-activity; sid:100003502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.102.137"; classtype:trojan-activity; sid:100003503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.117.115"; classtype:trojan-activity; sid:100003504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.119.161"; classtype:trojan-activity; sid:100003505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.122.161"; classtype:trojan-activity; sid:100003506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.123.162"; classtype:trojan-activity; sid:100003507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.192.49"; classtype:trojan-activity; sid:100003508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.2.35"; classtype:trojan-activity; sid:100003509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.201.162"; classtype:trojan-activity; sid:100003510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.54.255"; classtype:trojan-activity; sid:100003511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.72.250"; classtype:trojan-activity; sid:100003512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.81.18"; classtype:trojan-activity; sid:100003513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.99.179"; classtype:trojan-activity; sid:100003514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.103.56"; classtype:trojan-activity; sid:100003515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.168.35"; classtype:trojan-activity; sid:100003516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.232.45"; classtype:trojan-activity; sid:100003517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.40.202"; classtype:trojan-activity; sid:100003518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.58.190"; classtype:trojan-activity; sid:100003519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.58.20"; classtype:trojan-activity; sid:100003520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.63.23"; classtype:trojan-activity; sid:100003521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.64.104"; classtype:trojan-activity; sid:100003522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.76.122"; classtype:trojan-activity; sid:100003523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.77.175"; classtype:trojan-activity; sid:100003524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.180.67"; classtype:trojan-activity; sid:100003525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.181.7"; classtype:trojan-activity; sid:100003526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.57.96.116"; classtype:trojan-activity; sid:100003527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.170.60"; classtype:trojan-activity; sid:100003528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.73.220"; classtype:trojan-activity; sid:100003529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.61.218.23"; classtype:trojan-activity; sid:100003530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.65.172.121"; classtype:trojan-activity; sid:100003531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.0.22"; classtype:trojan-activity; sid:100003532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.104.46"; classtype:trojan-activity; sid:100003533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.110.59"; classtype:trojan-activity; sid:100003534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.195"; classtype:trojan-activity; sid:100003535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.86"; classtype:trojan-activity; sid:100003536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.255.60"; classtype:trojan-activity; sid:100003537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.45.130"; classtype:trojan-activity; sid:100003538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.98.144.75"; classtype:trojan-activity; sid:100003539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.1.98.131"; classtype:trojan-activity; sid:100003540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.117.124.114"; classtype:trojan-activity; sid:100003541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.141.73.58"; classtype:trojan-activity; sid:100003542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.131.205"; classtype:trojan-activity; sid:100003543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.143.46"; classtype:trojan-activity; sid:100003544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.155.61"; classtype:trojan-activity; sid:100003545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.227.31"; classtype:trojan-activity; sid:100003546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.31.126.33"; classtype:trojan-activity; sid:100003547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.149.66"; classtype:trojan-activity; sid:100003548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.222.98"; classtype:trojan-activity; sid:100003549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.43.207.148"; classtype:trojan-activity; sid:100003550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.90.165.236"; classtype:trojan-activity; sid:100003551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"63.245.122.93"; classtype:trojan-activity; sid:100003552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"64.233.154.99"; classtype:trojan-activity; sid:100003553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.125.128.196"; classtype:trojan-activity; sid:100003554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.21.58.252"; classtype:trojan-activity; sid:100003555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.26.155.131"; classtype:trojan-activity; sid:100003556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.35.61.255"; classtype:trojan-activity; sid:100003557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.153.233.87"; classtype:trojan-activity; sid:100003558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.229.214.115"; classtype:trojan-activity; sid:100003559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.57.55.210"; classtype:trojan-activity; sid:100003560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.74.7.197"; classtype:trojan-activity; sid:100003561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.91.21.31"; classtype:trojan-activity; sid:100003562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.196"; classtype:trojan-activity; sid:100003563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.213"; classtype:trojan-activity; sid:100003564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.245.151.203"; classtype:trojan-activity; sid:100003565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.3.169.223"; classtype:trojan-activity; sid:100003566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.8.138.101"; classtype:trojan-activity; sid:100003567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.81.98.111"; classtype:trojan-activity; sid:100003568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.82.242.243"; classtype:trojan-activity; sid:100003569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.83.49.234"; classtype:trojan-activity; sid:100003570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.84.138.165"; classtype:trojan-activity; sid:100003571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.151.244.128"; classtype:trojan-activity; sid:100003572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.174.182.226"; classtype:trojan-activity; sid:100003573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.175.107.153"; classtype:trojan-activity; sid:100003574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.188.144.143"; classtype:trojan-activity; sid:100003575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.204.88.29"; classtype:trojan-activity; sid:100003576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.106.84"; classtype:trojan-activity; sid:100003577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.119.241"; classtype:trojan-activity; sid:100003578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.78.33.33"; classtype:trojan-activity; sid:100003579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.115.37.205"; classtype:trojan-activity; sid:100003580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.120.237.255"; classtype:trojan-activity; sid:100003581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.123.245.151"; classtype:trojan-activity; sid:100003582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.124.231.110"; classtype:trojan-activity; sid:100003583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.127.214.47"; classtype:trojan-activity; sid:100003584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.146.232.34"; classtype:trojan-activity; sid:100003585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.165.173.49"; classtype:trojan-activity; sid:100003586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.196.158.227"; classtype:trojan-activity; sid:100003587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.222.157.166"; classtype:trojan-activity; sid:100003588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.229.0.133"; classtype:trojan-activity; sid:100003589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.63.73.234"; classtype:trojan-activity; sid:100003590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.115.194"; classtype:trojan-activity; sid:100003591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.227.186"; classtype:trojan-activity; sid:100003592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.76.240.206"; classtype:trojan-activity; sid:100003593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.115.31.30"; classtype:trojan-activity; sid:100003594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.118.240.88"; classtype:trojan-activity; sid:100003595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.167.10.180"; classtype:trojan-activity; sid:100003596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.236.190.250"; classtype:trojan-activity; sid:100003597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.25.5.105"; classtype:trojan-activity; sid:100003598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.93.129.118"; classtype:trojan-activity; sid:100003599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.127.148.69"; classtype:trojan-activity; sid:100003600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.146.190.91"; classtype:trojan-activity; sid:100003601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.167.164.113"; classtype:trojan-activity; sid:100003602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.19.150.93"; classtype:trojan-activity; sid:100003603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.204.63.239"; classtype:trojan-activity; sid:100003604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.29.48.164"; classtype:trojan-activity; sid:100003605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.34.191.213"; classtype:trojan-activity; sid:100003606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.40.234.166"; classtype:trojan-activity; sid:100003607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.106.142"; classtype:trojan-activity; sid:100003608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.2.122"; classtype:trojan-activity; sid:100003609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.235.106"; classtype:trojan-activity; sid:100003610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.47.133.58"; classtype:trojan-activity; sid:100003611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.71.60.69"; classtype:trojan-activity; sid:100003612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.85.106.211"; classtype:trojan-activity; sid:100003613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.17.22.30"; classtype:trojan-activity; sid:100003614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.186.139.38"; classtype:trojan-activity; sid:100003615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.180.98"; classtype:trojan-activity; sid:100003616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.200.62"; classtype:trojan-activity; sid:100003617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.214.69.226"; classtype:trojan-activity; sid:100003618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.230.118"; classtype:trojan-activity; sid:100003619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.35.40"; classtype:trojan-activity; sid:100003620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.204.216.103"; classtype:trojan-activity; sid:100003621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.101.1.159"; classtype:trojan-activity; sid:100003622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.108.224.112"; classtype:trojan-activity; sid:100003623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.194.117.165"; classtype:trojan-activity; sid:100003624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.195.115.176"; classtype:trojan-activity; sid:100003625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.199.84.77"; classtype:trojan-activity; sid:100003626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.64.139.223"; classtype:trojan-activity; sid:100003627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.75.165.81"; classtype:trojan-activity; sid:100003628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.127.141.52"; classtype:trojan-activity; sid:100003629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.176.213.114"; classtype:trojan-activity; sid:100003630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.83.102.27"; classtype:trojan-activity; sid:100003631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.99.213.61"; classtype:trojan-activity; sid:100003632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.108.199.153"; classtype:trojan-activity; sid:100003633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.170.11.82"; classtype:trojan-activity; sid:100003634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.178.22.145"; classtype:trojan-activity; sid:100003635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.250.199.133"; classtype:trojan-activity; sid:100003636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.254.129.227"; classtype:trojan-activity; sid:100003637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.84.134.33"; classtype:trojan-activity; sid:100003638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.95.12.137"; classtype:trojan-activity; sid:100003639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.237.25.210"; classtype:trojan-activity; sid:100003640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.50.153"; classtype:trojan-activity; sid:100003641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.52.220"; classtype:trojan-activity; sid:100003642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.79.191.32"; classtype:trojan-activity; sid:100003643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.89.203.238"; classtype:trojan-activity; sid:100003644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.186.155.18"; classtype:trojan-activity; sid:100003645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.141.144"; classtype:trojan-activity; sid:100003646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.240.125"; classtype:trojan-activity; sid:100003647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.41.200"; classtype:trojan-activity; sid:100003648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.168.64"; classtype:trojan-activity; sid:100003649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.188.141"; classtype:trojan-activity; sid:100003650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.104.157"; classtype:trojan-activity; sid:100003651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.176.163"; classtype:trojan-activity; sid:100003652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.23.172.81"; classtype:trojan-activity; sid:100003653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.8.225.77"; classtype:trojan-activity; sid:100003654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.11.195.121"; classtype:trojan-activity; sid:100003655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.13.49.221"; classtype:trojan-activity; sid:100003656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.130.253.13"; classtype:trojan-activity; sid:100003657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.147.123.48"; classtype:trojan-activity; sid:100003658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.170.31.56"; classtype:trojan-activity; sid:100003659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.175.42.244"; classtype:trojan-activity; sid:100003660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.21.84.63"; classtype:trojan-activity; sid:100003661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.7.170.58"; classtype:trojan-activity; sid:100003662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.79.58.94"; classtype:trojan-activity; sid:100003663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.8.70.162"; classtype:trojan-activity; sid:100003664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.9.88.185"; classtype:trojan-activity; sid:100003665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.107.89.207"; classtype:trojan-activity; sid:100003666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.19.101.218"; classtype:trojan-activity; sid:100003667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.211.181.77"; classtype:trojan-activity; sid:100003668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.217.12.7"; classtype:trojan-activity; sid:100003669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.67.32.66"; classtype:trojan-activity; sid:100003670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.99.128.61"; classtype:trojan-activity; sid:100003671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.136.146.213"; classtype:trojan-activity; sid:100003672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.165.44.109"; classtype:trojan-activity; sid:100003673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.191.40.58"; classtype:trojan-activity; sid:100003674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.111.60"; classtype:trojan-activity; sid:100003675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.141.184"; classtype:trojan-activity; sid:100003676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.215.199.29"; classtype:trojan-activity; sid:100003677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.187.113"; classtype:trojan-activity; sid:100003678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.195.216"; classtype:trojan-activity; sid:100003679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.237.128.200"; classtype:trojan-activity; sid:100003680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.246.225.203"; classtype:trojan-activity; sid:100003681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.92.36.96"; classtype:trojan-activity; sid:100003682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.103.108.72"; classtype:trojan-activity; sid:100003683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.135.196.130"; classtype:trojan-activity; sid:100003684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.212.178"; classtype:trojan-activity; sid:100003685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.85.112"; classtype:trojan-activity; sid:100003686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.207.61.194"; classtype:trojan-activity; sid:100003687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.209.250.155"; classtype:trojan-activity; sid:100003688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.211.156.38"; classtype:trojan-activity; sid:100003689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.110.252"; classtype:trojan-activity; sid:100003690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.53.77"; classtype:trojan-activity; sid:100003691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.138.72"; classtype:trojan-activity; sid:100003692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.139.92"; classtype:trojan-activity; sid:100003693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.154.214"; classtype:trojan-activity; sid:100003694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.187.109"; classtype:trojan-activity; sid:100003695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.100.54"; classtype:trojan-activity; sid:100003696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.106.65"; classtype:trojan-activity; sid:100003697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.108.172"; classtype:trojan-activity; sid:100003698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.131.158"; classtype:trojan-activity; sid:100003699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.19.42"; classtype:trojan-activity; sid:100003700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.197.254"; classtype:trojan-activity; sid:100003701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.215.149"; classtype:trojan-activity; sid:100003702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.232.68"; classtype:trojan-activity; sid:100003703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.234.195"; classtype:trojan-activity; sid:100003704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.246.96"; classtype:trojan-activity; sid:100003705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.28.57"; classtype:trojan-activity; sid:100003706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.4.57"; classtype:trojan-activity; sid:100003707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.55.84"; classtype:trojan-activity; sid:100003708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.73.245"; classtype:trojan-activity; sid:100003709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.9.62"; classtype:trojan-activity; sid:100003710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.98.51"; classtype:trojan-activity; sid:100003711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.165.237.163"; classtype:trojan-activity; sid:100003712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.147.99"; classtype:trojan-activity; sid:100003713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.218.42"; classtype:trojan-activity; sid:100003714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.242.253.154"; classtype:trojan-activity; sid:100003715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.252.9.37"; classtype:trojan-activity; sid:100003716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.208"; classtype:trojan-activity; sid:100003717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.213"; classtype:trojan-activity; sid:100003718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.212.219.127"; classtype:trojan-activity; sid:100003719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.224.162.170"; classtype:trojan-activity; sid:100003720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.50.118"; classtype:trojan-activity; sid:100003721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.95.204"; classtype:trojan-activity; sid:100003722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.247.83.74"; classtype:trojan-activity; sid:100003723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.254.39.129"; classtype:trojan-activity; sid:100003724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.33.111.227"; classtype:trojan-activity; sid:100003725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.40.127.242"; classtype:trojan-activity; sid:100003726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.42.20.217"; classtype:trojan-activity; sid:100003727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; classtype:trojan-activity; sid:100003728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.11.216"; classtype:trojan-activity; sid:100003729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.123.251"; classtype:trojan-activity; sid:100003730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.135.187"; classtype:trojan-activity; sid:100003731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.208.25"; classtype:trojan-activity; sid:100003732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.224.141"; classtype:trojan-activity; sid:100003733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.241.2"; classtype:trojan-activity; sid:100003734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.214.149.236"; classtype:trojan-activity; sid:100003735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.64.181.50"; classtype:trojan-activity; sid:100003736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.74.215.180"; classtype:trojan-activity; sid:100003737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.130.227"; classtype:trojan-activity; sid:100003738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.195.129"; classtype:trojan-activity; sid:100003739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"86.35.43.220"; classtype:trojan-activity; sid:100003740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.61.89.40"; classtype:trojan-activity; sid:100003741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.119.171.253"; classtype:trojan-activity; sid:100003742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.208.71"; classtype:trojan-activity; sid:100003743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.219.179"; classtype:trojan-activity; sid:100003744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.225.222.128"; classtype:trojan-activity; sid:100003745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.247.96.19"; classtype:trojan-activity; sid:100003746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.136.231"; classtype:trojan-activity; sid:100003747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.51.139"; classtype:trojan-activity; sid:100003748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.249.244.180"; classtype:trojan-activity; sid:100003749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.204.12"; classtype:trojan-activity; sid:100003750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.226.26"; classtype:trojan-activity; sid:100003751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.254.90"; classtype:trojan-activity; sid:100003752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.122.183.130"; classtype:trojan-activity; sid:100003753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.29.213.33"; classtype:trojan-activity; sid:100003754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.34.26.165"; classtype:trojan-activity; sid:100003755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.35.62.96"; classtype:trojan-activity; sid:100003756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.85.166"; classtype:trojan-activity; sid:100003757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.87.5"; classtype:trojan-activity; sid:100003758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.46.237.89"; classtype:trojan-activity; sid:100003759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8poieq.bn.files.1drv.com"; classtype:trojan-activity; sid:100003760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"90.152.144.139"; classtype:trojan-activity; sid:100003761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"90.63.176.144"; classtype:trojan-activity; sid:100003762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.177.139.132"; classtype:trojan-activity; sid:100003763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.187.103.32"; classtype:trojan-activity; sid:100003764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.212.150.241"; classtype:trojan-activity; sid:100003765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.217.104.185"; classtype:trojan-activity; sid:100003766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.233.112.188"; classtype:trojan-activity; sid:100003767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.234.60.94"; classtype:trojan-activity; sid:100003768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.239.168.83"; classtype:trojan-activity; sid:100003769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.244.169.139"; classtype:trojan-activity; sid:100003770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.92.16.244"; classtype:trojan-activity; sid:100003771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.98.4.181"; classtype:trojan-activity; sid:100003772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.113.93.34"; classtype:trojan-activity; sid:100003773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.114.191.82"; classtype:trojan-activity; sid:100003774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.241.78.114"; classtype:trojan-activity; sid:100003775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.27.246.202"; classtype:trojan-activity; sid:100003776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.54.237.143"; classtype:trojan-activity; sid:100003777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.54.237.237"; classtype:trojan-activity; sid:100003778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.83.62.139"; classtype:trojan-activity; sid:100003779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.85.18.138"; classtype:trojan-activity; sid:100003780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.171.157.73"; classtype:trojan-activity; sid:100003781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.21.224.154"; classtype:trojan-activity; sid:100003782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.115.176"; classtype:trojan-activity; sid:100003783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.137.16"; classtype:trojan-activity; sid:100003784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.182.249"; classtype:trojan-activity; sid:100003785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.206.56"; classtype:trojan-activity; sid:100003786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.57.43.233"; classtype:trojan-activity; sid:100003787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.73.99.102"; classtype:trojan-activity; sid:100003788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.136.69.199"; classtype:trojan-activity; sid:100003789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.143.53.34"; classtype:trojan-activity; sid:100003790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.17.170"; classtype:trojan-activity; sid:100003791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.82.190"; classtype:trojan-activity; sid:100003792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.200.16.22"; classtype:trojan-activity; sid:100003793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.224.83.208"; classtype:trojan-activity; sid:100003794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.53.120.109"; classtype:trojan-activity; sid:100003795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.132.129.250"; classtype:trojan-activity; sid:100003796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.153.241.63"; classtype:trojan-activity; sid:100003797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.154.20.231"; classtype:trojan-activity; sid:100003798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.158.19.130"; classtype:trojan-activity; sid:100003799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.113.52"; classtype:trojan-activity; sid:100003800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.201.34"; classtype:trojan-activity; sid:100003801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.181.155.112"; classtype:trojan-activity; sid:100003802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.146.134"; classtype:trojan-activity; sid:100003803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.6.114"; classtype:trojan-activity; sid:100003804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.66.196.63"; classtype:trojan-activity; sid:100003805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.9.120.40"; classtype:trojan-activity; sid:100003806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.239.73.246"; classtype:trojan-activity; sid:100003807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.47.147.169"; classtype:trojan-activity; sid:100003808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.103.64.196"; classtype:trojan-activity; sid:100003809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.68.140.254"; classtype:trojan-activity; sid:100003810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.96.199.75"; classtype:trojan-activity; sid:100003811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.210.218"; classtype:trojan-activity; sid:100003812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.239.142"; classtype:trojan-activity; sid:100003813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.113.239.207"; classtype:trojan-activity; sid:100003814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.116.72.119"; classtype:trojan-activity; sid:100003815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.128.147.115"; classtype:trojan-activity; sid:100003816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.178.242.44"; classtype:trojan-activity; sid:100003817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.249.236.11"; classtype:trojan-activity; sid:100003818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.28.200.139"; classtype:trojan-activity; sid:100003819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.30.24.54"; classtype:trojan-activity; sid:100003820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.150.245.203"; classtype:trojan-activity; sid:100003821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.33.195.164"; classtype:trojan-activity; sid:100003822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99centsdigitals.com"; classtype:trojan-activity; sid:100003823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abcd.bg"; classtype:trojan-activity; sid:100003824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abclicks.in"; classtype:trojan-activity; sid:100003825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abissnet.net"; classtype:trojan-activity; sid:100003826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aboveandbelow.com.au"; classtype:trojan-activity; sid:100003827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absoftechworld.com"; classtype:trojan-activity; sid:100003828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absupplies.co.uk"; classtype:trojan-activity; sid:100003829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abyssos.eu"; classtype:trojan-activity; sid:100003830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acbick.com"; classtype:trojan-activity; sid:100003831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"accounts.thesmarttechhub.com"; classtype:trojan-activity; sid:100003832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aceeprc.com.aceeprc.com"; classtype:trojan-activity; sid:100003833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acellr.co.uk"; classtype:trojan-activity; sid:100003834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aciabogados.com"; classtype:trojan-activity; sid:100003835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acteon.com.ar"; classtype:trojan-activity; sid:100003836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"activateyourdiscount.com"; classtype:trojan-activity; sid:100003837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"activecost.com.au"; classtype:trojan-activity; sid:100003838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adamorinmusic.com"; classtype:trojan-activity; sid:100003839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"addahealingmusic.com"; classtype:trojan-activity; sid:100003840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.com"; classtype:trojan-activity; sid:100003841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.memengers.com"; classtype:trojan-activity; sid:100003842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.erapor.smk-alasror.net"; classtype:trojan-activity; sid:100003843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.gentbcn.org"; classtype:trojan-activity; sid:100003844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.grandoceanvilla.com"; classtype:trojan-activity; sid:100003845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adventureexplorer.in"; classtype:trojan-activity; sid:100003846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aeropilates.cl"; classtype:trojan-activity; sid:100003847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afrimedspecialist.com"; classtype:trojan-activity; sid:100003848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agemn.co.za"; classtype:trojan-activity; sid:100003849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciadigitalwdys.com"; classtype:trojan-activity; sid:100003850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciatabletshouse.com.br"; classtype:trojan-activity; sid:100003851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenda.gmelloinformatica.com.br"; classtype:trojan-activity; sid:100003852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agentt.ac.ug"; classtype:trojan-activity; sid:100003853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agile8studio.com"; classtype:trojan-activity; sid:100003854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agmcarpetcare.co.uk"; classtype:trojan-activity; sid:100003855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiqtest.com"; classtype:trojan-activity; sid:100003856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajpharmaholding.com"; classtype:trojan-activity; sid:100003857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajstudiollc.com"; classtype:trojan-activity; sid:100003858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"akivj07.top"; classtype:trojan-activity; sid:100003859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"al-wahd.com"; classtype:trojan-activity; sid:100003860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alasdemariposas.org"; classtype:trojan-activity; sid:100003861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alemelektronik.com"; classtype:trojan-activity; sid:100003862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alena1971.es"; classtype:trojan-activity; sid:100003863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alexdubai.com.aldiabsteel.com"; classtype:trojan-activity; sid:100003864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"algreenstdykelveskbg.dns.army"; classtype:trojan-activity; sid:100003865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alka.institute"; classtype:trojan-activity; sid:100003866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"allforcreative.com.au"; classtype:trojan-activity; sid:100003867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alltheway.travel"; classtype:trojan-activity; sid:100003868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alpaylar.com.tr"; classtype:trojan-activity; sid:100003869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"am-concepts.ca"; classtype:trojan-activity; sid:100003870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amamontajes.com"; classtype:trojan-activity; sid:100003871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarresdeamorymaestroshechiceros.com"; classtype:trojan-activity; sid:100003872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarteargentina.com.ar"; classtype:trojan-activity; sid:100003873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amenyan.zouri.jp"; classtype:trojan-activity; sid:100003874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amos524.org"; classtype:trojan-activity; sid:100003875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ams.alvinasschools.org.ng"; classtype:trojan-activity; sid:100003876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anantam.net.in"; classtype:trojan-activity; sid:100003877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreelapeyre.com"; classtype:trojan-activity; sid:100003878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andremaraisbeleggings.co.za"; classtype:trojan-activity; sid:100003879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ac.ug"; classtype:trojan-activity; sid:100003880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ug"; classtype:trojan-activity; sid:100003881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreshconcejal.solucioneslink.com"; classtype:trojan-activity; sid:100003882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelazgheibld.com"; classtype:trojan-activity; sid:100003883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelsdetour.com"; classtype:trojan-activity; sid:100003884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angloteste.bigprime.com.br"; classtype:trojan-activity; sid:100003885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anhung1102.vn"; classtype:trojan-activity; sid:100003886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anysbergbiltong.co.za"; classtype:trojan-activity; sid:100003887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apartamentoscitta.com"; classtype:trojan-activity; sid:100003888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api-ms.cobainaja.id"; classtype:trojan-activity; sid:100003889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.cstdevs.com"; classtype:trojan-activity; sid:100003890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.quocbao.biz"; classtype:trojan-activity; sid:100003891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.sampy.io"; classtype:trojan-activity; sid:100003892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apoolcondo.com"; classtype:trojan-activity; sid:100003893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.adsensearticle.com"; classtype:trojan-activity; sid:100003894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.explicitsurveys.co.uk"; classtype:trojan-activity; sid:100003895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.prerana.info"; classtype:trojan-activity; sid:100003896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apps.saintsoporte.com"; classtype:trojan-activity; sid:100003897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aqv.news"; classtype:trojan-activity; sid:100003898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"areyoulivingwell.com"; classtype:trojan-activity; sid:100003899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"arsapetrolab.com"; classtype:trojan-activity; sid:100003900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"artedibujoyarquitectura.com"; classtype:trojan-activity; sid:100003901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ask-regard.call-save.biz"; classtype:trojan-activity; sid:100003902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atfile.com"; classtype:trojan-activity; sid:100003903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"athenacapsg.com"; classtype:trojan-activity; sid:100003904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atlasconcreteworks.com"; classtype:trojan-activity; sid:100003905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atnetech.com"; classtype:trojan-activity; sid:100003906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"attach.66rpg.com"; classtype:trojan-activity; sid:100003907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atteuqpotentialunlimited.com"; classtype:trojan-activity; sid:100003908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"augustair.com"; classtype:trojan-activity; sid:100003909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aulist.com"; classtype:trojan-activity; sid:100003910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"australiafashions.com"; classtype:trojan-activity; sid:100003911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"automaticrefreshments.com"; classtype:trojan-activity; sid:100003912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"avadhanagames.com"; classtype:trojan-activity; sid:100003913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"avissrilanka.com"; classtype:trojan-activity; sid:100003914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayamallah.com"; classtype:trojan-activity; sid:100003915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azmeasurement.com"; classtype:trojan-activity; sid:100003916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azraktours.com"; classtype:trojan-activity; sid:100003917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"b2b.toptanakaryakit.com.tr"; classtype:trojan-activity; sid:100003918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"backgrounds.pk"; classtype:trojan-activity; sid:100003919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"badeggdesign.com"; classtype:trojan-activity; sid:100003920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"balealgodon.mx"; classtype:trojan-activity; sid:100003921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangkok-orchids.com"; classtype:trojan-activity; sid:100003922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"barcionstw.eastus.cloudapp.azure.com"; classtype:trojan-activity; sid:100003923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bary.sz4h.com"; classtype:trojan-activity; sid:100003924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bash.givemexyz.in"; classtype:trojan-activity; sid:100003925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"basma.com.kw"; classtype:trojan-activity; sid:100003926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; classtype:trojan-activity; sid:100003927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bavhome.com"; classtype:trojan-activity; sid:100003928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bbia.co.uk"; classtype:trojan-activity; sid:100003929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcmt.elin.co.za"; classtype:trojan-activity; sid:100003930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcrg.co.za"; classtype:trojan-activity; sid:100003931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bearcatpumps.com.cn"; classtype:trojan-activity; sid:100003932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beautincollagen.rs"; classtype:trojan-activity; sid:100003933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bekape.co.id"; classtype:trojan-activity; sid:100003934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bespokeweddings.ie"; classtype:trojan-activity; sid:100003935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bestcarenepal.com"; classtype:trojan-activity; sid:100003936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betone.co.kr"; classtype:trojan-activity; sid:100003937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betycopaints.com"; classtype:trojan-activity; sid:100003938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beveragesmiami.solucioneslink.com"; classtype:trojan-activity; sid:100003939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bhavaniengineering.com"; classtype:trojan-activity; sid:100003940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bigbag.wootraining.certificacion.cl"; classtype:trojan-activity; sid:100003941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilbosaquet.ug"; classtype:trojan-activity; sid:100003942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilhen.co.za"; classtype:trojan-activity; sid:100003943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"billing.rahitechnosoft.com"; classtype:trojan-activity; sid:100003944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"binoy.stalphonsamissionva.org"; classtype:trojan-activity; sid:100003945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birdi.elin.co.za"; classtype:trojan-activity; sid:100003946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birminghamlink.org"; classtype:trojan-activity; sid:100003947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.callensaxen.com"; classtype:trojan-activity; sid:100003948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.oyinblogs.com"; classtype:trojan-activity; sid:100003949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.takbelit.com"; classtype:trojan-activity; sid:100003950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bmlifestyle.co.uk"; classtype:trojan-activity; sid:100003951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bnrbook.com"; classtype:trojan-activity; sid:100003952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bnrnews.id"; classtype:trojan-activity; sid:100003953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bodenstein.co.za"; classtype:trojan-activity; sid:100003954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"booksearch.com"; classtype:trojan-activity; sid:100003955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bounces.mi-fs.com"; classtype:trojan-activity; sid:100003956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bpo.correct.go.th"; classtype:trojan-activity; sid:100003957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brandtrust.com.pk"; classtype:trojan-activity; sid:100003958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brendanquine.com"; classtype:trojan-activity; sid:100003959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brideofmessiah.com"; classtype:trojan-activity; sid:100003960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bridesofmaldives.com"; classtype:trojan-activity; sid:100003961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightmega.com"; classtype:trojan-activity; sid:100003962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightonrooms.co.uk"; classtype:trojan-activity; sid:100003963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightstarshop.com"; classtype:trojan-activity; sid:100003964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"browardinsurancemiami.solucioneslink.com"; classtype:trojan-activity; sid:100003965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bt2.elin.co.za"; classtype:trojan-activity; sid:100003966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"btdapi.robotake.com"; classtype:trojan-activity; sid:100003967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bucrinsuranlceonlines.com"; classtype:trojan-activity; sid:100003968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buenavista.co"; classtype:trojan-activity; sid:100003969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buigiaphat.com.vn"; classtype:trojan-activity; sid:100003970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bullseyemedia.in"; classtype:trojan-activity; sid:100003971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"busandvanrentalmalaysia.com"; classtype:trojan-activity; sid:100003972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buscascolegios.diit.cl"; classtype:trojan-activity; sid:100003973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business.softberg.ro"; classtype:trojan-activity; sid:100003974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buyingmusiconline.com"; classtype:trojan-activity; sid:100003975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bwsr.eu"; classtype:trojan-activity; sid:100003976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c.oooooooooo.ga"; classtype:trojan-activity; sid:100003977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c0140529.ferozo.com"; classtype:trojan-activity; sid:100003978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"caballo.com.au"; classtype:trojan-activity; sid:100003979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"calgaryautorepairservice.com"; classtype:trojan-activity; sid:100003980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"callbury.in"; classtype:trojan-activity; sid:100003981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"camminachetipassa.it"; classtype:trojan-activity; sid:100003982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"campusvirtual.cepsanjuanbosco.net.pe"; classtype:trojan-activity; sid:100003983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cancer.educandome.co"; classtype:trojan-activity; sid:100003984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalgroup-kw.com"; classtype:trojan-activity; sid:100003985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalnewsagency.com"; classtype:trojan-activity; sid:100003986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capoeiraventrelivre.com"; classtype:trojan-activity; sid:100003987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cashyinvestment.org"; classtype:trojan-activity; sid:100003988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchpoolshetlands.co.uk"; classtype:trojan-activity; sid:100003989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cazyacustomfurniture.com"; classtype:trojan-activity; sid:100003990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ccauthority.net"; classtype:trojan-activity; sid:100003991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cdaonline.com.ar"; classtype:trojan-activity; sid:100003992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cec.asso.ac-amiens.fr"; classtype:trojan-activity; sid:100003993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cellas.sk"; classtype:trojan-activity; sid:100003994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cendekiabinaaksara.com"; classtype:trojan-activity; sid:100003995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cespol-bote.com.mx"; classtype:trojan-activity; sid:100003996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cfs5.tistory.com"; classtype:trojan-activity; sid:100003997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ch.rmu.ac.th"; classtype:trojan-activity; sid:100003998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"changematterscounselling.com"; classtype:trojan-activity; sid:100003999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chardhamdodham.com"; classtype:trojan-activity; sid:100004000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cheacrilnsurances.com"; classtype:trojan-activity; sid:100004001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chealablilitycarinsurances.com"; classtype:trojan-activity; sid:100004002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chezalice.co.za"; classtype:trojan-activity; sid:100004003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"childselect.com"; classtype:trojan-activity; sid:100004004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile.myvnc.com"; classtype:trojan-activity; sid:100004005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile80.myvnc.com"; classtype:trojan-activity; sid:100004006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cible-energy.com"; classtype:trojan-activity; sid:100004007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cifeer.net"; classtype:trojan-activity; sid:100004008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citycapproperty.ru"; classtype:trojan-activity; sid:100004009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cityglobalgospel.com"; classtype:trojan-activity; sid:100004010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"civi.istmejia.com"; classtype:trojan-activity; sid:100004011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cleanbydesignllc.com"; classtype:trojan-activity; sid:100004012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cloud.fc.co.mz"; classtype:trojan-activity; sid:100004013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"codsambal.com"; classtype:trojan-activity; sid:100004014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colinde.pricesne.com"; classtype:trojan-activity; sid:100004015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colorpak.pl"; classtype:trojan-activity; sid:100004016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"competancy.indigoconsult.net"; classtype:trojan-activity; sid:100004017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"config.cqhbkjzx.com"; classtype:trojan-activity; sid:100004018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"constructoralyon.com"; classtype:trojan-activity; sid:100004019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"consulateins.solucioneslink.com"; classtype:trojan-activity; sid:100004020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"contributeindustry.com"; classtype:trojan-activity; sid:100004021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"controladoradeplagasmm.com"; classtype:trojan-activity; sid:100004022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"controleautomacao.com.br"; classtype:trojan-activity; sid:100004023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"copelandscapes.com"; classtype:trojan-activity; sid:100004024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"coulsongraphics.com"; classtype:trojan-activity; sid:100004025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"coutler.newreadermedia.net"; classtype:trojan-activity; sid:100004026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"covid19.cyberschool.or.id"; classtype:trojan-activity; sid:100004027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cr-sq.com"; classtype:trojan-activity; sid:100004028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"craftnesia.id"; classtype:trojan-activity; sid:100004029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"creationskateboards.com"; classtype:trojan-activity; sid:100004030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crecerco.com"; classtype:trojan-activity; sid:100004031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crittersbythebay.com"; classtype:trojan-activity; sid:100004032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crm.notariavieitoyvelamazan.com"; classtype:trojan-activity; sid:100004033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crscorretordeimoveis.com.br"; classtype:trojan-activity; sid:100004034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cse-engineer.com"; classtype:trojan-activity; sid:100004035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"csnserver.com"; classtype:trojan-activity; sid:100004036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubescargoexpress.com"; classtype:trojan-activity; sid:100004037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubrebocasenpuebla.com.mx"; classtype:trojan-activity; sid:100004038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"curasoles.co.za"; classtype:trojan-activity; sid:100004039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"currantmedia.com"; classtype:trojan-activity; sid:100004040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cwa.mx"; classtype:trojan-activity; sid:100004041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyber.searchkero.com"; classtype:trojan-activity; sid:100004042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyclomove.com"; classtype:trojan-activity; sid:100004043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cynkon.kairoscs.net"; classtype:trojan-activity; sid:100004044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czas.dbstrony.pl"; classtype:trojan-activity; sid:100004045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czsl.91756.cn"; classtype:trojan-activity; sid:100004046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d.powerofwish.com"; classtype:trojan-activity; sid:100004047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d9.99ddd.com"; classtype:trojan-activity; sid:100004048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"da.alibuf.com"; classtype:trojan-activity; sid:100004049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"damagedessentialtelecommunications.testmail4.repl.co"; classtype:trojan-activity; sid:100004050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dandyair.com"; classtype:trojan-activity; sid:100004051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dartoonpictures.com"; classtype:trojan-activity; sid:100004052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.cdevelop.org"; classtype:trojan-activity; sid:100004053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.over-blog-kiwi.com"; classtype:trojan-activity; sid:100004054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datapolish.com"; classtype:trojan-activity; sid:100004055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dating.khokhas.co.za"; classtype:trojan-activity; sid:100004056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datsom.vn"; classtype:trojan-activity; sid:100004057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"daunhotq10.com"; classtype:trojan-activity; sid:100004058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davethompson.me.uk"; classtype:trojan-activity; sid:100004059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davidmcguinness.info"; classtype:trojan-activity; sid:100004060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dayspringdaisies.com"; classtype:trojan-activity; sid:100004061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dd.qiyuea.cn"; classtype:trojan-activity; sid:100004062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"de.gsearch.com.de"; classtype:trojan-activity; sid:100004063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"decifrar.com.br"; classtype:trojan-activity; sid:100004064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"deigratia2.elin.co.za"; classtype:trojan-activity; sid:100004065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dekovizyon.com"; classtype:trojan-activity; sid:100004066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo-cliente.mindcreative.com.br"; classtype:trojan-activity; sid:100004067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo6.hiites.com"; classtype:trojan-activity; sid:100004068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dent-estet.com"; classtype:trojan-activity; sid:100004069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dental.xiaoxiao.media"; classtype:trojan-activity; sid:100004070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dentalalliance.se"; classtype:trojan-activity; sid:100004071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"designerliving.co.za"; classtype:trojan-activity; sid:100004072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"desiringhands.com"; classtype:trojan-activity; sid:100004073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"despertaresi.com.br"; classtype:trojan-activity; sid:100004074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"destinymc.co.za"; classtype:trojan-activity; sid:100004075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"detorre.es"; classtype:trojan-activity; sid:100004076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev-interestingtech.pantheonsite.io"; classtype:trojan-activity; sid:100004077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.sayse-tienda.com"; classtype:trojan-activity; sid:100004078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.sebpo.net"; classtype:trojan-activity; sid:100004079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfcf.91756.cn"; classtype:trojan-activity; sid:100004080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfsfcsfcdsfsdvcfsvcscv.com"; classtype:trojan-activity; sid:100004081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"diamantenegro.mi-fs.com"; classtype:trojan-activity; sid:100004082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dienmayminhhung.com"; classtype:trojan-activity; sid:100004083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digilib.dianhusada.ac.id"; classtype:trojan-activity; sid:100004084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"djking.f3322.net"; classtype:trojan-activity; sid:100004085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.1003b.56a.com"; classtype:trojan-activity; sid:100004086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.198424.com"; classtype:trojan-activity; sid:100004087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.installcdn-aws.com"; classtype:trojan-activity; sid:100004088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.packetstormsecurity.net"; classtype:trojan-activity; sid:100004089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.rina-roleplay.com"; classtype:trojan-activity; sid:100004090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.zkytech.com"; classtype:trojan-activity; sid:100004091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dns.cyberium.cc"; classtype:trojan-activity; sid:100004092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dockerupdate.anondns.net"; classtype:trojan-activity; sid:100004093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"docman.orientalservices.in"; classtype:trojan-activity; sid:100004094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dodsonimaging.com"; classtype:trojan-activity; sid:100004095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dokan.blueberrytec.com"; classtype:trojan-activity; sid:100004096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom-chel74.ru"; classtype:trojan-activity; sid:100004097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom.daf.free.fr"; classtype:trojan-activity; sid:100004098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doncedyhall.com"; classtype:trojan-activity; sid:100004099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donghobinhminh.com"; classtype:trojan-activity; sid:100004100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dongphuctop.com"; classtype:trojan-activity; sid:100004101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donwnloasecury.ath.cx"; classtype:trojan-activity; sid:100004102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosame.com"; classtype:trojan-activity; sid:100004103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosman.pl"; classtype:trojan-activity; sid:100004104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dovberger.com"; classtype:trojan-activity; sid:100004105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.flash-plays.com"; classtype:trojan-activity; sid:100004106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.pcclear.com"; classtype:trojan-activity; sid:100004107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.udashi.com"; classtype:trojan-activity; sid:100004108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.webbora.com"; classtype:trojan-activity; sid:100004109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down1.arpun.com"; classtype:trojan-activity; sid:100004110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.caihong.com"; classtype:trojan-activity; sid:100004111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.doumaibiji.cn"; classtype:trojan-activity; sid:100004112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.exrnybuf.cn"; classtype:trojan-activity; sid:100004113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.kaobeitu.com"; classtype:trojan-activity; sid:100004114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.pdf00.cn"; classtype:trojan-activity; sid:100004115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.rising.com.cn"; classtype:trojan-activity; sid:100004116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.skycn.com"; classtype:trojan-activity; sid:100004117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.zjsyawqj.cn"; classtype:trojan-activity; sid:100004118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"downloads.jxtsteel.cn"; classtype:trojan-activity; sid:100004119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dragonsknot.com"; classtype:trojan-activity; sid:100004120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drbaby.com.sa"; classtype:trojan-activity; sid:100004121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drohnen.ensenanzainteligente.com"; classtype:trojan-activity; sid:100004122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drools-moved.46999.n3.nabble.com"; classtype:trojan-activity; sid:100004123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drsha.innovativesolutions.mobi"; classtype:trojan-activity; sid:100004124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsenterprize.co.za"; classtype:trojan-activity; sid:100004125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsspainting.com"; classtype:trojan-activity; sid:100004126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"du-wizards.com"; classtype:trojan-activity; sid:100004127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duque.guantanameratravel.com"; classtype:trojan-activity; sid:100004128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dutapp.wisolve.co.za"; classtype:trojan-activity; sid:100004129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duvalcharter.dekitout.com"; classtype:trojan-activity; sid:100004130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dx.qqyewu.com"; classtype:trojan-activity; sid:100004131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dzinestudio87.co.uk"; classtype:trojan-activity; sid:100004132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e-commerce.saleensuporte.com.br"; classtype:trojan-activity; sid:100004133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e.sldov.ru"; classtype:trojan-activity; sid:100004134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ebruyatkin.com"; classtype:trojan-activity; sid:100004135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"econews.treegle.org"; classtype:trojan-activity; sid:100004136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"efficientegroup.com"; classtype:trojan-activity; sid:100004137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"elliot.newreadermedia.net"; classtype:trojan-activity; sid:100004138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"en.baoend.com"; classtype:trojan-activity; sid:100004139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enc-tech.com"; classtype:trojan-activity; sid:100004140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"endurotanzania.co.tz"; classtype:trojan-activity; sid:100004141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ennovate.elin.co.za"; classtype:trojan-activity; sid:100004142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enriquecendocomconsorcio.com.br"; classtype:trojan-activity; sid:100004143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"envios.petpienso.cl"; classtype:trojan-activity; sid:100004144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"equimination.ee"; classtype:trojan-activity; sid:100004145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"escola.probommar.org.br"; classtype:trojan-activity; sid:100004146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"esnconsultants.com"; classtype:trojan-activity; sid:100004147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"essentia.org.br"; classtype:trojan-activity; sid:100004148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eubanks7.com"; classtype:trojan-activity; sid:100004149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"evidencemarketing.ca"; classtype:trojan-activity; sid:100004150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exilum.com"; classtype:trojan-activity; sid:100004151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exitoalfaomega.co"; classtype:trojan-activity; sid:100004152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"extrovertoffers.com"; classtype:trojan-activity; sid:100004153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"f1sol.com"; classtype:trojan-activity; sid:100004154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"familydentist.site"; classtype:trojan-activity; sid:100004155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"farmaciasdrogaminas.com.br"; classtype:trojan-activity; sid:100004156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fate3.xyz"; classtype:trojan-activity; sid:100004157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"faveraprojects.com"; classtype:trojan-activity; sid:100004158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fc.co.mz"; classtype:trojan-activity; sid:100004159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"felicienne.nl"; classtype:trojan-activity; sid:100004160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fi.bonitastores.com"; classtype:trojan-activity; sid:100004161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files.martellexpress.us"; classtype:trojan-activity; sid:100004162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"final.makkahkmcc.com"; classtype:trojan-activity; sid:100004163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fineartgallerym.com"; classtype:trojan-activity; sid:100004164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fkd.derpcity.ru"; classtype:trojan-activity; sid:100004165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flintspin.com"; classtype:trojan-activity; sid:100004166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flyingbuddhadesign.com"; classtype:trojan-activity; sid:100004167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fmjplastering.co.uk"; classtype:trojan-activity; sid:100004168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fms.buladde.or.ug"; classtype:trojan-activity; sid:100004169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foothills.com.br"; classtype:trojan-activity; sid:100004170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"footweardirect.elin.co.za"; classtype:trojan-activity; sid:100004171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"forum.mdb.nu"; classtype:trojan-activity; sid:100004172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fotoobjetivo.com"; classtype:trojan-activity; sid:100004173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foundationrepairhoustontx.net"; classtype:trojan-activity; sid:100004174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foxeps.com.br"; classtype:trojan-activity; sid:100004175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freecnetdownload.com"; classtype:trojan-activity; sid:100004176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freedombookshop.tickme.lk"; classtype:trojan-activity; sid:100004177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freisites.com.br"; classtype:trojan-activity; sid:100004178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ftp.n3twork30cm.ml"; classtype:trojan-activity; sid:100004179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fullelectronica.com.ar"; classtype:trojan-activity; sid:100004180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"funletters.net"; classtype:trojan-activity; sid:100004181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fusionfiresolutions.com"; classtype:trojan-activity; sid:100004182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gametwogame.com"; classtype:trojan-activity; sid:100004183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garciadogshow.com"; classtype:trojan-activity; sid:100004184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow.myvnc.com"; classtype:trojan-activity; sid:100004185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow4.myvnc.com"; classtype:trojan-activity; sid:100004186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gbbulls.co.uk"; classtype:trojan-activity; sid:100004187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gcpc.co.id.chronoscurtain.com"; classtype:trojan-activity; sid:100004188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"generaldeviales.com"; classtype:trojan-activity; sid:100004189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfmodd1.webselffiles01.com"; classtype:trojan-activity; sid:100004190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfold1.webselffiles01.com"; classtype:trojan-activity; sid:100004191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghettohub.co.za"; classtype:trojan-activity; sid:100004192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghislain.dartois.pagesperso-orange.fr"; classtype:trojan-activity; sid:100004193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giadungg7.com"; classtype:trojan-activity; sid:100004194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giddos.ga"; classtype:trojan-activity; sid:100004195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gilliem.com"; classtype:trojan-activity; sid:100004196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"girotexuniformes.com"; classtype:trojan-activity; sid:100004197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giteletropical.com"; classtype:trojan-activity; sid:100004198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"globaltask.ar"; classtype:trojan-activity; sid:100004199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"glowinmedia.co.ke"; classtype:trojan-activity; sid:100004200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmtransformationacademy.com"; classtype:trojan-activity; sid:100004201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmvadmission.org"; classtype:trojan-activity; sid:100004202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnimelf.net"; classtype:trojan-activity; sid:100004203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnscrew.ro"; classtype:trojan-activity; sid:100004204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gold.investforex.id"; classtype:trojan-activity; sid:100004205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcake.co.id"; classtype:trojan-activity; sid:100004206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com"; classtype:trojan-activity; sid:100004207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com.au"; classtype:trojan-activity; sid:100004208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcupmortgage.com"; classtype:trojan-activity; sid:100004209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"golden-memories-funerals.yourpageserver.com"; classtype:trojan-activity; sid:100004210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldmen.in"; classtype:trojan-activity; sid:100004211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"grupoinmare.com"; classtype:trojan-activity; sid:100004212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gruposelt.000webhostapp.com"; classtype:trojan-activity; sid:100004213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gs.monerorx.com"; classtype:trojan-activity; sid:100004214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gulfac-house.com"; classtype:trojan-activity; sid:100004215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gvpcdpgc.edu.in"; classtype:trojan-activity; sid:100004216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"habbotips.free.fr"; classtype:trojan-activity; sid:100004217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hagebakken.no"; classtype:trojan-activity; sid:100004218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"harshraval.in"; classtype:trojan-activity; sid:100004219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hd11315.com"; classtype:trojan-activity; sid:100004220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hdkamera2003.hu"; classtype:trojan-activity; sid:100004221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hds.sz4h.com"; classtype:trojan-activity; sid:100004222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"healthy20.net"; classtype:trojan-activity; sid:100004223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"heavymaq.cl"; classtype:trojan-activity; sid:100004224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com"; classtype:trojan-activity; sid:100004225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hellogorgeous.com.au"; classtype:trojan-activity; sid:100004226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"help.hizuko.com"; classtype:trojan-activity; sid:100004227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"herchinfitout.com.sg"; classtype:trojan-activity; sid:100004228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hhaward.org"; classtype:trojan-activity; sid:100004229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandroadcoc.com"; classtype:trojan-activity; sid:100004230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandslasvegas.atakdev.com"; classtype:trojan-activity; sid:100004231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hindi.factsriver.com"; classtype:trojan-activity; sid:100004232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hiptool.net"; classtype:trojan-activity; sid:100004233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitpe.com"; classtype:trojan-activity; sid:100004234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitstation.nl"; classtype:trojan-activity; sid:100004235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hmpmall.co.kr"; classtype:trojan-activity; sid:100004236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoagietesting10.com"; classtype:trojan-activity; sid:100004237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoayeuthuong-my.sharepoint.com"; classtype:trojan-activity; sid:100004238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"homefindersolutions.com"; classtype:trojan-activity; sid:100004239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hongluosi.com"; classtype:trojan-activity; sid:100004240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hookedupboatclub.com"; classtype:trojan-activity; sid:100004241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostelkielce.com"; classtype:trojan-activity; sid:100004242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostzaa.com"; classtype:trojan-activity; sid:100004243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"houstonshutters.site"; classtype:trojan-activity; sid:100004244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hr2019.vrcom7.com"; classtype:trojan-activity; sid:100004245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hseda.com"; classtype:trojan-activity; sid:100004246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hsmwebapp.com"; classtype:trojan-activity; sid:100004247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"htownbars.com"; classtype:trojan-activity; sid:100004248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hubtech.co.za"; classtype:trojan-activity; sid:100004249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hunggiang.vn"; classtype:trojan-activity; sid:100004250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"husamiyahschool.com"; classtype:trojan-activity; sid:100004251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iam313.com"; classtype:trojan-activity; sid:100004252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"icon.shatangmu.cn"; classtype:trojan-activity; sid:100004253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idea-secure-login.com"; classtype:trojan-activity; sid:100004254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idilsoft.com"; classtype:trojan-activity; sid:100004255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idj.no"; classtype:trojan-activity; sid:100004256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idvindia.com"; classtype:trojan-activity; sid:100004257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iesanjosemonitos.edu.co"; classtype:trojan-activity; sid:100004258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ikexpert.com"; classtype:trojan-activity; sid:100004259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ilrafrica.com"; classtype:trojan-activity; sid:100004260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"images.jermiau.com"; classtype:trojan-activity; sid:100004261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"imbueautoworx.co.za"; classtype:trojan-activity; sid:100004262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incodimsa.com"; classtype:trojan-activity; sid:100004263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incrediblepixels.com"; classtype:trojan-activity; sid:100004264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incredicole.com"; classtype:trojan-activity; sid:100004265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infair.vn"; classtype:trojan-activity; sid:100004266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infovator.com"; classtype:trojan-activity; sid:100004267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"innatosbrand.com"; classtype:trojan-activity; sid:100004268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inodesthetotaldesigners.com"; classtype:trojan-activity; sid:100004269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inovations.searchkero.com"; classtype:trojan-activity; sid:100004270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inrajahmundry.co.in"; classtype:trojan-activity; sid:100004271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"insignificantfinecore.testmail4.repl.co"; classtype:trojan-activity; sid:100004272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"instantindialoan.com"; classtype:trojan-activity; sid:100004273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intellectsmart.in"; classtype:trojan-activity; sid:100004274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intersel-idf.org"; classtype:trojan-activity; sid:100004275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intuitiveideas.com.my"; classtype:trojan-activity; sid:100004276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inversiones.arrayanfinanciero.cl"; classtype:trojan-activity; sid:100004277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"invest.xpcorporative.com.br"; classtype:trojan-activity; sid:100004278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ipmes.ma"; classtype:trojan-activity; sid:100004279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iremart.es"; classtype:trojan-activity; sid:100004280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isaac.mikhailmotoringschool.com"; classtype:trojan-activity; sid:100004281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iscamenabe.com"; classtype:trojan-activity; sid:100004282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ismf.com.ng"; classtype:trojan-activity; sid:100004283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iso-dubai.net"; classtype:trojan-activity; sid:100004284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"israrulhaq.me"; classtype:trojan-activity; sid:100004285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isrorg.com"; classtype:trojan-activity; sid:100004286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isso.ps"; classtype:trojan-activity; sid:100004287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"it123.ru"; classtype:trojan-activity; sid:100004288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itc-demo.softgig.co.ke"; classtype:trojan-activity; sid:100004289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itconsultus.com.co"; classtype:trojan-activity; sid:100004290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamesjorgensen.newreadermedia.net"; classtype:trojan-activity; sid:100004291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamiekaylive.com"; classtype:trojan-activity; sid:100004292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamshed.pk"; classtype:trojan-activity; sid:100004293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jansen-heesch.nl"; classtype:trojan-activity; sid:100004294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jathra.co.uk"; classtype:trojan-activity; sid:100004295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jay.diamondrelationscrm.us"; classtype:trojan-activity; sid:100004296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jebs.net.au"; classtype:trojan-activity; sid:100004297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jeffdahlke.com"; classtype:trojan-activity; sid:100004298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jewsjuice.com"; classtype:trojan-activity; sid:100004299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jhayesconsulting.com"; classtype:trojan-activity; sid:100004300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jiaoyuzixun.cn"; classtype:trojan-activity; sid:100004301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jing-da.com.tw"; classtype:trojan-activity; sid:100004302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jmcomputacion.com.ar"; classtype:trojan-activity; sid:100004303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jmtc.91756.cn"; classtype:trojan-activity; sid:100004304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jnanbharati.com"; classtype:trojan-activity; sid:100004305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jobs.thebeessolution.com"; classtype:trojan-activity; sid:100004306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"joelbonissilver.com"; classtype:trojan-activity; sid:100004307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"join.cl8movement.co.za"; classtype:trojan-activity; sid:100004308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josegene.com"; classtype:trojan-activity; sid:100004309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josuarochoa.com"; classtype:trojan-activity; sid:100004310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jpwoodfordco.com"; classtype:trojan-activity; sid:100004311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jumpmanualjacobhiller.com"; classtype:trojan-activity; sid:100004312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jupiter.toxsl.in"; classtype:trojan-activity; sid:100004313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jurgensen.newreadermedia.net"; classtype:trojan-activity; sid:100004314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"justinscott.com.au"; classtype:trojan-activity; sid:100004315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kaizenjanitorial.com"; classtype:trojan-activity; sid:100004316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalawatihomes.com"; classtype:trojan-activity; sid:100004317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalpataru-elitus-mulund.thakkers.in"; classtype:trojan-activity; sid:100004318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"karer.by"; classtype:trojan-activity; sid:100004319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"katanvetov.co.il"; classtype:trojan-activity; sid:100004320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kbdom.com"; classtype:trojan-activity; sid:100004321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kensingtondriving.com"; classtype:trojan-activity; sid:100004322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kevinjewelry.com.co"; classtype:trojan-activity; sid:100004323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"keywatch.yourpageserver.com"; classtype:trojan-activity; sid:100004324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kingssa.co.za"; classtype:trojan-activity; sid:100004325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kjcpromo.com"; classtype:trojan-activity; sid:100004326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kleinendeli.co.za"; classtype:trojan-activity; sid:100004327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"korrectconceptservices.com"; classtype:trojan-activity; sid:100004328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ktb.sch.id"; classtype:trojan-activity; sid:100004329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kubatoglubaklava.com.tr"; classtype:trojan-activity; sid:100004330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kumaralok.in"; classtype:trojan-activity; sid:100004331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kwanfromhongkong.com"; classtype:trojan-activity; sid:100004332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kz.sldov.ru"; classtype:trojan-activity; sid:100004333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lacasadelosalebrijes.com"; classtype:trojan-activity; sid:100004334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ladylabonde.com"; classtype:trojan-activity; sid:100004335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lameguard.ru"; classtype:trojan-activity; sid:100004336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laodongnhat.vn"; classtype:trojan-activity; sid:100004337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laravel.pointersoftwares.com.br"; classtype:trojan-activity; sid:100004338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lasermobilesounds.co.uk"; classtype:trojan-activity; sid:100004339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lauratomismith.com"; classtype:trojan-activity; sid:100004340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lautarosanmiguel.com"; classtype:trojan-activity; sid:100004341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawforall.edu.lk"; classtype:trojan-activity; sid:100004342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lceventos.net"; classtype:trojan-activity; sid:100004343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ld.mediaget.com"; classtype:trojan-activity; sid:100004344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ldgcorp.com"; classtype:trojan-activity; sid:100004345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"learning.real-academy.net"; classtype:trojan-activity; sid:100004346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leasiacherise.com"; classtype:trojan-activity; sid:100004347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leczkregoslup.acelero.pl"; classtype:trojan-activity; sid:100004348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"legend.nu"; classtype:trojan-activity; sid:100004349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leluibuffet.com.br"; classtype:trojan-activity; sid:100004350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lestesteux.ca"; classtype:trojan-activity; sid:100004351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"libantravel.pl"; classtype:trojan-activity; sid:100004352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.arihantmbainstitute.ac.in"; classtype:trojan-activity; sid:100004353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.uib.ac.id"; classtype:trojan-activity; sid:100004354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lidoraggiodisole.it"; classtype:trojan-activity; sid:100004355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lifebeam.elin.co.za"; classtype:trojan-activity; sid:100004356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lindnerelektroanlagen.de"; classtype:trojan-activity; sid:100004357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"linkintec.cn"; classtype:trojan-activity; sid:100004358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"litroxlitro.com"; classtype:trojan-activity; sid:100004359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"livetrack.in"; classtype:trojan-activity; sid:100004360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lloydsindian.co.uk"; classtype:trojan-activity; sid:100004361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lm.stagingarea.co.za"; classtype:trojan-activity; sid:100004362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmaancha.co.il"; classtype:trojan-activity; sid:100004363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.cstdevs.com"; classtype:trojan-activity; sid:100004364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.login2.in"; classtype:trojan-activity; sid:100004365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmvirtualbookkeeping.com"; classtype:trojan-activity; sid:100004366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lnt-rejuve-360.thakkers.in"; classtype:trojan-activity; sid:100004367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"location-voitures.ma"; classtype:trojan-activity; sid:100004368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"login.trezor.com.stockfootagesindia.com"; classtype:trojan-activity; sid:100004369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"logotypfabriken.se"; classtype:trojan-activity; sid:100004370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotix.de"; classtype:trojan-activity; sid:100004371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotusanddragonfly.com"; classtype:trojan-activity; sid:100004372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.carrduci.com"; classtype:trojan-activity; sid:100004373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.definerisco.com"; classtype:trojan-activity; sid:100004374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.difusodesign.com"; classtype:trojan-activity; sid:100004375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.juancamilogarciareyes.com"; classtype:trojan-activity; sid:100004376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.tecnimasdecolombia.com.co"; classtype:trojan-activity; sid:100004377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ltc.typoten.com"; classtype:trojan-activity; sid:100004378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luckybrownie.com"; classtype:trojan-activity; sid:100004379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luminouspneuma.com"; classtype:trojan-activity; sid:100004380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luxomodels.com"; classtype:trojan-activity; sid:100004381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m-technics.kz"; classtype:trojan-activity; sid:100004382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m.estudiomoros.com.ar"; classtype:trojan-activity; sid:100004383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"madicon.co.za"; classtype:trojan-activity; sid:100004384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"magianegramagiablancayamarres.com"; classtype:trojan-activity; sid:100004385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.bs-eiendomme.co.za"; classtype:trojan-activity; sid:100004386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.golimoapp.com"; classtype:trojan-activity; sid:100004387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.jeffsono.org"; classtype:trojan-activity; sid:100004388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maksi.feb.unib.ac.id"; classtype:trojan-activity; sid:100004389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malaya.tv"; classtype:trojan-activity; sid:100004390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malwarecoding.github.io"; classtype:trojan-activity; sid:100004391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managed.oss-cn-beijing.aliyuncs.com"; classtype:trojan-activity; sid:100004392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managemysalon.in"; classtype:trojan-activity; sid:100004393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manantialesdelnorte.uy"; classtype:trojan-activity; sid:100004394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manhtien.net"; classtype:trojan-activity; sid:100004395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marcapinyo.ru"; classtype:trojan-activity; sid:100004396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mario-sunjic.com"; classtype:trojan-activity; sid:100004397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariobrown.net"; classtype:trojan-activity; sid:100004398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariotessarollo.com"; classtype:trojan-activity; sid:100004399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketinfosales.com"; classtype:trojan-activity; sid:100004400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketing.enexusgroup.com.au"; classtype:trojan-activity; sid:100004401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marksidfgs.ug"; classtype:trojan-activity; sid:100004402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"masjidhabeebiyarazviya.mysunni.com"; classtype:trojan-activity; sid:100004403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"materialescantu.com"; classtype:trojan-activity; sid:100004404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"matruchhaya.co.in"; classtype:trojan-activity; sid:100004405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mattysplayground.com"; classtype:trojan-activity; sid:100004406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxtox.com.pk"; classtype:trojan-activity; sid:100004407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbgrm.com"; classtype:trojan-activity; sid:100004408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbsolutions.ge"; classtype:trojan-activity; sid:100004409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mdasa.elin.co.za"; classtype:trojan-activity; sid:100004410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medevlb.org"; classtype:trojan-activity; sid:100004411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"media-server.skyinternet.com.pk"; classtype:trojan-activity; sid:100004412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mediamaster.co.za"; classtype:trojan-activity; sid:100004413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medianews.ge"; classtype:trojan-activity; sid:100004414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medistaffconsulting.com"; classtype:trojan-activity; sid:100004415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meeweb.com"; classtype:trojan-activity; sid:100004416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megamart.afnan-amc.com"; classtype:trojan-activity; sid:100004417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merbay.ru"; classtype:trojan-activity; sid:100004418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merkathink.com"; classtype:trojan-activity; sid:100004419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mertlog.com"; classtype:trojan-activity; sid:100004420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"metalin-cr.com"; classtype:trojan-activity; sid:100004421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mettaanand.org"; classtype:trojan-activity; sid:100004422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meuoculosnanet.com.br"; classtype:trojan-activity; sid:100004423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mfevr.com"; classtype:trojan-activity; sid:100004424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot.myvnc.com"; classtype:trojan-activity; sid:100004425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot80.myvnc.com"; classtype:trojan-activity; sid:100004426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"micalle.com.au"; classtype:trojan-activity; sid:100004427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michaelphilip.com"; classtype:trojan-activity; sid:100004428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michimal2.000webhostapp.com"; classtype:trojan-activity; sid:100004429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microblading.mirliandias.com.br"; classtype:trojan-activity; sid:100004430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microcomm-group.com"; classtype:trojan-activity; sid:100004431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mikhailmotoringschool.com"; classtype:trojan-activity; sid:100004432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mindfulbuildingandliving.com"; classtype:trojan-activity; sid:100004433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mingguanwms.com"; classtype:trojan-activity; sid:100004434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"minuevavida.org"; classtype:trojan-activity; sid:100004435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mirror.mypage.sk"; classtype:trojan-activity; sid:100004436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mis.nbcc.ac.th"; classtype:trojan-activity; sid:100004437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"misterson.com"; classtype:trojan-activity; sid:100004438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mixr.at"; classtype:trojan-activity; sid:100004439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mkontakt.az"; classtype:trojan-activity; sid:100004440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mktf.mx"; classtype:trojan-activity; sid:100004441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmogollon.com.mx"; classtype:trojan-activity; sid:100004442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mncarteam.com"; classtype:trojan-activity; sid:100004443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mobile.illumetechnology.com"; classtype:trojan-activity; sid:100004444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modelhouseturkey.com"; classtype:trojan-activity; sid:100004445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modernmanna.org"; classtype:trojan-activity; sid:100004446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"monetization.business"; classtype:trojan-activity; sid:100004447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moninediy.com"; classtype:trojan-activity; sid:100004448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mopai.sg"; classtype:trojan-activity; sid:100004449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"motorcomunicacion.com"; classtype:trojan-activity; sid:100004450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"msacontabil.com.br"; classtype:trojan-activity; sid:100004451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mtspsmjeli.sch.id"; classtype:trojan-activity; sid:100004452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"muzimbiti.xigubo.co.mz"; classtype:trojan-activity; sid:100004453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mxpiqw.am.files.1drv.com"; classtype:trojan-activity; sid:100004454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mydatebook.in"; classtype:trojan-activity; sid:100004455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mymlql.com"; classtype:trojan-activity; sid:100004456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myritz.vettickal.com"; classtype:trojan-activity; sid:100004457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myscape.in"; classtype:trojan-activity; sid:100004458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysura.it"; classtype:trojan-activity; sid:100004459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"namnyak.co.ke"; classtype:trojan-activity; sid:100004460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nap.mgsservers.com"; classtype:trojan-activity; sid:100004461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"navayurveda.in"; classtype:trojan-activity; sid:100004462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nbs.vizzhost.com"; classtype:trojan-activity; sid:100004463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nec-i.com"; classtype:trojan-activity; sid:100004464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nelitrianggraeni.000webhostapp.com"; classtype:trojan-activity; sid:100004465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nerve.untergrund.net"; classtype:trojan-activity; sid:100004466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nettube.com.br"; classtype:trojan-activity; sid:100004467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"networkwheels.co.za"; classtype:trojan-activity; sid:100004468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neuromedic.com.br"; classtype:trojan-activity; sid:100004469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neverseenshop.com.mx"; classtype:trojan-activity; sid:100004470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newinfinitysynergy.com"; classtype:trojan-activity; sid:100004471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"news.dbstrony.pl"; classtype:trojan-activity; sid:100004472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtreedesign.co.uk"; classtype:trojan-activity; sid:100004473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtrendeg.com"; classtype:trojan-activity; sid:100004474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newvisionopticallab.com"; classtype:trojan-activity; sid:100004475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newxing.com"; classtype:trojan-activity; sid:100004476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nextdigitalday.ru"; classtype:trojan-activity; sid:100004477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ngdaycare.co.za"; classtype:trojan-activity; sid:100004478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nguyenkekhuyen.com"; classtype:trojan-activity; sid:100004479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nhorangtreem.com"; classtype:trojan-activity; sid:100004480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nicolas.ug"; classtype:trojan-activity; sid:100004481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nidhi.iexist.in"; classtype:trojan-activity; sid:100004482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nikanpolimer.ir"; classtype:trojan-activity; sid:100004483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilehouse.co.ug"; classtype:trojan-activity; sid:100004484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilinkeji.com"; classtype:trojan-activity; sid:100004485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nisacooks.com"; classtype:trojan-activity; sid:100004486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"njtiledesigncenter.com"; classtype:trojan-activity; sid:100004487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nobius.org"; classtype:trojan-activity; sid:100004488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nocalnoodle.elin.co.za"; classtype:trojan-activity; sid:100004489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nomadicbees.com"; classtype:trojan-activity; sid:100004490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nonnarina.ax"; classtype:trojan-activity; sid:100004491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"notamuzikaletleri.com"; classtype:trojan-activity; sid:100004492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ns1.the-widyantos.com"; classtype:trojan-activity; sid:100004493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsb.org.uk"; classtype:trojan-activity; sid:100004494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsheldon.co.uk"; classtype:trojan-activity; sid:100004495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nuthuassociates.com"; classtype:trojan-activity; sid:100004496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nuwagi.com"; classtype:trojan-activity; sid:100004497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyeh2o.com.au"; classtype:trojan-activity; sid:100004498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oakleyandfriends.co.uk"; classtype:trojan-activity; sid:100004499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"obseques-conseils.com"; classtype:trojan-activity; sid:100004500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ocean.tecnasulstore.com.br"; classtype:trojan-activity; sid:100004501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohe.ie"; classtype:trojan-activity; sid:100004502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohsewgorgeous.co.uk"; classtype:trojan-activity; sid:100004503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oknoplastik.sk"; classtype:trojan-activity; sid:100004504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oleholeh.memangbeda.website"; classtype:trojan-activity; sid:100004505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"olirecords.mixture.ltd"; classtype:trojan-activity; sid:100004506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"olooom.com"; classtype:trojan-activity; sid:100004507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaia.org"; classtype:trojan-activity; sid:100004508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaromatic.com"; classtype:trojan-activity; sid:100004509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omega.az"; classtype:trojan-activity; sid:100004510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oms.pappai.com"; classtype:trojan-activity; sid:100004511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omscoc.pappai.com"; classtype:trojan-activity; sid:100004512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedigitalcard.granvizionnecorp.com"; classtype:trojan-activity; sid:100004513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedrive.listifyapp.co"; classtype:trojan-activity; sid:100004514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"online.creedglobal.in"; classtype:trojan-activity; sid:100004515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onlinestatis.bar"; classtype:trojan-activity; sid:100004516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ont.proman.id"; classtype:trojan-activity; sid:100004517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"open.warehousesaas.co.uk"; classtype:trojan-activity; sid:100004518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opolis.io"; classtype:trojan-activity; sid:100004519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opticaoptigral.cl"; classtype:trojan-activity; sid:100004520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optimus.com.sg"; classtype:trojan-activity; sid:100004521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optitechsa.co.za"; classtype:trojan-activity; sid:100004522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"order.bizpeed.com"; classtype:trojan-activity; sid:100004523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orientgatewayltd.com"; classtype:trojan-activity; sid:100004524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orion445.com"; classtype:trojan-activity; sid:100004525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orpod.ru"; classtype:trojan-activity; sid:100004526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oserve.pk"; classtype:trojan-activity; sid:100004527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ottimade.com"; classtype:trojan-activity; sid:100004528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ourteam.searchkero.com"; classtype:trojan-activity; sid:100004529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ozemag.com"; classtype:trojan-activity; sid:100004530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p1.lingpao8.com"; classtype:trojan-activity; sid:100004531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p3.zbjimg.com"; classtype:trojan-activity; sid:100004532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p6.zbjimg.com"; classtype:trojan-activity; sid:100004533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pablobrothel.com.ar"; classtype:trojan-activity; sid:100004534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacificgroup.ws"; classtype:trojan-activity; sid:100004535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacwebdesigns.com"; classtype:trojan-activity; sid:100004536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pagos.krayem.com.mx"; classtype:trojan-activity; sid:100004537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"palochusvet.szm.com"; classtype:trojan-activity; sid:100004538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parallel.rockvideos.at"; classtype:trojan-activity; sid:100004539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parejasfelices.mi-fs.com"; classtype:trojan-activity; sid:100004540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parkhussion.com"; classtype:trojan-activity; sid:100004541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pastorpaulocosta.com"; classtype:trojan-activity; sid:100004542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.51lg.com"; classtype:trojan-activity; sid:100004543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.99ddd.com"; classtype:trojan-activity; sid:100004544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch3.99ddd.com"; classtype:trojan-activity; sid:100004545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paths.elin.co.za"; classtype:trojan-activity; sid:100004546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paulmercier.biz"; classtype:trojan-activity; sid:100004547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payerrealty.com"; classtype:trojan-activity; sid:100004548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payments.atifsiddiqui.me"; classtype:trojan-activity; sid:100004549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pcsoori.com"; classtype:trojan-activity; sid:100004550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pd.oceaniarp.net"; classtype:trojan-activity; sid:100004551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpus.onlineman7-jombang.sch.id"; classtype:trojan-activity; sid:100004552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpustekim.untirta.ac.id"; classtype:trojan-activity; sid:100004553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"petercollie.com"; classtype:trojan-activity; sid:100004554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ph4s.ru"; classtype:trojan-activity; sid:100004555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phasdesign.com"; classtype:trojan-activity; sid:100004556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phenhuong.sanpham.online"; classtype:trojan-activity; sid:100004557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phittc.com"; classtype:trojan-activity; sid:100004558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photo360.kubooking.com"; classtype:trojan-activity; sid:100004559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photographytipsclub.com"; classtype:trojan-activity; sid:100004560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pink99.com"; classtype:trojan-activity; sid:100004561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pizzabarletta.com.br"; classtype:trojan-activity; sid:100004562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"plasfan.ind.br"; classtype:trojan-activity; sid:100004563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pmglance.startwriteup.com"; classtype:trojan-activity; sid:100004564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pokojewewladyslawowie.pl"; classtype:trojan-activity; sid:100004565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pole.com.vc"; classtype:trojan-activity; sid:100004566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pool.phxdir.com"; classtype:trojan-activity; sid:100004567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pooltablemoversdenver.net"; classtype:trojan-activity; sid:100004568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"posmicrosystems.com"; classtype:trojan-activity; sid:100004569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"poulman.panagiotopoulos-tours.gr"; classtype:trojan-activity; sid:100004570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ppdb.smk-ciptaskill.sch.id"; classtype:trojan-activity; sid:100004571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pptvideotemplates.com"; classtype:trojan-activity; sid:100004572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestigehomeautomation.net"; classtype:trojan-activity; sid:100004573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prishaartcreations.com"; classtype:trojan-activity; sid:100004574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"production.sparshims.com"; classtype:trojan-activity; sid:100004575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"programaoperadoronline.com.br"; classtype:trojan-activity; sid:100004576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"project.exquitec.com"; classtype:trojan-activity; sid:100004577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promotoradescomplica.com.br"; classtype:trojan-activity; sid:100004578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promoversdubai.com"; classtype:trojan-activity; sid:100004579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq.elin.co.za"; classtype:trojan-activity; sid:100004580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq2.elin.co.za"; classtype:trojan-activity; sid:100004581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosoc.nl"; classtype:trojan-activity; sid:100004582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosyarmakassar.com"; classtype:trojan-activity; sid:100004583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"provence.elin.co.za"; classtype:trojan-activity; sid:100004584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prueba.danielluza.com"; classtype:trojan-activity; sid:100004585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ptpmeccatronica.eu"; classtype:trojan-activity; sid:100004586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pujashoppe.in"; classtype:trojan-activity; sid:100004587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punchdialogues.com"; classtype:trojan-activity; sid:100004588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punjabdevelopersassociation.com.pk"; classtype:trojan-activity; sid:100004589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"purefoe.top"; classtype:trojan-activity; sid:100004590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pvcprinting.co.uk"; classtype:trojan-activity; sid:100004591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qadir.tickfa.ir"; classtype:trojan-activity; sid:100004592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qatarglobalconsulting.com"; classtype:trojan-activity; sid:100004593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qmsled.com"; classtype:trojan-activity; sid:100004594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"quartier-midi.be"; classtype:trojan-activity; sid:100004595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"querocar.com"; classtype:trojan-activity; sid:100004596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rachmat-assuhaimi.my.id"; classtype:trojan-activity; sid:100004597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rainbowisp.info"; classtype:trojan-activity; sid:100004598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raodigitalmedia.com"; classtype:trojan-activity; sid:100004599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rarlabarchiver.ac"; classtype:trojan-activity; sid:100004600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rasadbar.ir"; classtype:trojan-activity; sid:100004601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rashika.ascarvalho.co.za"; classtype:trojan-activity; sid:100004602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ratemyfenancialadvisor.com"; classtype:trojan-activity; sid:100004603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ravenproductionsltd.com"; classtype:trojan-activity; sid:100004604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rc.ixiaoyang.cn"; classtype:trojan-activity; sid:100004605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rcmesilva.charbelsales.com.br"; classtype:trojan-activity; sid:100004606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"readymmade.com"; classtype:trojan-activity; sid:100004607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redchillicrackers.com"; classtype:trojan-activity; sid:100004608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reifenquick.de"; classtype:trojan-activity; sid:100004609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"relaxindulge.co.nz"; classtype:trojan-activity; sid:100004610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"renehavis.com.ua"; classtype:trojan-activity; sid:100004611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"repatriacioncolombia.com"; classtype:trojan-activity; sid:100004612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"res.uf1.cn"; classtype:trojan-activity; sid:100004613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.digimitra.in"; classtype:trojan-activity; sid:100004614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"resuco.net"; classtype:trojan-activity; sid:100004615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rezkabum.ru"; classtype:trojan-activity; sid:100004616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rhema.com.sg"; classtype:trojan-activity; sid:100004617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richancyber.info"; classtype:trojan-activity; sid:100004618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richmondminerals.co.zm"; classtype:trojan-activity; sid:100004619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinaefoundation.org.za"; classtype:trojan-activity; sid:100004620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinkaisystem-ht.com"; classtype:trojan-activity; sid:100004621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"riverfox.co.za"; classtype:trojan-activity; sid:100004622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkcable.co.in"; classtype:trojan-activity; sid:100004623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkverify.securestudies.com"; classtype:trojan-activity; sid:100004624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roadfurylifts.com"; classtype:trojan-activity; sid:100004625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertmcardle.com"; classtype:trojan-activity; sid:100004626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertsinclair.net"; classtype:trojan-activity; sid:100004627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robinhood-sports.com"; classtype:trojan-activity; sid:100004628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"romanianpoints.com"; classtype:trojan-activity; sid:100004629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ronnietucker.co.uk"; classtype:trojan-activity; sid:100004630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roomsvc.servegate.kr"; classtype:trojan-activity; sid:100004631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshan.academy"; classtype:trojan-activity; sid:100004632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshnijewellery.com"; classtype:trojan-activity; sid:100004633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rs-toolkit.mikestclair.org"; classtype:trojan-activity; sid:100004634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rsgym.net"; classtype:trojan-activity; sid:100004635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubazar.pro"; classtype:trojan-activity; sid:100004636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubycityvietnam.com"; classtype:trojan-activity; sid:100004637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruch.newreadermedia.net"; classtype:trojan-activity; sid:100004638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruisgood.ru"; classtype:trojan-activity; sid:100004639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruwadalkuwait.com"; classtype:trojan-activity; sid:100004640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rydchile.cl"; classtype:trojan-activity; sid:100004641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rzminc.com"; classtype:trojan-activity; sid:100004642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.51shijuan.com"; classtype:trojan-activity; sid:100004643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.thechinesemuslim.com"; classtype:trojan-activity; sid:100004644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sacredscentsonline.com"; classtype:trojan-activity; sid:100004645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safcol-colors.com"; classtype:trojan-activity; sid:100004646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safehubsecurity.ca"; classtype:trojan-activity; sid:100004647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safety.nanotechproautocare.com"; classtype:trojan-activity; sid:100004648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sahathaikasetpan.com"; classtype:trojan-activity; sid:100004649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"saisoftwareinc.com"; classtype:trojan-activity; sid:100004650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salecorner.yourpageserver.com"; classtype:trojan-activity; sid:100004651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sandovalgraphics.com"; classtype:trojan-activity; sid:100004652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"santyago.org"; classtype:trojan-activity; sid:100004653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sarakem.cl"; classtype:trojan-activity; sid:100004654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sasystemsuk.com"; classtype:trojan-activity; sid:100004655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"savasaachi.systems"; classtype:trojan-activity; sid:100004656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scarfaceindustries.com"; classtype:trojan-activity; sid:100004657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scglobal.co.th"; classtype:trojan-activity; sid:100004658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schalke04rss.de"; classtype:trojan-activity; sid:100004659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scheff.com"; classtype:trojan-activity; sid:100004660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schoolbustracker.softgig.co.ke"; classtype:trojan-activity; sid:100004661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sec-doc-w.com"; classtype:trojan-activity; sid:100004662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"secure-doc-reader.com"; classtype:trojan-activity; sid:100004663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"segalsmetals.elin.co.za"; classtype:trojan-activity; sid:100004664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sellmyphonela.com"; classtype:trojan-activity; sid:100004665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"selltechtoday.com"; classtype:trojan-activity; sid:100004666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"senbiaojita.com"; classtype:trojan-activity; sid:100004667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sentierodelviandante.ml"; classtype:trojan-activity; sid:100004668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serendibsourcing.com"; classtype:trojan-activity; sid:100004669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd.myvnc.com"; classtype:trojan-activity; sid:100004670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd80.myvnc.com"; classtype:trojan-activity; sid:100004671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"seyranikenger.com.tr"; classtype:trojan-activity; sid:100004672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sgessy.com.br"; classtype:trojan-activity; sid:100004673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shaheentbfoundation.com"; classtype:trojan-activity; sid:100004674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahikhana.cstdevs.com"; classtype:trojan-activity; sid:100004675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharkrigs.com"; classtype:trojan-activity; sid:100004676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharpelevators.in"; classtype:trojan-activity; sid:100004677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shembefoundation.com"; classtype:trojan-activity; sid:100004678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shivakunwar.com.np"; classtype:trojan-activity; sid:100004679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shoblasaathitrust.org"; classtype:trojan-activity; sid:100004680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shooka-co.com"; classtype:trojan-activity; sid:100004681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shop.goldspot.agency"; classtype:trojan-activity; sid:100004682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shopsofe.com"; classtype:trojan-activity; sid:100004683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shrushtiinfotech.com"; classtype:trojan-activity; sid:100004684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sibernetix.fr"; classtype:trojan-activity; sid:100004685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siddharthpanditpautra.com"; classtype:trojan-activity; sid:100004686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sige.brisainformatica.com.br"; classtype:trojan-activity; sid:100004687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"signatureads.co.in"; classtype:trojan-activity; sid:100004688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siili.net"; classtype:trojan-activity; sid:100004689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simoneporzi.it"; classtype:trojan-activity; sid:100004690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simplithy.co.uk"; classtype:trojan-activity; sid:100004691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindicato1ucm.cl"; classtype:trojan-activity; sid:100004692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindpol.tiejuris.com.br"; classtype:trojan-activity; sid:100004693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sinergidwireka.com"; classtype:trojan-activity; sid:100004694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sipahielektrik.com"; classtype:trojan-activity; sid:100004695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siperb.in"; classtype:trojan-activity; sid:100004696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sistelligent.com"; classtype:trojan-activity; sid:100004697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skkksolo.beweiretail.com"; classtype:trojan-activity; sid:100004698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyflyfares.com"; classtype:trojan-activity; sid:100004699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyscan.com"; classtype:trojan-activity; sid:100004700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarthouseforum.ru"; classtype:trojan-activity; sid:100004701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarts.tj"; classtype:trojan-activity; sid:100004702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smartzedu.com"; classtype:trojan-activity; sid:100004703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokeandgrowrichtour.com"; classtype:trojan-activity; sid:100004704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokesolutionindia.com"; classtype:trojan-activity; sid:100004705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobethuacademy.com"; classtype:trojan-activity; sid:100004706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.110route.com"; classtype:trojan-activity; sid:100004707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.officelabo.net"; classtype:trojan-activity; sid:100004708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sohs.conceptechs.info"; classtype:trojan-activity; sid:100004709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solar.amazingtribe.lk"; classtype:trojan-activity; sid:100004710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solo2.dbstrony.pl"; classtype:trojan-activity; sid:100004711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somcorbera.cat"; classtype:trojan-activity; sid:100004712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somir.com.mx"; classtype:trojan-activity; sid:100004713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soralapps.com"; classtype:trojan-activity; sid:100004714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sorteio.orgaostalita.com.br"; classtype:trojan-activity; sid:100004715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sota-france.fr"; classtype:trojan-activity; sid:100004716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sowingminerals.cl"; classtype:trojan-activity; sid:100004717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"space.proactint.org"; classtype:trojan-activity; sid:100004718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spaceframe.mobi.space-frame.co.za"; classtype:trojan-activity; sid:100004719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"special-key.cf"; classtype:trojan-activity; sid:100004720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spent.com.pl"; classtype:trojan-activity; sid:100004721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spetsesyachtcharter.gr"; classtype:trojan-activity; sid:100004722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spititourism.com"; classtype:trojan-activity; sid:100004723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spittinfire.com"; classtype:trojan-activity; sid:100004724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sports-net.de"; classtype:trojan-activity; sid:100004725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"src1.minibai.com"; classtype:trojan-activity; sid:100004726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sreenivasapaintingworks.com"; classtype:trojan-activity; sid:100004727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sriglobalit.com"; classtype:trojan-activity; sid:100004728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srvmanos.no-ip.info"; classtype:trojan-activity; sid:100004729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ss.monita.co.id"; classtype:trojan-activity; sid:100004730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"staging.apparelpunch.com"; classtype:trojan-activity; sid:100004731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"starcountry.net"; classtype:trojan-activity; sid:100004732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"static.3001.net"; classtype:trojan-activity; sid:100004733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statsres.com"; classtype:trojan-activity; sid:100004734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statssound.com"; classtype:trojan-activity; sid:100004735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statsspot.com"; classtype:trojan-activity; sid:100004736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stattilion.bar"; classtype:trojan-activity; sid:100004737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiepancasetia.ac.id"; classtype:trojan-activity; sid:100004738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stott-thompson.co.uk"; classtype:trojan-activity; sid:100004739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stratexec.co.za"; classtype:trojan-activity; sid:100004740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"streetdemo.yourpageserver.com"; classtype:trojan-activity; sid:100004741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"suboldesign.com"; classtype:trojan-activity; sid:100004742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sumerians.org"; classtype:trojan-activity; sid:100004743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunbrero.com.au"; classtype:trojan-activity; sid:100004744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunmarkholidays.com"; classtype:trojan-activity; sid:100004745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supermercadostia.com"; classtype:trojan-activity; sid:100004746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support-4-free.com"; classtype:trojan-activity; sid:100004747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support.clz.kr"; classtype:trojan-activity; sid:100004748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sw.yourpageserver.com"; classtype:trojan-activity; sid:100004749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweaty.dk"; classtype:trojan-activity; sid:100004750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweet-diet.com"; classtype:trojan-activity; sid:100004751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swentsai.com"; classtype:trojan-activity; sid:100004752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swiftlogisticseg.com"; classtype:trojan-activity; sid:100004753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swwbia.com"; classtype:trojan-activity; sid:100004754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"syedpro.dezinetimes.com"; classtype:trojan-activity; sid:100004755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"syracusecoffee.com"; classtype:trojan-activity; sid:100004756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sys.pbmadu.co.id"; classtype:trojan-activity; sid:100004757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sytraders.co"; classtype:trojan-activity; sid:100004758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.honker.info"; classtype:trojan-activity; sid:100004759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.netcatkit.com"; classtype:trojan-activity; sid:100004760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tacticohosting.com"; classtype:trojan-activity; sid:100004761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tadoo.ca"; classtype:trojan-activity; sid:100004762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tafsantoursandtravels.com"; classtype:trojan-activity; sid:100004763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tallyinvoicecustomization.com"; classtype:trojan-activity; sid:100004764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taltus.co.uk"; classtype:trojan-activity; sid:100004765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tapalkoedacoffee.com"; classtype:trojan-activity; sid:100004766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tarravalleyfoods.com.au"; classtype:trojan-activity; sid:100004767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taurus.ug"; classtype:trojan-activity; sid:100004768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taxicabsrilanka.com"; classtype:trojan-activity; sid:100004769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taxpos.com"; classtype:trojan-activity; sid:100004770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tc.snpsresidential.com"; classtype:trojan-activity; sid:100004771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tcy.198424.com"; classtype:trojan-activity; sid:100004772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tdsp.yngw518.com"; classtype:trojan-activity; sid:100004773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"techgms.com"; classtype:trojan-activity; sid:100004774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"technogreen.crmmanivela.com"; classtype:trojan-activity; sid:100004775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"technohub.searchkero.com"; classtype:trojan-activity; sid:100004776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tecnicaencolectores.com.mx"; classtype:trojan-activity; sid:100004777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tecnologyschool.com"; classtype:trojan-activity; sid:100004778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teduae.com"; classtype:trojan-activity; sid:100004779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teleargentina.com"; classtype:trojan-activity; sid:100004780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telescopelms.com"; classtype:trojan-activity; sid:100004781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telmed.cl"; classtype:trojan-activity; sid:100004782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"temptmag.com"; classtype:trojan-activity; sid:100004783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tentandoserfitness.000webhostapp.com"; classtype:trojan-activity; sid:100004784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.adventser.com"; classtype:trojan-activity; sid:100004785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.letraele.es"; classtype:trojan-activity; sid:100004786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.typoten.com"; classtype:trojan-activity; sid:100004787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.wanepghana.org"; classtype:trojan-activity; sid:100004788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.milenial.id"; classtype:trojan-activity; sid:100004789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.tenplusone.my"; classtype:trojan-activity; sid:100004790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.basis-web.com"; classtype:trojan-activity; sid:100004791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.marrenconstruction.ie"; classtype:trojan-activity; sid:100004792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.clickitsolutionsmw.com"; classtype:trojan-activity; sid:100004793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.thinkingcorp.in"; classtype:trojan-activity; sid:100004794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testnew.yourpageserver.com"; classtype:trojan-activity; sid:100004795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teteaffiche.stephanebillon.com"; classtype:trojan-activity; sid:100004796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tewoerd.eu"; classtype:trojan-activity; sid:100004797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"textile.softberg.ro"; classtype:trojan-activity; sid:100004798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"texturesbyvinita.com"; classtype:trojan-activity; sid:100004799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tharringtonsponsorship.com"; classtype:trojan-activity; sid:100004800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecleaningladiespdx.com"; classtype:trojan-activity; sid:100004801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecreativecafe.co.uk"; classtype:trojan-activity; sid:100004802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefuturelife.in"; classtype:trojan-activity; sid:100004803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehighlightinterior.com"; classtype:trojan-activity; sid:100004804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehouseofpragya.com"; classtype:trojan-activity; sid:100004805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thekassia.co.uk"; classtype:trojan-activity; sid:100004806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thelaunchpadteam.com"; classtype:trojan-activity; sid:100004807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thesummitpc.net"; classtype:trojan-activity; sid:100004808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theurbantutors.com"; classtype:trojan-activity; sid:100004809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thosewebbs.com"; classtype:trojan-activity; sid:100004810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tianangdep.com"; classtype:trojan-activity; sid:100004811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickfood.tickme.lk"; classtype:trojan-activity; sid:100004812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickjobs.tickme.lk"; classtype:trojan-activity; sid:100004813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickmart.tickme.lk"; classtype:trojan-activity; sid:100004814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"timegonebuy.com"; classtype:trojan-activity; sid:100004815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tksb.net"; classtype:trojan-activity; sid:100004816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tlcc.com.gt"; classtype:trojan-activity; sid:100004817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"todoapp.cstdevs.com"; classtype:trojan-activity; sid:100004818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonydong.com"; classtype:trojan-activity; sid:100004819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonyzone.com"; classtype:trojan-activity; sid:100004820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tooba.tenplusone.my"; classtype:trojan-activity; sid:100004821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topcell9.com"; classtype:trojan-activity; sid:100004822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topicsnepal.com"; classtype:trojan-activity; sid:100004823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toplevel.com.br"; classtype:trojan-activity; sid:100004824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"torresquinterocorp.com"; classtype:trojan-activity; sid:100004825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"towme.services"; classtype:trojan-activity; sid:100004826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toyotacollege.ac.th"; classtype:trojan-activity; sid:100004827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpef.lsoftdemo.com"; classtype:trojan-activity; sid:100004828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpke.hu"; classtype:trojan-activity; sid:100004829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tradezone.ejuicysolutions.com"; classtype:trojan-activity; sid:100004830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"translaterjemah.com"; classtype:trojan-activity; sid:100004831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"travelwithmanta.co.za"; classtype:trojan-activity; sid:100004832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trezors.io.mahlongwa.com"; classtype:trojan-activity; sid:100004833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"triplonet.com.br"; classtype:trojan-activity; sid:100004834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"troki.com.co"; classtype:trojan-activity; sid:100004835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tropics.codeleek.net"; classtype:trojan-activity; sid:100004836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trucks.softwarenecessities.com"; classtype:trojan-activity; sid:100004837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trudelfavreau.com"; classtype:trojan-activity; sid:100004838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tsd.jxwan.com"; classtype:trojan-activity; sid:100004839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tulli.info"; classtype:trojan-activity; sid:100004840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tupperware.michaelroberge.ca"; classtype:trojan-activity; sid:100004841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"turanggaresources.com"; classtype:trojan-activity; sid:100004842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uat.indianfilmzone.com"; classtype:trojan-activity; sid:100004843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ublretailerdemo.cstdevs.com"; classtype:trojan-activity; sid:100004844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uc-56.ru"; classtype:trojan-activity; sid:100004845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"udesk.searchkero.com"; classtype:trojan-activity; sid:100004846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ugprs-ubih.org"; classtype:trojan-activity; sid:100004847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ultimate-24.de"; classtype:trojan-activity; sid:100004848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"umwelt-kirchhof.de"; classtype:trojan-activity; sid:100004849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unicorpbrunei.com"; classtype:trojan-activity; sid:100004850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uniengrisb.com"; classtype:trojan-activity; sid:100004851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unisoftcc.com"; classtype:trojan-activity; sid:100004852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unyazitelecom.com"; classtype:trojan-activity; sid:100004853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"upcbpta.com"; classtype:trojan-activity; sid:100004854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"urbane.dezinetimes.com"; classtype:trojan-activity; sid:100004855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"useformoney.000webhostapp.com"; classtype:trojan-activity; sid:100004856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"usmadetshirts.com"; classtype:trojan-activity; sid:100004857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uss.ac.th"; classtype:trojan-activity; sid:100004858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uzzepay.com.br"; classtype:trojan-activity; sid:100004859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vbcargo.hu"; classtype:trojan-activity; sid:100004860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vcah.co.uk"; classtype:trojan-activity; sid:100004861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vegadelcasero.cl"; classtype:trojan-activity; sid:100004862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vendas.lidiacarmeli.com.br"; classtype:trojan-activity; sid:100004863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"verify.aicosoft.com"; classtype:trojan-activity; sid:100004864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vfocus.net"; classtype:trojan-activity; sid:100004865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vidmattic.com"; classtype:trojan-activity; sid:100004866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vienen.gblix.srv.br"; classtype:trojan-activity; sid:100004867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villamarand.com"; classtype:trojan-activity; sid:100004868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villatera.com"; classtype:trojan-activity; sid:100004869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"violinstop.com"; classtype:trojan-activity; sid:100004870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viraltalking.com"; classtype:trojan-activity; sid:100004871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visions.alnisamart.com"; classtype:trojan-activity; sid:100004872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visualhome.cl"; classtype:trojan-activity; sid:100004873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vitoriamodaintima.com.br"; classtype:trojan-activity; sid:100004874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vivationdesign.com"; classtype:trojan-activity; sid:100004875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viveirodoiscorregos.com.br"; classtype:trojan-activity; sid:100004876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vksales.com"; classtype:trojan-activity; sid:100004877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vladimirinternational.com"; classtype:trojan-activity; sid:100004878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vokasi.ub.ac.id"; classtype:trojan-activity; sid:100004879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vologroup.com.br"; classtype:trojan-activity; sid:100004880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"voteyouramerica.dekitout.com"; classtype:trojan-activity; sid:100004881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vstsample.com"; classtype:trojan-activity; sid:100004882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vtube.fadlymotivator.com"; classtype:trojan-activity; sid:100004883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vvsskmodinationalschool.com"; classtype:trojan-activity; sid:100004884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepliberia.org"; classtype:trojan-activity; sid:100004885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepniger.org"; classtype:trojan-activity; sid:100004886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weareactum.com"; classtype:trojan-activity; sid:100004887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.eng.ubu.ac.th"; classtype:trojan-activity; sid:100004888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geetle.ga"; classtype:trojan-activity; sid:100004889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geomegasoft.net"; classtype:trojan-activity; sid:100004890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.newinnovationtechnology.com"; classtype:trojan-activity; sid:100004891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.smarts-works.com"; classtype:trojan-activity; sid:100004892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.thebeessolution.com"; classtype:trojan-activity; sid:100004893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webgis.perumdasolo.com"; classtype:trojan-activity; sid:100004894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; classtype:trojan-activity; sid:100004895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webpresario.com"; classtype:trojan-activity; sid:100004896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"website-work.com"; classtype:trojan-activity; sid:100004897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weinsteincounseling.com"; classtype:trojan-activity; sid:100004898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wexfashion.com"; classtype:trojan-activity; sid:100004899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whcms.yourpageserver.com"; classtype:trojan-activity; sid:100004900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteglovetailgate.com"; classtype:trojan-activity; sid:100004901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteresponse.com"; classtype:trojan-activity; sid:100004902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wi522012.ferozo.com"; classtype:trojan-activity; sid:100004903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wikalen.co.za"; classtype:trojan-activity; sid:100004904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildnights.co.uk"; classtype:trojan-activity; sid:100004905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildtrust.mediadevstaging.com"; classtype:trojan-activity; sid:100004906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wimbamusica.com"; classtype:trojan-activity; sid:100004907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"windcomtechnologies.com"; classtype:trojan-activity; sid:100004908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wishesconcierge.com"; classtype:trojan-activity; sid:100004909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woezon.agency"; classtype:trojan-activity; sid:100004910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wolfgang-brodte.de"; classtype:trojan-activity; sid:100004911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woodsytech.com"; classtype:trojan-activity; sid:100004912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wordpress.saleensuporte.com.br"; classtype:trojan-activity; sid:100004913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wozata.000webhostapp.com"; classtype:trojan-activity; sid:100004914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wp.readhere.in"; classtype:trojan-activity; sid:100004915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wpdemo.101clients.com.au"; classtype:trojan-activity; sid:100004916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"writtendeer.com"; classtype:trojan-activity; sid:100004917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ws5588.f3322.net"; classtype:trojan-activity; sid:100004918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wyklej.pl"; classtype:trojan-activity; sid:100004919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"x2vn.com"; classtype:trojan-activity; sid:100004920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xia.beihaixue.com"; classtype:trojan-activity; sid:100004921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xixaoclothing.com"; classtype:trojan-activity; sid:100004922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xk.996is.com"; classtype:trojan-activity; sid:100004923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--80akinnkiib6h.xn--90ais"; classtype:trojan-activity; sid:100004924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--polimerbizmimarlk-rvc.com"; classtype:trojan-activity; sid:100004925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ybom.urbanolab.com"; classtype:trojan-activity; sid:100004926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yeichner.com"; classtype:trojan-activity; sid:100004927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ylfpremium.com"; classtype:trojan-activity; sid:100004928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yoast.yourpageserver.com"; classtype:trojan-activity; sid:100004929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yourtopdog.com.au"; classtype:trojan-activity; sid:100004930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"youtubetrainingacademy.com"; classtype:trojan-activity; sid:100004931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yp.hnggzyjy.cn"; classtype:trojan-activity; sid:100004932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yskadvisors.com"; classtype:trojan-activity; sid:100004933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yummyyogaudaipur.com"; classtype:trojan-activity; sid:100004934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yzkzixun.com"; classtype:trojan-activity; sid:100004935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zakra.tecnasulstore.com.br"; classtype:trojan-activity; sid:100004936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zytrox.tk"; classtype:trojan-activity; sid:100004937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zz.690tx.com"; classtype:trojan-activity; sid:100004938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; endswith; nocase; http.host; content:"amumufree.weebly.com"; classtype:trojan-activity; sid:100004939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/proxyi.exe"; endswith; nocase; http.host; content:"analogx.com"; classtype:trojan-activity; sid:100004940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/densjons/bro/downloads/rew.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvdfv/anjj/downloads/jami.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/4.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/6.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr3.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/instaler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/installer.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatej.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatev.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/work.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/component.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/regsvc.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skygaming/updates/downloads/update.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/001.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1488.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1_cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1fc2d.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/26a5.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/abjects.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/attached.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/b7f2c.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/battletext.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_makros.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_silent.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_sup.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildss.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientnik.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientrevers.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dcrat.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hans.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hulu.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfive.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfour.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelone.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelthree.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/inteltwo.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/kleiman.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/notepadplus.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/putty.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/rockethcd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/scvhost900.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/sessionwin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/siliculose.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/statemobi.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stgedo.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/svcperf.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurjok.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurusbabac.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/telekiller.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateanddr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateandr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/vhajeja.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/word.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/www.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/xlsd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmatrix/data/hack1226.exe"; endswith; nocase; http.host; content:"cd.textfiles.com"; classtype:trojan-activity; sid:100005021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100005022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/816070119281131570/816070273254162442/all.txt"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100005023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100005024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razor/rzr-winner_intro.zip"; endswith; nocase; http.host; content:"chiptune.com"; classtype:trojan-activity; sid:100005025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100005026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100005027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meteoradminz/hidden-tear/zip/master"; endswith; nocase; http.host; content:"codeload.github.com"; classtype:trojan-activity; sid:100005028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; endswith; nocase; http.host; content:"colfincas.com"; classtype:trojan-activity; sid:100005029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qz0h69.pdf"; endswith; nocase; http.host; content:"deepfreedom.org"; classtype:trojan-activity; sid:100005030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=11jnyjpzkjiie_rzc4xwa2feok3x__yvc"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=151uxflny3vqh_lmghrkgjhhsqxi163sh"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=15iwonkjkhyvri_okkc_llq56aasvnvb9"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=16gqndqbduwuhy3qzxdn2nd9nufm_9ctq"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1ak46tqftzejmq-og_ky2oupgpmkgujtm"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1b6stzilakqykxaw1ct2w9hzccizwotff"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1brsmnj6g0lxa44ixkypvg5tcxkvi5gjt"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1by_s4vv8gdmmz8wl-lbpjbjy5adcrjk1"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1dpsxfbptpyl-zegto9t29vvcku2rjm9u"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1dwb7nww_ahtjfeed-afxl4hvm_xqkx-h"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1e7t_hnuohxuziwcxihocdievcj5_dsgj"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1erajjbz6gdxhsvvorlykzxyeoq-xu7wn"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1ev7gkzwjgtv2vlbbisg1ragd7nf0-xog"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1ey8zl85vszh-gdmubkoudacqs6zv2dup"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1f5trx90ulgsd-m1zvdupuf_kfugoo9ye"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1gq_jf503du9oip5bwzcoi6_kgolr3kx2"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1hlaoow8ug5gjejeeihwetcxyfjodcdut"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1imrv00kqbfz4ljzwq5qdau1to0zlmaqy"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1j6pvg1rznjh9pkldcyjiogo8ysiyl8_y"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1jlcqojhfhgifmirrsv0o5t-2rl-hblai"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1jvvuxwek4wrjqs94bjm8_klnnngj7b5r"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1k6sh5h-nptesem_jsnuxmhzntnvdlgxz"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1lc8lpsmu5ndjweyusqrxblm0g84sdcc7"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1lk6n-xrtv0dvdqljl26pzebxzp8tladk"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1lkcqgpimry4yp8grinnhsotnawquozcz"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1m34mp1cggxz-cz3a5ipjrgfog_qx8myx"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1m6kdawqt1fwxea6epcae6t1qevfhl0-5"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1m8w1y1-mxxa2pktrzkwfetwjxrlw1alo"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1m9jxzqcbnb8j8uph1qfcas8b9pngcogj"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1mdnlxs6vy5qk-u4dxz9movem4j3a3o-8"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1o6omlk34dxy3cbai8rvkvrnp5g-ovsj-"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1od6gtslxvylgyeujmrbvm9yhupmq_1lv"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1ozpasp-mr-e-ui4lshy4qy4a2pl8pxsi"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1pnmkgw-rlm9mjstqdxfcq0en07_x93ue"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1q0edpjr7vgo_ytns7dgjcav6317juz9y"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1q5gqeinogsri3i-ynlgvu88ajqnn9siq"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1quyiobd7-d-vcddlhxiqbqrwxyg7ongo"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1qyzpbxbnmnbp5opdk5rmeplmbga9c_q9"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1rrtyvouwizor2icbcoywdid4w9rwngxi"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1sao6yxf-a0t6wdgdr36srwlju57vigx_"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1sbg8kdmxp5futgje5jcfvh-ieq28holg"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1seb4h5c8z5jaf2_ulvhdv7mzqzmntp0k"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1skuwjvkgsmicbr1o48gnalcksfytwtdp"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1st5mtgqyofsskuhlomfihfmz_qx-i32o"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1umz5zjobot9__v2jxdutyborb2az90hz"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1we-h5qtxj9czhkhzvzg0qqpxufgu_v__"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1wmi0gpfe9ebcgai4w6iw6pninxo6ke-m"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1wurpipyf0s__fqtn1ov619nx7v1-tcy3"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1wwkqbfluu4qusqz26ewulr48zh9vzq-w"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1xbvceq1wmfjad59zyxwtykzy3xwy9iqb"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1xqcnagjbut3pdajnpsx0nonhla3nqes-"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1xsj8d2ysnoluawhk3g4tadaoyp8ktmab"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1xtflvdimom8odrygcmip7j4aesrjtgsm"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1yyuejm8cerrq2tctsibww4uetepcmh4i"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; endswith; nocase; http.host; content:"drive.google.com.it-barcelona.com"; classtype:trojan-activity; sid:100005085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/1zilg/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100005111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/qcgfmfvh/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100005112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/emclick.zip"; endswith; nocase; http.host; content:"e-mudhra.com"; classtype:trojan-activity; sid:100005113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100005114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100005115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; endswith; nocase; http.host; content:"file.elecfans.com"; classtype:trojan-activity; sid:100005123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100005124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100005125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; endswith; nocase; http.host; content:"gist.githubusercontent.com"; classtype:trojan-activity; sid:100005126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; endswith; nocase; http.host; content:"hqdecig.com"; classtype:trojan-activity; sid:100005127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/suy/"; endswith; nocase; http.host; content:"hsecaravans.co.uk"; classtype:trojan-activity; sid:100005128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19/items/startup_20210219/startup.txt"; endswith; nocase; http.host; content:"ia801802.us.archive.org"; classtype:trojan-activity; sid:100005129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/online-timer-kvhxz/ilxl/"; endswith; nocase; http.host; content:"ie-best.net"; classtype:trojan-activity; sid:100005130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100005131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100005132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebook/cs17.exe"; endswith; nocase; http.host; content:"jcedu.org"; classtype:trojan-activity; sid:100005133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/jl01o54yy09qrzg/fac215.tgz/file"; endswith; nocase; http.host; content:"justlficante.mediafire.com"; classtype:trojan-activity; sid:100005137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; endswith; nocase; http.host; content:"karmakoincodes.weebly.com"; classtype:trojan-activity; sid:100005138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dg/etrac/nf4emwz/"; endswith; nocase; http.host; content:"kotakwarna.co.id"; classtype:trojan-activity; sid:100005139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; endswith; nocase; http.host; content:"ksh.hu"; classtype:trojan-activity; sid:100005140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/affiliate/kuaizip_setup_10029.exe"; endswith; nocase; http.host; content:"kuaizip.com"; classtype:trojan-activity; sid:100005141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linuxforensicscode.zip"; endswith; nocase; http.host; content:"linuxforensicsbook.com.s3.amazonaws.com"; classtype:trojan-activity; sid:100005142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k/big5/1giof6/"; endswith; nocase; http.host; content:"minpic.de"; classtype:trojan-activity; sid:100005143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-contentbak/t9m/"; endswith; nocase; http.host; content:"morrobaydrugandgift.com"; classtype:trojan-activity; sid:100005144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; endswith; nocase; http.host; content:"my.cloudme.com"; classtype:trojan-activity; sid:100005145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/aacenc.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100005146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/doxillionsetup.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100005147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/4/1/6/6/4166984/keygen.exe"; endswith; nocase; http.host; content:"newyarlfm.weebly.com"; classtype:trojan-activity; sid:100005148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; endswith; nocase; http.host; content:"nhipcauytevietnhat.com"; classtype:trojan-activity; sid:100005149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; endswith; nocase; http.host; content:"note.youdao.com"; classtype:trojan-activity; sid:100005150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; endswith; nocase; http.host; content:"oldschoolvalue.s3.amazonaws.com"; classtype:trojan-activity; sid:100005151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!296&authkey=adsdrrjllbu1nwa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!297&authkey=am7nspchat4aqtw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21296&authkey=adsdrrjllbu1nwa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!210&authkey=agpl0pgvft8faaa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=80dabacd46496407&resid=80dabacd46496407%21124&authkey=abnj7t59iwijpdy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1045&authkey=aetgoeo_eku-6ba"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211045&authkey=aetgoeo_eku-6ba"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21122&authkey=ajqq2okqxfq8iuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774!124&authkey=afq42wqejwvcv8o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774%21124&authkey=afq42wqejwvcv8o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4a3bd996f92bf71&resid=e4a3bd996f92bf71%211944&authkey=ao3lztaialsza88"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f8d2350982acb14f&resid=f8d2350982acb14f%21140&authkey=ajo86idqg2jvzfq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!196&authkey=amm2av5ubkbhoru"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!197&authkey=apnt4trskzjga_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21196&authkey=amm2av5ubkbhoru"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21197&authkey=apnt4trskzjga_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/yqvsvlvq"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100005732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/llc/mwcacs65xienqdp/"; endswith; nocase; http.host; content:"pierreconsulting.info"; classtype:trojan-activity; sid:100005733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; endswith; nocase; http.host; content:"pioneiraagronegocio.com.br"; classtype:trojan-activity; sid:100005734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skoda22.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100005735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100005736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; endswith; nocase; http.host; content:"qjbutterflyevents.co.za"; classtype:trojan-activity; sid:100005737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maersk-bl+draft-copy-shipping-documents.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100005738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100005739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/purchasing+ordersigned+contractinv-30067121.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100005740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myqseeaccount/one/main/one.htm"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tennc/webshell/master/other/small_shell.txt"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; endswith; nocase; http.host; content:"res.yeshen.com"; classtype:trojan-activity; sid:100005752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/q05z91"; endswith; nocase; http.host; content:"sendspace.com"; classtype:trojan-activity; sid:100005753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; endswith; nocase; http.host; content:"sites.google.com"; classtype:trojan-activity; sid:100005754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-nurse-ss8d9/z/"; endswith; nocase; http.host; content:"technologydistilled.com"; classtype:trojan-activity; sid:100005765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/databases/merit.php"; endswith; nocase; http.host; content:"truemerit.io"; classtype:trojan-activity; sid:100005766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23.exe"; endswith; nocase; http.host; content:"tsrv4.ws"; classtype:trojan-activity; sid:100005767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crisanar/defis/jek_crackme1.7.zip"; endswith; nocase; http.host; content:"users.skynet.be"; classtype:trojan-activity; sid:100005768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/amowvegfrt9ja/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100005769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100005770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100005771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100005772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb%5efr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb^fr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/151_155/tidex_-_short_stuff.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syria-files/attach/222/222051_instruction.zip"; endswith; nocase; http.host; content:"wikileaks.org"; classtype:trojan-activity; sid:100005778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.46.55"; classtype:trojan-activity; sid:100003207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.48.162"; classtype:trojan-activity; sid:100003208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.231.95.247"; classtype:trojan-activity; sid:100003209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.232.102.163"; classtype:trojan-activity; sid:100003210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.232.46.169"; classtype:trojan-activity; sid:100003211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.233.159.21"; classtype:trojan-activity; sid:100003212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.233.78.236"; classtype:trojan-activity; sid:100003213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.234.247.41"; classtype:trojan-activity; sid:100003214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.234.85.184"; classtype:trojan-activity; sid:100003215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.23.163"; classtype:trojan-activity; sid:100003216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.67.162"; classtype:trojan-activity; sid:100003217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.82.112"; classtype:trojan-activity; sid:100003218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.87.100"; classtype:trojan-activity; sid:100003219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.90.32"; classtype:trojan-activity; sid:100003220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.95.254"; classtype:trojan-activity; sid:100003221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.148.201"; classtype:trojan-activity; sid:100003222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.237.142.157"; classtype:trojan-activity; sid:100003223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.237.24.151"; classtype:trojan-activity; sid:100003224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.237.252.159"; classtype:trojan-activity; sid:100003225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.237.60.73"; classtype:trojan-activity; sid:100003226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.238.228.0"; classtype:trojan-activity; sid:100003227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.155.147"; classtype:trojan-activity; sid:100003228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.202.121"; classtype:trojan-activity; sid:100003229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.21.27"; classtype:trojan-activity; sid:100003230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.218.137"; classtype:trojan-activity; sid:100003231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.98.70"; classtype:trojan-activity; sid:100003232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.242.200.90"; classtype:trojan-activity; sid:100003233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.56.15.227"; classtype:trojan-activity; sid:100003234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.61.99.155"; classtype:trojan-activity; sid:100003235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.84.37.198"; classtype:trojan-activity; sid:100003236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.87.29.162"; classtype:trojan-activity; sid:100003237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.230.156.44"; classtype:trojan-activity; sid:100003238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.241.106.183"; classtype:trojan-activity; sid:100003239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.252.8.94"; classtype:trojan-activity; sid:100003240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.137"; classtype:trojan-activity; sid:100003241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.139"; classtype:trojan-activity; sid:100003242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.242"; classtype:trojan-activity; sid:100003243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.203.192"; classtype:trojan-activity; sid:100003244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.135.134.228"; classtype:trojan-activity; sid:100003245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.182"; classtype:trojan-activity; sid:100003246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.204"; classtype:trojan-activity; sid:100003247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.244"; classtype:trojan-activity; sid:100003248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.66"; classtype:trojan-activity; sid:100003249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.141.84.184"; classtype:trojan-activity; sid:100003250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.142"; classtype:trojan-activity; sid:100003251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.65"; classtype:trojan-activity; sid:100003252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.47"; classtype:trojan-activity; sid:100003253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.94"; classtype:trojan-activity; sid:100003254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.165.215.19"; classtype:trojan-activity; sid:100003255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.116"; classtype:trojan-activity; sid:100003256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.164"; classtype:trojan-activity; sid:100003257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.22"; classtype:trojan-activity; sid:100003258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.248"; classtype:trojan-activity; sid:100003259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.110.99"; classtype:trojan-activity; sid:100003260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.119"; classtype:trojan-activity; sid:100003261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.154"; classtype:trojan-activity; sid:100003262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.16"; classtype:trojan-activity; sid:100003263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.202"; classtype:trojan-activity; sid:100003264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.84"; classtype:trojan-activity; sid:100003265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.178.101.22"; classtype:trojan-activity; sid:100003266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.179.171.252"; classtype:trojan-activity; sid:100003267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.22.209.58"; classtype:trojan-activity; sid:100003268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.23.22.186"; classtype:trojan-activity; sid:100003269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.231.210.27"; classtype:trojan-activity; sid:100003270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.27.253.137"; classtype:trojan-activity; sid:100003271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.33.112.19"; classtype:trojan-activity; sid:100003272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.51.104.59"; classtype:trojan-activity; sid:100003273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.81.235.31"; classtype:trojan-activity; sid:100003274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.9.148.37"; classtype:trojan-activity; sid:100003275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.151.155.218"; classtype:trojan-activity; sid:100003276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.161.185.15"; classtype:trojan-activity; sid:100003277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.172.75.231"; classtype:trojan-activity; sid:100003278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.175.184.121"; classtype:trojan-activity; sid:100003279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.182.173.246"; classtype:trojan-activity; sid:100003280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.20.63.218"; classtype:trojan-activity; sid:100003281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.21.153.231"; classtype:trojan-activity; sid:100003282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.214.27.4"; classtype:trojan-activity; sid:100003283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.24.130.254"; classtype:trojan-activity; sid:100003284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.243.179.115"; classtype:trojan-activity; sid:100003285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.249.33.79"; classtype:trojan-activity; sid:100003286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.25.242.211"; classtype:trojan-activity; sid:100003287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.118.86"; classtype:trojan-activity; sid:100003288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.86.128"; classtype:trojan-activity; sid:100003289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.97.76.242"; classtype:trojan-activity; sid:100003290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.145.152.26"; classtype:trojan-activity; sid:100003291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.151.23.172"; classtype:trojan-activity; sid:100003292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.157.97.71"; classtype:trojan-activity; sid:100003293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.16.131.51"; classtype:trojan-activity; sid:100003294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.197.0.119"; classtype:trojan-activity; sid:100003295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.21.202.98"; classtype:trojan-activity; sid:100003296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.46.231.38"; classtype:trojan-activity; sid:100003297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.162.113"; classtype:trojan-activity; sid:100003298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.87.36"; classtype:trojan-activity; sid:100003299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.143.32.36"; classtype:trojan-activity; sid:100003300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.143.43.93"; classtype:trojan-activity; sid:100003301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.158.201.200"; classtype:trojan-activity; sid:100003302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.20.121"; classtype:trojan-activity; sid:100003303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.21.3"; classtype:trojan-activity; sid:100003304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.174.182.99"; classtype:trojan-activity; sid:100003305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.170.49"; classtype:trojan-activity; sid:100003306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.178.183"; classtype:trojan-activity; sid:100003307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.179.129"; classtype:trojan-activity; sid:100003308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.68.221.252"; classtype:trojan-activity; sid:100003309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.68.249.121"; classtype:trojan-activity; sid:100003310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.70.15.16"; classtype:trojan-activity; sid:100003311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.70.95.181"; classtype:trojan-activity; sid:100003312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.146.202.18"; classtype:trojan-activity; sid:100003313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.181.135.114"; classtype:trojan-activity; sid:100003314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.2.70.50"; classtype:trojan-activity; sid:100003315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.42.37.74"; classtype:trojan-activity; sid:100003316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.53.146.179"; classtype:trojan-activity; sid:100003317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.8.10.62"; classtype:trojan-activity; sid:100003318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.102"; classtype:trojan-activity; sid:100003319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.121.91.255"; classtype:trojan-activity; sid:100003320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.252.47.29"; classtype:trojan-activity; sid:100003321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"51.171.146.13"; classtype:trojan-activity; sid:100003322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"51.222.56.159"; classtype:trojan-activity; sid:100003323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.114.136"; classtype:trojan-activity; sid:100003324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.180.122"; classtype:trojan-activity; sid:100003325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.114.246.26"; classtype:trojan-activity; sid:100003326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.108.164"; classtype:trojan-activity; sid:100003327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.162.92"; classtype:trojan-activity; sid:100003328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.174.4"; classtype:trojan-activity; sid:100003329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.125.191.4"; classtype:trojan-activity; sid:100003330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.126.247.118"; classtype:trojan-activity; sid:100003331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.141.122.109"; classtype:trojan-activity; sid:100003332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.166.120"; classtype:trojan-activity; sid:100003333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.200.124"; classtype:trojan-activity; sid:100003334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.143.142.142"; classtype:trojan-activity; sid:100003335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.143.189.75"; classtype:trojan-activity; sid:100003336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.18.103.109"; classtype:trojan-activity; sid:100003337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.19.249.50"; classtype:trojan-activity; sid:100003338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.218.67.253"; classtype:trojan-activity; sid:100003339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.22.212.107"; classtype:trojan-activity; sid:100003340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.226.129.29"; classtype:trojan-activity; sid:100003341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.23.245.24"; classtype:trojan-activity; sid:100003342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.230.89.42"; classtype:trojan-activity; sid:100003343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.238.42.192"; classtype:trojan-activity; sid:100003344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.240.147.97"; classtype:trojan-activity; sid:100003345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.57.237"; classtype:trojan-activity; sid:100003346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.78.55"; classtype:trojan-activity; sid:100003347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.243.126.133"; classtype:trojan-activity; sid:100003348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.112.254"; classtype:trojan-activity; sid:100003349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.117.238"; classtype:trojan-activity; sid:100003350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.142.5"; classtype:trojan-activity; sid:100003351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.143.240"; classtype:trojan-activity; sid:100003352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.144.229"; classtype:trojan-activity; sid:100003353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.147.196"; classtype:trojan-activity; sid:100003354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.151.33"; classtype:trojan-activity; sid:100003355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.153.224"; classtype:trojan-activity; sid:100003356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.74.240"; classtype:trojan-activity; sid:100003357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.77.38"; classtype:trojan-activity; sid:100003358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.12.80"; classtype:trojan-activity; sid:100003359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.14.53"; classtype:trojan-activity; sid:100003360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.16.173"; classtype:trojan-activity; sid:100003361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.19.127"; classtype:trojan-activity; sid:100003362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.72.88"; classtype:trojan-activity; sid:100003363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.74.243"; classtype:trojan-activity; sid:100003364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.74.245"; classtype:trojan-activity; sid:100003365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.75.213"; classtype:trojan-activity; sid:100003366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.77.88"; classtype:trojan-activity; sid:100003367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.80.25"; classtype:trojan-activity; sid:100003368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.82.35"; classtype:trojan-activity; sid:100003369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.87.171"; classtype:trojan-activity; sid:100003370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.89.158"; classtype:trojan-activity; sid:100003371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.252.176.71"; classtype:trojan-activity; sid:100003372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.255.133.161"; classtype:trojan-activity; sid:100003373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.255.140.150"; classtype:trojan-activity; sid:100003374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.48.154.143"; classtype:trojan-activity; sid:100003375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.50.221.148"; classtype:trojan-activity; sid:100003376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.153"; classtype:trojan-activity; sid:100003377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.39"; classtype:trojan-activity; sid:100003378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.76.151.189"; classtype:trojan-activity; sid:100003379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.76.151.51"; classtype:trojan-activity; sid:100003380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.97.206.33"; classtype:trojan-activity; sid:100003381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.0.211.161"; classtype:trojan-activity; sid:100003382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.102.168.189"; classtype:trojan-activity; sid:100003383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.127.11.50"; classtype:trojan-activity; sid:100003384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.202.3"; classtype:trojan-activity; sid:100003385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.214.4"; classtype:trojan-activity; sid:100003386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.246.125"; classtype:trojan-activity; sid:100003387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.29.133.229"; classtype:trojan-activity; sid:100003388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.45.235.176"; classtype:trojan-activity; sid:100003389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.58.104.244"; classtype:trojan-activity; sid:100003390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.58.117.226"; classtype:trojan-activity; sid:100003391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.7.124.148"; classtype:trojan-activity; sid:100003392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.8.35.22"; classtype:trojan-activity; sid:100003393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.180.232"; classtype:trojan-activity; sid:100003394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.217.35"; classtype:trojan-activity; sid:100003395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.94.180.230"; classtype:trojan-activity; sid:100003396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.96.37.181"; classtype:trojan-activity; sid:100003397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.96.37.192"; classtype:trojan-activity; sid:100003398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.96.39.222"; classtype:trojan-activity; sid:100003399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.193.255"; classtype:trojan-activity; sid:100003400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.13.61.12"; classtype:trojan-activity; sid:100003401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.14.48.221"; classtype:trojan-activity; sid:100003402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.16.247.78"; classtype:trojan-activity; sid:100003403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.162.122.36"; classtype:trojan-activity; sid:100003404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.164.130.220"; classtype:trojan-activity; sid:100003405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.176.249.56"; classtype:trojan-activity; sid:100003406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.184.149.169"; classtype:trojan-activity; sid:100003407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.20.217.142"; classtype:trojan-activity; sid:100003408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.208.135.42"; classtype:trojan-activity; sid:100003409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.122.57"; classtype:trojan-activity; sid:100003410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.186.185"; classtype:trojan-activity; sid:100003411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.216.23"; classtype:trojan-activity; sid:100003412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.233.94"; classtype:trojan-activity; sid:100003413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.33.5"; classtype:trojan-activity; sid:100003414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.19.63"; classtype:trojan-activity; sid:100003415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.6.112"; classtype:trojan-activity; sid:100003416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.100.83"; classtype:trojan-activity; sid:100003417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.111.39"; classtype:trojan-activity; sid:100003418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.162.152"; classtype:trojan-activity; sid:100003419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.202.218"; classtype:trojan-activity; sid:100003420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.206.246"; classtype:trojan-activity; sid:100003421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.218.31"; classtype:trojan-activity; sid:100003422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.220.167"; classtype:trojan-activity; sid:100003423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.23.84"; classtype:trojan-activity; sid:100003424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.254.178"; classtype:trojan-activity; sid:100003425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.162.59"; classtype:trojan-activity; sid:100003426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.58.188"; classtype:trojan-activity; sid:100003427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.83.55"; classtype:trojan-activity; sid:100003428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.214.217.96"; classtype:trojan-activity; sid:100003429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.214.32.17"; classtype:trojan-activity; sid:100003430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.214.73.6"; classtype:trojan-activity; sid:100003431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.214.93.166"; classtype:trojan-activity; sid:100003432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.165.64"; classtype:trojan-activity; sid:100003433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.195.111"; classtype:trojan-activity; sid:100003434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.207.11"; classtype:trojan-activity; sid:100003435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.4.239"; classtype:trojan-activity; sid:100003436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.177.196"; classtype:trojan-activity; sid:100003437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.86.208"; classtype:trojan-activity; sid:100003438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.223.84.102"; classtype:trojan-activity; sid:100003439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.25.109.240"; classtype:trojan-activity; sid:100003440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.25.115.48"; classtype:trojan-activity; sid:100003441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.25.76.224"; classtype:trojan-activity; sid:100003442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.15.104"; classtype:trojan-activity; sid:100003443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.4.72"; classtype:trojan-activity; sid:100003444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.42.72"; classtype:trojan-activity; sid:100003445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.51.127"; classtype:trojan-activity; sid:100003446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.26.17.221"; classtype:trojan-activity; sid:100003447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.10.121"; classtype:trojan-activity; sid:100003448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.8.43"; classtype:trojan-activity; sid:100003449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.99.254"; classtype:trojan-activity; sid:100003450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.102.243.124"; classtype:trojan-activity; sid:100003451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.130.195.121"; classtype:trojan-activity; sid:100003452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.162.169.210"; classtype:trojan-activity; sid:100003453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.162.55.42"; classtype:trojan-activity; sid:100003454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.163.142.96"; classtype:trojan-activity; sid:100003455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.164.96.98"; classtype:trojan-activity; sid:100003456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.171.60"; classtype:trojan-activity; sid:100003457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.194"; classtype:trojan-activity; sid:100003458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.230"; classtype:trojan-activity; sid:100003459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.192.73.253"; classtype:trojan-activity; sid:100003460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.213.118.28"; classtype:trojan-activity; sid:100003461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.247.224.66"; classtype:trojan-activity; sid:100003462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.253.94.230"; classtype:trojan-activity; sid:100003463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.124.125"; classtype:trojan-activity; sid:100003464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.151.60"; classtype:trojan-activity; sid:100003465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.47.220.169"; classtype:trojan-activity; sid:100003466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.103.144"; classtype:trojan-activity; sid:100003467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.103.217"; classtype:trojan-activity; sid:100003468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.109.9"; classtype:trojan-activity; sid:100003469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.11.87"; classtype:trojan-activity; sid:100003470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.159.231"; classtype:trojan-activity; sid:100003471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.167.66"; classtype:trojan-activity; sid:100003472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.195.226"; classtype:trojan-activity; sid:100003473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.210.53"; classtype:trojan-activity; sid:100003474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.211.61"; classtype:trojan-activity; sid:100003475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.212.191"; classtype:trojan-activity; sid:100003476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.214.11"; classtype:trojan-activity; sid:100003477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.234.193"; classtype:trojan-activity; sid:100003478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.237.212"; classtype:trojan-activity; sid:100003479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.242.56"; classtype:trojan-activity; sid:100003480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.30.172"; classtype:trojan-activity; sid:100003481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.4.214"; classtype:trojan-activity; sid:100003482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.42.174"; classtype:trojan-activity; sid:100003483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.48.40"; classtype:trojan-activity; sid:100003484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.76.72"; classtype:trojan-activity; sid:100003485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.9.166"; classtype:trojan-activity; sid:100003486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.9.62"; classtype:trojan-activity; sid:100003487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.98.22"; classtype:trojan-activity; sid:100003488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.99.161"; classtype:trojan-activity; sid:100003489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.102.137"; classtype:trojan-activity; sid:100003490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.117.115"; classtype:trojan-activity; sid:100003491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.119.161"; classtype:trojan-activity; sid:100003492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.122.161"; classtype:trojan-activity; sid:100003493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.123.162"; classtype:trojan-activity; sid:100003494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.192.49"; classtype:trojan-activity; sid:100003495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.201.162"; classtype:trojan-activity; sid:100003496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.103.56"; classtype:trojan-activity; sid:100003497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.168.35"; classtype:trojan-activity; sid:100003498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.232.45"; classtype:trojan-activity; sid:100003499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.40.202"; classtype:trojan-activity; sid:100003500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.58.20"; classtype:trojan-activity; sid:100003501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.64.104"; classtype:trojan-activity; sid:100003502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.180.67"; classtype:trojan-activity; sid:100003503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.181.7"; classtype:trojan-activity; sid:100003504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.57.96.116"; classtype:trojan-activity; sid:100003505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.170.60"; classtype:trojan-activity; sid:100003506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.73.220"; classtype:trojan-activity; sid:100003507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.61.218.23"; classtype:trojan-activity; sid:100003508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.65.172.121"; classtype:trojan-activity; sid:100003509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.0.22"; classtype:trojan-activity; sid:100003510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.104.46"; classtype:trojan-activity; sid:100003511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.110.59"; classtype:trojan-activity; sid:100003512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.195"; classtype:trojan-activity; sid:100003513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.86"; classtype:trojan-activity; sid:100003514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.255.60"; classtype:trojan-activity; sid:100003515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.45.130"; classtype:trojan-activity; sid:100003516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.98.144.75"; classtype:trojan-activity; sid:100003517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.1.98.131"; classtype:trojan-activity; sid:100003518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.117.124.114"; classtype:trojan-activity; sid:100003519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.141.73.58"; classtype:trojan-activity; sid:100003520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.131.205"; classtype:trojan-activity; sid:100003521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.143.46"; classtype:trojan-activity; sid:100003522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.155.61"; classtype:trojan-activity; sid:100003523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.227.31"; classtype:trojan-activity; sid:100003524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.31.126.33"; classtype:trojan-activity; sid:100003525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.149.66"; classtype:trojan-activity; sid:100003526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.222.98"; classtype:trojan-activity; sid:100003527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.43.207.148"; classtype:trojan-activity; sid:100003528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.90.165.236"; classtype:trojan-activity; sid:100003529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"63.245.122.93"; classtype:trojan-activity; sid:100003530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"64.233.154.99"; classtype:trojan-activity; sid:100003531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.125.128.196"; classtype:trojan-activity; sid:100003532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.21.58.252"; classtype:trojan-activity; sid:100003533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.26.155.131"; classtype:trojan-activity; sid:100003534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.35.61.255"; classtype:trojan-activity; sid:100003535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.153.233.87"; classtype:trojan-activity; sid:100003536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.229.214.115"; classtype:trojan-activity; sid:100003537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.57.55.210"; classtype:trojan-activity; sid:100003538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.74.7.197"; classtype:trojan-activity; sid:100003539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.91.21.31"; classtype:trojan-activity; sid:100003540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.196"; classtype:trojan-activity; sid:100003541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.213"; classtype:trojan-activity; sid:100003542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.245.151.203"; classtype:trojan-activity; sid:100003543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.3.169.223"; classtype:trojan-activity; sid:100003544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.8.138.101"; classtype:trojan-activity; sid:100003545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.81.98.111"; classtype:trojan-activity; sid:100003546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.83.49.234"; classtype:trojan-activity; sid:100003547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.84.138.165"; classtype:trojan-activity; sid:100003548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.151.244.128"; classtype:trojan-activity; sid:100003549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.174.182.226"; classtype:trojan-activity; sid:100003550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.175.107.153"; classtype:trojan-activity; sid:100003551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.183.25.71"; classtype:trojan-activity; sid:100003552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.188.144.143"; classtype:trojan-activity; sid:100003553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.204.88.29"; classtype:trojan-activity; sid:100003554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.106.84"; classtype:trojan-activity; sid:100003555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.119.241"; classtype:trojan-activity; sid:100003556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.78.33.33"; classtype:trojan-activity; sid:100003557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68468438438.xyz"; classtype:trojan-activity; sid:100003558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.115.37.205"; classtype:trojan-activity; sid:100003559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.120.237.255"; classtype:trojan-activity; sid:100003560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.123.245.151"; classtype:trojan-activity; sid:100003561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.124.231.110"; classtype:trojan-activity; sid:100003562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.127.214.47"; classtype:trojan-activity; sid:100003563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.146.232.34"; classtype:trojan-activity; sid:100003564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.165.173.49"; classtype:trojan-activity; sid:100003565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.196.158.227"; classtype:trojan-activity; sid:100003566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.222.157.166"; classtype:trojan-activity; sid:100003567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.229.0.133"; classtype:trojan-activity; sid:100003568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.63.73.234"; classtype:trojan-activity; sid:100003569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.115.194"; classtype:trojan-activity; sid:100003570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.227.186"; classtype:trojan-activity; sid:100003571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.76.240.206"; classtype:trojan-activity; sid:100003572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.115.31.30"; classtype:trojan-activity; sid:100003573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.118.240.88"; classtype:trojan-activity; sid:100003574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.167.10.180"; classtype:trojan-activity; sid:100003575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.236.190.250"; classtype:trojan-activity; sid:100003576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.25.5.105"; classtype:trojan-activity; sid:100003577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.93.129.118"; classtype:trojan-activity; sid:100003578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.127.148.69"; classtype:trojan-activity; sid:100003579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.146.190.91"; classtype:trojan-activity; sid:100003580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.167.164.113"; classtype:trojan-activity; sid:100003581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.204.63.239"; classtype:trojan-activity; sid:100003582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.29.48.164"; classtype:trojan-activity; sid:100003583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.34.191.213"; classtype:trojan-activity; sid:100003584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.40.234.166"; classtype:trojan-activity; sid:100003585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.106.142"; classtype:trojan-activity; sid:100003586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.2.122"; classtype:trojan-activity; sid:100003587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.235.106"; classtype:trojan-activity; sid:100003588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.47.133.58"; classtype:trojan-activity; sid:100003589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.71.60.69"; classtype:trojan-activity; sid:100003590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.85.106.211"; classtype:trojan-activity; sid:100003591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.17.22.30"; classtype:trojan-activity; sid:100003592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.186.139.38"; classtype:trojan-activity; sid:100003593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.180.98"; classtype:trojan-activity; sid:100003594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.200.62"; classtype:trojan-activity; sid:100003595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.214.69.226"; classtype:trojan-activity; sid:100003596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.230.118"; classtype:trojan-activity; sid:100003597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.35.40"; classtype:trojan-activity; sid:100003598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.31.40.122"; classtype:trojan-activity; sid:100003599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.204.216.103"; classtype:trojan-activity; sid:100003600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.101.1.159"; classtype:trojan-activity; sid:100003601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.108.224.112"; classtype:trojan-activity; sid:100003602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.116.216.141"; classtype:trojan-activity; sid:100003603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.194.117.165"; classtype:trojan-activity; sid:100003604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.195.115.176"; classtype:trojan-activity; sid:100003605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.199.84.77"; classtype:trojan-activity; sid:100003606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.64.139.223"; classtype:trojan-activity; sid:100003607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.75.165.81"; classtype:trojan-activity; sid:100003608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.127.141.52"; classtype:trojan-activity; sid:100003609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.83.102.27"; classtype:trojan-activity; sid:100003610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.99.213.61"; classtype:trojan-activity; sid:100003611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.108.199.153"; classtype:trojan-activity; sid:100003612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.170.11.82"; classtype:trojan-activity; sid:100003613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.178.22.145"; classtype:trojan-activity; sid:100003614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.250.199.133"; classtype:trojan-activity; sid:100003615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.254.129.227"; classtype:trojan-activity; sid:100003616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.84.134.33"; classtype:trojan-activity; sid:100003617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.95.12.137"; classtype:trojan-activity; sid:100003618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.237.25.210"; classtype:trojan-activity; sid:100003619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.50.153"; classtype:trojan-activity; sid:100003620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.52.220"; classtype:trojan-activity; sid:100003621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.79.191.32"; classtype:trojan-activity; sid:100003622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.89.203.238"; classtype:trojan-activity; sid:100003623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.94.89.20"; classtype:trojan-activity; sid:100003624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.186.155.18"; classtype:trojan-activity; sid:100003625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.141.144"; classtype:trojan-activity; sid:100003626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.240.125"; classtype:trojan-activity; sid:100003627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.41.200"; classtype:trojan-activity; sid:100003628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.168.64"; classtype:trojan-activity; sid:100003629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.188.141"; classtype:trojan-activity; sid:100003630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.104.157"; classtype:trojan-activity; sid:100003631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.176.163"; classtype:trojan-activity; sid:100003632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.23.172.81"; classtype:trojan-activity; sid:100003633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.8.225.77"; classtype:trojan-activity; sid:100003634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.11.195.121"; classtype:trojan-activity; sid:100003635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.13.49.221"; classtype:trojan-activity; sid:100003636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.130.253.13"; classtype:trojan-activity; sid:100003637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.147.123.48"; classtype:trojan-activity; sid:100003638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.170.31.56"; classtype:trojan-activity; sid:100003639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.175.42.244"; classtype:trojan-activity; sid:100003640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.21.84.63"; classtype:trojan-activity; sid:100003641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.7.170.58"; classtype:trojan-activity; sid:100003642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.79.58.94"; classtype:trojan-activity; sid:100003643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.8.70.162"; classtype:trojan-activity; sid:100003644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.9.88.185"; classtype:trojan-activity; sid:100003645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.107.89.207"; classtype:trojan-activity; sid:100003646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.19.101.218"; classtype:trojan-activity; sid:100003647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.211.181.77"; classtype:trojan-activity; sid:100003648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.217.12.7"; classtype:trojan-activity; sid:100003649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.67.32.66"; classtype:trojan-activity; sid:100003650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.99.128.61"; classtype:trojan-activity; sid:100003651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.136.146.213"; classtype:trojan-activity; sid:100003652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.165.44.109"; classtype:trojan-activity; sid:100003653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.191.40.58"; classtype:trojan-activity; sid:100003654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.111.60"; classtype:trojan-activity; sid:100003655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.141.184"; classtype:trojan-activity; sid:100003656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.215.199.29"; classtype:trojan-activity; sid:100003657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.187.113"; classtype:trojan-activity; sid:100003658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.195.216"; classtype:trojan-activity; sid:100003659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.237.128.200"; classtype:trojan-activity; sid:100003660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.246.225.203"; classtype:trojan-activity; sid:100003661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.92.36.96"; classtype:trojan-activity; sid:100003662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.103.108.72"; classtype:trojan-activity; sid:100003663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.135.196.130"; classtype:trojan-activity; sid:100003664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.212.178"; classtype:trojan-activity; sid:100003665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.85.112"; classtype:trojan-activity; sid:100003666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.207.61.194"; classtype:trojan-activity; sid:100003667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.209.250.155"; classtype:trojan-activity; sid:100003668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.211.156.38"; classtype:trojan-activity; sid:100003669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.110.252"; classtype:trojan-activity; sid:100003670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.53.77"; classtype:trojan-activity; sid:100003671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.138.72"; classtype:trojan-activity; sid:100003672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.139.92"; classtype:trojan-activity; sid:100003673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.154.214"; classtype:trojan-activity; sid:100003674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.187.109"; classtype:trojan-activity; sid:100003675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.100.54"; classtype:trojan-activity; sid:100003676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.108.172"; classtype:trojan-activity; sid:100003677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.131.158"; classtype:trojan-activity; sid:100003678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.19.42"; classtype:trojan-activity; sid:100003679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.197.254"; classtype:trojan-activity; sid:100003680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.215.149"; classtype:trojan-activity; sid:100003681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.232.68"; classtype:trojan-activity; sid:100003682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.234.195"; classtype:trojan-activity; sid:100003683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.246.96"; classtype:trojan-activity; sid:100003684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.28.57"; classtype:trojan-activity; sid:100003685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.4.57"; classtype:trojan-activity; sid:100003686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.55.84"; classtype:trojan-activity; sid:100003687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.73.245"; classtype:trojan-activity; sid:100003688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.9.62"; classtype:trojan-activity; sid:100003689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.98.51"; classtype:trojan-activity; sid:100003690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.165.237.163"; classtype:trojan-activity; sid:100003691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.147.99"; classtype:trojan-activity; sid:100003692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.218.42"; classtype:trojan-activity; sid:100003693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.242.253.154"; classtype:trojan-activity; sid:100003694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.252.9.37"; classtype:trojan-activity; sid:100003695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.208"; classtype:trojan-activity; sid:100003696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.213"; classtype:trojan-activity; sid:100003697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.212.219.127"; classtype:trojan-activity; sid:100003698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.50.118"; classtype:trojan-activity; sid:100003699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.95.204"; classtype:trojan-activity; sid:100003700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.238.24.35"; classtype:trojan-activity; sid:100003701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.247.83.74"; classtype:trojan-activity; sid:100003702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.254.39.129"; classtype:trojan-activity; sid:100003703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.33.111.227"; classtype:trojan-activity; sid:100003704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.40.127.242"; classtype:trojan-activity; sid:100003705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.42.20.217"; classtype:trojan-activity; sid:100003706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; classtype:trojan-activity; sid:100003707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.11.216"; classtype:trojan-activity; sid:100003708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.123.251"; classtype:trojan-activity; sid:100003709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.135.187"; classtype:trojan-activity; sid:100003710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.208.25"; classtype:trojan-activity; sid:100003711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.224.141"; classtype:trojan-activity; sid:100003712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.241.2"; classtype:trojan-activity; sid:100003713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.214.149.236"; classtype:trojan-activity; sid:100003714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.64.181.50"; classtype:trojan-activity; sid:100003715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.74.215.180"; classtype:trojan-activity; sid:100003716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.130.227"; classtype:trojan-activity; sid:100003717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.195.129"; classtype:trojan-activity; sid:100003718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"86.35.43.220"; classtype:trojan-activity; sid:100003719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.61.89.40"; classtype:trojan-activity; sid:100003720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87du.vip"; classtype:trojan-activity; sid:100003721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.119.171.253"; classtype:trojan-activity; sid:100003722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.208.71"; classtype:trojan-activity; sid:100003723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.219.179"; classtype:trojan-activity; sid:100003724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.225.222.128"; classtype:trojan-activity; sid:100003725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.247.96.19"; classtype:trojan-activity; sid:100003726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.136.231"; classtype:trojan-activity; sid:100003727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.51.139"; classtype:trojan-activity; sid:100003728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.249.244.180"; classtype:trojan-activity; sid:100003729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.204.12"; classtype:trojan-activity; sid:100003730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.226.26"; classtype:trojan-activity; sid:100003731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.254.90"; classtype:trojan-activity; sid:100003732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.122.183.130"; classtype:trojan-activity; sid:100003733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.29.213.33"; classtype:trojan-activity; sid:100003734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.35.62.96"; classtype:trojan-activity; sid:100003735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.85.166"; classtype:trojan-activity; sid:100003736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.87.5"; classtype:trojan-activity; sid:100003737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.46.237.89"; classtype:trojan-activity; sid:100003738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8poieq.bn.files.1drv.com"; classtype:trojan-activity; sid:100003739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"90.152.144.139"; classtype:trojan-activity; sid:100003740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"90.63.176.144"; classtype:trojan-activity; sid:100003741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.177.139.132"; classtype:trojan-activity; sid:100003742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.187.103.32"; classtype:trojan-activity; sid:100003743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.212.150.241"; classtype:trojan-activity; sid:100003744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.217.104.185"; classtype:trojan-activity; sid:100003745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.233.112.188"; classtype:trojan-activity; sid:100003746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.234.60.94"; classtype:trojan-activity; sid:100003747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.239.168.83"; classtype:trojan-activity; sid:100003748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.244.169.139"; classtype:trojan-activity; sid:100003749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.92.16.244"; classtype:trojan-activity; sid:100003750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.98.4.181"; classtype:trojan-activity; sid:100003751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.113.93.34"; classtype:trojan-activity; sid:100003752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.114.191.82"; classtype:trojan-activity; sid:100003753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.241.78.114"; classtype:trojan-activity; sid:100003754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.27.246.202"; classtype:trojan-activity; sid:100003755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.54.237.237"; classtype:trojan-activity; sid:100003756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.83.62.139"; classtype:trojan-activity; sid:100003757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.85.18.138"; classtype:trojan-activity; sid:100003758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.171.157.73"; classtype:trojan-activity; sid:100003759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.21.224.154"; classtype:trojan-activity; sid:100003760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.115.176"; classtype:trojan-activity; sid:100003761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.137.16"; classtype:trojan-activity; sid:100003762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.182.249"; classtype:trojan-activity; sid:100003763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.206.56"; classtype:trojan-activity; sid:100003764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.57.43.233"; classtype:trojan-activity; sid:100003765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.73.99.102"; classtype:trojan-activity; sid:100003766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.136.69.199"; classtype:trojan-activity; sid:100003767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.143.53.34"; classtype:trojan-activity; sid:100003768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.17.170"; classtype:trojan-activity; sid:100003769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.82.190"; classtype:trojan-activity; sid:100003770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.200.16.22"; classtype:trojan-activity; sid:100003771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.224.83.208"; classtype:trojan-activity; sid:100003772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.53.120.109"; classtype:trojan-activity; sid:100003773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.132.129.250"; classtype:trojan-activity; sid:100003774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.153.241.63"; classtype:trojan-activity; sid:100003775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.154.20.231"; classtype:trojan-activity; sid:100003776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.158.19.130"; classtype:trojan-activity; sid:100003777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.113.227"; classtype:trojan-activity; sid:100003778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.113.52"; classtype:trojan-activity; sid:100003779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.201.34"; classtype:trojan-activity; sid:100003780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.181.155.112"; classtype:trojan-activity; sid:100003781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.146.134"; classtype:trojan-activity; sid:100003782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.6.114"; classtype:trojan-activity; sid:100003783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.66.196.63"; classtype:trojan-activity; sid:100003784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.9.120.40"; classtype:trojan-activity; sid:100003785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.239.73.246"; classtype:trojan-activity; sid:100003786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.47.147.169"; classtype:trojan-activity; sid:100003787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.68.140.254"; classtype:trojan-activity; sid:100003788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.96.199.75"; classtype:trojan-activity; sid:100003789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.210.218"; classtype:trojan-activity; sid:100003790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.239.142"; classtype:trojan-activity; sid:100003791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.113.239.207"; classtype:trojan-activity; sid:100003792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.116.72.119"; classtype:trojan-activity; sid:100003793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.128.147.115"; classtype:trojan-activity; sid:100003794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.178.242.44"; classtype:trojan-activity; sid:100003795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.249.236.11"; classtype:trojan-activity; sid:100003796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.28.200.139"; classtype:trojan-activity; sid:100003797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.30.24.54"; classtype:trojan-activity; sid:100003798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.150.245.203"; classtype:trojan-activity; sid:100003799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.33.195.164"; classtype:trojan-activity; sid:100003800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abcd.bg"; classtype:trojan-activity; sid:100003801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abclicks.in"; classtype:trojan-activity; sid:100003802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abissnet.net"; classtype:trojan-activity; sid:100003803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aboveandbelow.com.au"; classtype:trojan-activity; sid:100003804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absoftechworld.com"; classtype:trojan-activity; sid:100003805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absupplies.co.uk"; classtype:trojan-activity; sid:100003806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abyssos.eu"; classtype:trojan-activity; sid:100003807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"academyshademani.com"; classtype:trojan-activity; sid:100003808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acbick.com"; classtype:trojan-activity; sid:100003809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"accounts.thesmarttechhub.com"; classtype:trojan-activity; sid:100003810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aceeprc.com.aceeprc.com"; classtype:trojan-activity; sid:100003811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acellr.co.uk"; classtype:trojan-activity; sid:100003812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aciabogados.com"; classtype:trojan-activity; sid:100003813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acteon.com.ar"; classtype:trojan-activity; sid:100003814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"activateyourdiscount.com"; classtype:trojan-activity; sid:100003815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"activecost.com.au"; classtype:trojan-activity; sid:100003816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adamorinmusic.com"; classtype:trojan-activity; sid:100003817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"addahealingmusic.com"; classtype:trojan-activity; sid:100003818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.com"; classtype:trojan-activity; sid:100003819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.memengers.com"; classtype:trojan-activity; sid:100003820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.erapor.smk-alasror.net"; classtype:trojan-activity; sid:100003821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.gentbcn.org"; classtype:trojan-activity; sid:100003822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.grandoceanvilla.com"; classtype:trojan-activity; sid:100003823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adventureexplorer.in"; classtype:trojan-activity; sid:100003824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aeropilates.cl"; classtype:trojan-activity; sid:100003825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afrimedspecialist.com"; classtype:trojan-activity; sid:100003826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agemn.co.za"; classtype:trojan-activity; sid:100003827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciadigitalwdys.com"; classtype:trojan-activity; sid:100003828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciatabletshouse.com.br"; classtype:trojan-activity; sid:100003829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenda.gmelloinformatica.com.br"; classtype:trojan-activity; sid:100003830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agentt.ac.ug"; classtype:trojan-activity; sid:100003831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agile8studio.com"; classtype:trojan-activity; sid:100003832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agmcarpetcare.co.uk"; classtype:trojan-activity; sid:100003833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiqtest.com"; classtype:trojan-activity; sid:100003834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajpharmaholding.com"; classtype:trojan-activity; sid:100003835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajstudiollc.com"; classtype:trojan-activity; sid:100003836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"akauk09.top"; classtype:trojan-activity; sid:100003837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"akivj07.top"; classtype:trojan-activity; sid:100003838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"akpgi08.top"; classtype:trojan-activity; sid:100003839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"al-wahd.com"; classtype:trojan-activity; sid:100003840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alasdemariposas.org"; classtype:trojan-activity; sid:100003841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alemelektronik.com"; classtype:trojan-activity; sid:100003842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alena1971.es"; classtype:trojan-activity; sid:100003843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alexdubai.com.aldiabsteel.com"; classtype:trojan-activity; sid:100003844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"algreenstdykelveskbg.dns.army"; classtype:trojan-activity; sid:100003845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alka.institute"; classtype:trojan-activity; sid:100003846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"allforcreative.com.au"; classtype:trojan-activity; sid:100003847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alltheway.travel"; classtype:trojan-activity; sid:100003848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alpaylar.com.tr"; classtype:trojan-activity; sid:100003849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"am-concepts.ca"; classtype:trojan-activity; sid:100003850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amamontajes.com"; classtype:trojan-activity; sid:100003851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarresdeamorymaestroshechiceros.com"; classtype:trojan-activity; sid:100003852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarteargentina.com.ar"; classtype:trojan-activity; sid:100003853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amenyan.zouri.jp"; classtype:trojan-activity; sid:100003854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amos524.org"; classtype:trojan-activity; sid:100003855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ams.alvinasschools.org.ng"; classtype:trojan-activity; sid:100003856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anantam.net.in"; classtype:trojan-activity; sid:100003857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreelapeyre.com"; classtype:trojan-activity; sid:100003858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andremaraisbeleggings.co.za"; classtype:trojan-activity; sid:100003859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ac.ug"; classtype:trojan-activity; sid:100003860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ug"; classtype:trojan-activity; sid:100003861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreshconcejal.solucioneslink.com"; classtype:trojan-activity; sid:100003862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelazgheibld.com"; classtype:trojan-activity; sid:100003863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelsdetour.com"; classtype:trojan-activity; sid:100003864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angloteste.bigprime.com.br"; classtype:trojan-activity; sid:100003865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anhung1102.vn"; classtype:trojan-activity; sid:100003866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anysbergbiltong.co.za"; classtype:trojan-activity; sid:100003867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apartamentoscitta.com"; classtype:trojan-activity; sid:100003868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api-ms.cobainaja.id"; classtype:trojan-activity; sid:100003869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.cstdevs.com"; classtype:trojan-activity; sid:100003870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.quocbao.biz"; classtype:trojan-activity; sid:100003871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.sampy.io"; classtype:trojan-activity; sid:100003872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aplicativoparasindicato.com.br"; classtype:trojan-activity; sid:100003873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apoolcondo.com"; classtype:trojan-activity; sid:100003874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.adsensearticle.com"; classtype:trojan-activity; sid:100003875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.explicitsurveys.co.uk"; classtype:trojan-activity; sid:100003876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.prerana.info"; classtype:trojan-activity; sid:100003877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apps.saintsoporte.com"; classtype:trojan-activity; sid:100003878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aqv.news"; classtype:trojan-activity; sid:100003879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"areyoulivingwell.com"; classtype:trojan-activity; sid:100003880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"artedibujoyarquitectura.com"; classtype:trojan-activity; sid:100003881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ask-regard.call-save.biz"; classtype:trojan-activity; sid:100003882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atfile.com"; classtype:trojan-activity; sid:100003883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"athenacapsg.com"; classtype:trojan-activity; sid:100003884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atlasconcreteworks.com"; classtype:trojan-activity; sid:100003885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atnetech.com"; classtype:trojan-activity; sid:100003886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"attach.66rpg.com"; classtype:trojan-activity; sid:100003887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atteuqpotentialunlimited.com"; classtype:trojan-activity; sid:100003888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"augustair.com"; classtype:trojan-activity; sid:100003889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aulist.com"; classtype:trojan-activity; sid:100003890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"automaticrefreshments.com"; classtype:trojan-activity; sid:100003891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"avadhanagames.com"; classtype:trojan-activity; sid:100003892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayamallah.com"; classtype:trojan-activity; sid:100003893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azmeasurement.com"; classtype:trojan-activity; sid:100003894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azraktours.com"; classtype:trojan-activity; sid:100003895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"b2b.toptanakaryakit.com.tr"; classtype:trojan-activity; sid:100003896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"backgrounds.pk"; classtype:trojan-activity; sid:100003897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"badeggdesign.com"; classtype:trojan-activity; sid:100003898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"balealgodon.mx"; classtype:trojan-activity; sid:100003899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangkok-orchids.com"; classtype:trojan-activity; sid:100003900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"barcionstw.eastus.cloudapp.azure.com"; classtype:trojan-activity; sid:100003901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bary.sz4h.com"; classtype:trojan-activity; sid:100003902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bash.givemexyz.in"; classtype:trojan-activity; sid:100003903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"basma.com.kw"; classtype:trojan-activity; sid:100003904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; classtype:trojan-activity; sid:100003905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bavhome.com"; classtype:trojan-activity; sid:100003906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bbia.co.uk"; classtype:trojan-activity; sid:100003907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcmt.elin.co.za"; classtype:trojan-activity; sid:100003908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcrg.co.za"; classtype:trojan-activity; sid:100003909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bearcatpumps.com.cn"; classtype:trojan-activity; sid:100003910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beautincollagen.rs"; classtype:trojan-activity; sid:100003911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bekape.co.id"; classtype:trojan-activity; sid:100003912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bespokeweddings.ie"; classtype:trojan-activity; sid:100003913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bestcarenepal.com"; classtype:trojan-activity; sid:100003914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betone.co.kr"; classtype:trojan-activity; sid:100003915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betycopaints.com"; classtype:trojan-activity; sid:100003916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beveragesmiami.solucioneslink.com"; classtype:trojan-activity; sid:100003917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bhavaniengineering.com"; classtype:trojan-activity; sid:100003918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bigbag.wootraining.certificacion.cl"; classtype:trojan-activity; sid:100003919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilbosaquet.ug"; classtype:trojan-activity; sid:100003920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilhen.co.za"; classtype:trojan-activity; sid:100003921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"billing.rahitechnosoft.com"; classtype:trojan-activity; sid:100003922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"binoy.stalphonsamissionva.org"; classtype:trojan-activity; sid:100003923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birdi.elin.co.za"; classtype:trojan-activity; sid:100003924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birminghamlink.org"; classtype:trojan-activity; sid:100003925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.callensaxen.com"; classtype:trojan-activity; sid:100003926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.oyinblogs.com"; classtype:trojan-activity; sid:100003927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.takbelit.com"; classtype:trojan-activity; sid:100003928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bmlifestyle.co.uk"; classtype:trojan-activity; sid:100003929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bnrnews.id"; classtype:trojan-activity; sid:100003930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bodenstein.co.za"; classtype:trojan-activity; sid:100003931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"booksearch.com"; classtype:trojan-activity; sid:100003932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bounces.mi-fs.com"; classtype:trojan-activity; sid:100003933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bpo.correct.go.th"; classtype:trojan-activity; sid:100003934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bradleyinstitute.co.za"; classtype:trojan-activity; sid:100003935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brandtrust.com.pk"; classtype:trojan-activity; sid:100003936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brendanquine.com"; classtype:trojan-activity; sid:100003937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brideofmessiah.com"; classtype:trojan-activity; sid:100003938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bridesofmaldives.com"; classtype:trojan-activity; sid:100003939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightmega.com"; classtype:trojan-activity; sid:100003940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightonrooms.co.uk"; classtype:trojan-activity; sid:100003941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightstarshop.com"; classtype:trojan-activity; sid:100003942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"browardinsurancemiami.solucioneslink.com"; classtype:trojan-activity; sid:100003943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bt2.elin.co.za"; classtype:trojan-activity; sid:100003944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"btdapi.robotake.com"; classtype:trojan-activity; sid:100003945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buigiaphat.com.vn"; classtype:trojan-activity; sid:100003946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bullseyemedia.in"; classtype:trojan-activity; sid:100003947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"busandvanrentalmalaysia.com"; classtype:trojan-activity; sid:100003948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buscascolegios.diit.cl"; classtype:trojan-activity; sid:100003949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business.softberg.ro"; classtype:trojan-activity; sid:100003950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buyingmusiconline.com"; classtype:trojan-activity; sid:100003951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bwsr.eu"; classtype:trojan-activity; sid:100003952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c.oooooooooo.ga"; classtype:trojan-activity; sid:100003953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c0140529.ferozo.com"; classtype:trojan-activity; sid:100003954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"caballo.com.au"; classtype:trojan-activity; sid:100003955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"calgaryautorepairservice.com"; classtype:trojan-activity; sid:100003956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"callbury.in"; classtype:trojan-activity; sid:100003957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"camminachetipassa.it"; classtype:trojan-activity; sid:100003958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"campusvirtual.cepsanjuanbosco.net.pe"; classtype:trojan-activity; sid:100003959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cancer.educandome.co"; classtype:trojan-activity; sid:100003960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalgroup-kw.com"; classtype:trojan-activity; sid:100003961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalnewsagency.com"; classtype:trojan-activity; sid:100003962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capoeiraventrelivre.com"; classtype:trojan-activity; sid:100003963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cashyinvestment.org"; classtype:trojan-activity; sid:100003964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchpoolshetlands.co.uk"; classtype:trojan-activity; sid:100003965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cazyacustomfurniture.com"; classtype:trojan-activity; sid:100003966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ccauthority.net"; classtype:trojan-activity; sid:100003967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cdaonline.com.ar"; classtype:trojan-activity; sid:100003968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cec.asso.ac-amiens.fr"; classtype:trojan-activity; sid:100003969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cecra.cl"; classtype:trojan-activity; sid:100003970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cellas.sk"; classtype:trojan-activity; sid:100003971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cendekiabinaaksara.com"; classtype:trojan-activity; sid:100003972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cespol-bote.com.mx"; classtype:trojan-activity; sid:100003973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cfs5.tistory.com"; classtype:trojan-activity; sid:100003974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ch.rmu.ac.th"; classtype:trojan-activity; sid:100003975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"changematterscounselling.com"; classtype:trojan-activity; sid:100003976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chardhamdodham.com"; classtype:trojan-activity; sid:100003977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chezalice.co.za"; classtype:trojan-activity; sid:100003978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"childselect.com"; classtype:trojan-activity; sid:100003979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile.myvnc.com"; classtype:trojan-activity; sid:100003980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile80.myvnc.com"; classtype:trojan-activity; sid:100003981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cible-energy.com"; classtype:trojan-activity; sid:100003982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cifeer.net"; classtype:trojan-activity; sid:100003983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citycapproperty.ru"; classtype:trojan-activity; sid:100003984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cityglobalgospel.com"; classtype:trojan-activity; sid:100003985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"civi.istmejia.com"; classtype:trojan-activity; sid:100003986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cleanbydesignllc.com"; classtype:trojan-activity; sid:100003987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cloud.fc.co.mz"; classtype:trojan-activity; sid:100003988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"codsambal.com"; classtype:trojan-activity; sid:100003989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colinde.pricesne.com"; classtype:trojan-activity; sid:100003990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colorpak.pl"; classtype:trojan-activity; sid:100003991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"competancy.indigoconsult.net"; classtype:trojan-activity; sid:100003992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"config.cqhbkjzx.com"; classtype:trojan-activity; sid:100003993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"constructoralyon.com"; classtype:trojan-activity; sid:100003994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"consulateins.solucioneslink.com"; classtype:trojan-activity; sid:100003995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"contributeindustry.com"; classtype:trojan-activity; sid:100003996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"controleautomacao.com.br"; classtype:trojan-activity; sid:100003997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"copelandscapes.com"; classtype:trojan-activity; sid:100003998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"coulsongraphics.com"; classtype:trojan-activity; sid:100003999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"covid19.cyberschool.or.id"; classtype:trojan-activity; sid:100004000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cr-sq.com"; classtype:trojan-activity; sid:100004001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"craftnesia.id"; classtype:trojan-activity; sid:100004002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"creationskateboards.com"; classtype:trojan-activity; sid:100004003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crecerco.com"; classtype:trojan-activity; sid:100004004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crittersbythebay.com"; classtype:trojan-activity; sid:100004005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crm.notariavieitoyvelamazan.com"; classtype:trojan-activity; sid:100004006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crscorretordeimoveis.com.br"; classtype:trojan-activity; sid:100004007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cse-engineer.com"; classtype:trojan-activity; sid:100004008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"csnserver.com"; classtype:trojan-activity; sid:100004009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubescargoexpress.com"; classtype:trojan-activity; sid:100004010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubrebocasenpuebla.com.mx"; classtype:trojan-activity; sid:100004011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"curasoles.co.za"; classtype:trojan-activity; sid:100004012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"currantmedia.com"; classtype:trojan-activity; sid:100004013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cwa.mx"; classtype:trojan-activity; sid:100004014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyber.searchkero.com"; classtype:trojan-activity; sid:100004015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyclomove.com"; classtype:trojan-activity; sid:100004016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cynkon.kairoscs.net"; classtype:trojan-activity; sid:100004017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czas.dbstrony.pl"; classtype:trojan-activity; sid:100004018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czsl.91756.cn"; classtype:trojan-activity; sid:100004019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d.powerofwish.com"; classtype:trojan-activity; sid:100004020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d9.99ddd.com"; classtype:trojan-activity; sid:100004021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"da.alibuf.com"; classtype:trojan-activity; sid:100004022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"damagedessentialtelecommunications.testmail4.repl.co"; classtype:trojan-activity; sid:100004023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dandyair.com"; classtype:trojan-activity; sid:100004024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dartoonpictures.com"; classtype:trojan-activity; sid:100004025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.cdevelop.org"; classtype:trojan-activity; sid:100004026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.over-blog-kiwi.com"; classtype:trojan-activity; sid:100004027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datapolish.com"; classtype:trojan-activity; sid:100004028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dating.khokhas.co.za"; classtype:trojan-activity; sid:100004029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datsom.vn"; classtype:trojan-activity; sid:100004030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"daunhotq10.com"; classtype:trojan-activity; sid:100004031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davethompson.me.uk"; classtype:trojan-activity; sid:100004032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davidmcguinness.info"; classtype:trojan-activity; sid:100004033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dayspringdaisies.com"; classtype:trojan-activity; sid:100004034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dd.qiyuea.cn"; classtype:trojan-activity; sid:100004035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"de.gsearch.com.de"; classtype:trojan-activity; sid:100004036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"decifrar.com.br"; classtype:trojan-activity; sid:100004037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"deigratia2.elin.co.za"; classtype:trojan-activity; sid:100004038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dekovizyon.com"; classtype:trojan-activity; sid:100004039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo-cliente.mindcreative.com.br"; classtype:trojan-activity; sid:100004040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo6.hiites.com"; classtype:trojan-activity; sid:100004041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dent-estet.com"; classtype:trojan-activity; sid:100004042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dental.xiaoxiao.media"; classtype:trojan-activity; sid:100004043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dentalalliance.se"; classtype:trojan-activity; sid:100004044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"designerliving.co.za"; classtype:trojan-activity; sid:100004045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"desiringhands.com"; classtype:trojan-activity; sid:100004046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"despertaresi.com.br"; classtype:trojan-activity; sid:100004047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"destinymc.co.za"; classtype:trojan-activity; sid:100004048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"detorre.es"; classtype:trojan-activity; sid:100004049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev-interestingtech.pantheonsite.io"; classtype:trojan-activity; sid:100004050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.sebpo.net"; classtype:trojan-activity; sid:100004051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dezcom.com"; classtype:trojan-activity; sid:100004052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfcf.91756.cn"; classtype:trojan-activity; sid:100004053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"diamantenegro.mi-fs.com"; classtype:trojan-activity; sid:100004054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dienmayminhhung.com"; classtype:trojan-activity; sid:100004055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digilib.dianhusada.ac.id"; classtype:trojan-activity; sid:100004056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"djking.f3322.net"; classtype:trojan-activity; sid:100004057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl-link.link"; classtype:trojan-activity; sid:100004058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.1003b.56a.com"; classtype:trojan-activity; sid:100004059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.198424.com"; classtype:trojan-activity; sid:100004060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.installcdn-aws.com"; classtype:trojan-activity; sid:100004061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.packetstormsecurity.net"; classtype:trojan-activity; sid:100004062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.rina-roleplay.com"; classtype:trojan-activity; sid:100004063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.zkytech.com"; classtype:trojan-activity; sid:100004064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dns.cyberium.cc"; classtype:trojan-activity; sid:100004065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dockerupdate.anondns.net"; classtype:trojan-activity; sid:100004066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"docman.orientalservices.in"; classtype:trojan-activity; sid:100004067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dodsonimaging.com"; classtype:trojan-activity; sid:100004068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dokan.blueberrytec.com"; classtype:trojan-activity; sid:100004069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom-chel74.ru"; classtype:trojan-activity; sid:100004070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom.daf.free.fr"; classtype:trojan-activity; sid:100004071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doncedyhall.com"; classtype:trojan-activity; sid:100004072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donghobinhminh.com"; classtype:trojan-activity; sid:100004073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dongphuctop.com"; classtype:trojan-activity; sid:100004074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donwnloasecury.ath.cx"; classtype:trojan-activity; sid:100004075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosame.com"; classtype:trojan-activity; sid:100004076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosman.pl"; classtype:trojan-activity; sid:100004077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dovberger.com"; classtype:trojan-activity; sid:100004078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.flash-plays.com"; classtype:trojan-activity; sid:100004079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.pcclear.com"; classtype:trojan-activity; sid:100004080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.webbora.com"; classtype:trojan-activity; sid:100004081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down1.arpun.com"; classtype:trojan-activity; sid:100004082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.caihong.com"; classtype:trojan-activity; sid:100004083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.doumaibiji.cn"; classtype:trojan-activity; sid:100004084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.exrnybuf.cn"; classtype:trojan-activity; sid:100004085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.kaobeitu.com"; classtype:trojan-activity; sid:100004086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.pdf00.cn"; classtype:trojan-activity; sid:100004087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.rising.com.cn"; classtype:trojan-activity; sid:100004088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.skycn.com"; classtype:trojan-activity; sid:100004089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.zjsyawqj.cn"; classtype:trojan-activity; sid:100004090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"downloads.jxtsteel.cn"; classtype:trojan-activity; sid:100004091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dragonsknot.com"; classtype:trojan-activity; sid:100004092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drbaby.com.sa"; classtype:trojan-activity; sid:100004093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drohnen.ensenanzainteligente.com"; classtype:trojan-activity; sid:100004094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drools-moved.46999.n3.nabble.com"; classtype:trojan-activity; sid:100004095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drsha.innovativesolutions.mobi"; classtype:trojan-activity; sid:100004096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsenterprize.co.za"; classtype:trojan-activity; sid:100004097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsspainting.com"; classtype:trojan-activity; sid:100004098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"du-wizards.com"; classtype:trojan-activity; sid:100004099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duckrambo.com"; classtype:trojan-activity; sid:100004100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duque.guantanameratravel.com"; classtype:trojan-activity; sid:100004101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dutapp.wisolve.co.za"; classtype:trojan-activity; sid:100004102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duvalcharter.dekitout.com"; classtype:trojan-activity; sid:100004103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dx.qqyewu.com"; classtype:trojan-activity; sid:100004104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dzinestudio87.co.uk"; classtype:trojan-activity; sid:100004105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e-commerce.saleensuporte.com.br"; classtype:trojan-activity; sid:100004106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e.sldov.ru"; classtype:trojan-activity; sid:100004107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ebruyatkin.com"; classtype:trojan-activity; sid:100004108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"econews.treegle.org"; classtype:trojan-activity; sid:100004109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"efficientegroup.com"; classtype:trojan-activity; sid:100004110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"en.baoend.com"; classtype:trojan-activity; sid:100004111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enc-tech.com"; classtype:trojan-activity; sid:100004112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"endurotanzania.co.tz"; classtype:trojan-activity; sid:100004113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ennovate.elin.co.za"; classtype:trojan-activity; sid:100004114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enriquecendocomconsorcio.com.br"; classtype:trojan-activity; sid:100004115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"envios.petpienso.cl"; classtype:trojan-activity; sid:100004116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"equimination.ee"; classtype:trojan-activity; sid:100004117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"escola.probommar.org.br"; classtype:trojan-activity; sid:100004118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"esnconsultants.com"; classtype:trojan-activity; sid:100004119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"essentia.org.br"; classtype:trojan-activity; sid:100004120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eubanks7.com"; classtype:trojan-activity; sid:100004121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"evidencemarketing.ca"; classtype:trojan-activity; sid:100004122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exilum.com"; classtype:trojan-activity; sid:100004123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exitoalfaomega.co"; classtype:trojan-activity; sid:100004124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"extrovertoffers.com"; classtype:trojan-activity; sid:100004125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"familydentist.site"; classtype:trojan-activity; sid:100004126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"farmaciasdrogaminas.com.br"; classtype:trojan-activity; sid:100004127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fate3.xyz"; classtype:trojan-activity; sid:100004128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"faveraprojects.com"; classtype:trojan-activity; sid:100004129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fc.co.mz"; classtype:trojan-activity; sid:100004130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"felicienne.nl"; classtype:trojan-activity; sid:100004131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fi.bonitastores.com"; classtype:trojan-activity; sid:100004132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files.martellexpress.us"; classtype:trojan-activity; sid:100004133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"final.makkahkmcc.com"; classtype:trojan-activity; sid:100004134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fineartgallerym.com"; classtype:trojan-activity; sid:100004135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fixauto.illumetechnology.com"; classtype:trojan-activity; sid:100004136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fkd.derpcity.ru"; classtype:trojan-activity; sid:100004137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flintspin.com"; classtype:trojan-activity; sid:100004138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flyingbuddhadesign.com"; classtype:trojan-activity; sid:100004139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fmjplastering.co.uk"; classtype:trojan-activity; sid:100004140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fms.buladde.or.ug"; classtype:trojan-activity; sid:100004141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foothills.com.br"; classtype:trojan-activity; sid:100004142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"footweardirect.elin.co.za"; classtype:trojan-activity; sid:100004143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"forum.mdb.nu"; classtype:trojan-activity; sid:100004144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fotoobjetivo.com"; classtype:trojan-activity; sid:100004145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foxeps.com.br"; classtype:trojan-activity; sid:100004146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freecnetdownload.com"; classtype:trojan-activity; sid:100004147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freedombookshop.tickme.lk"; classtype:trojan-activity; sid:100004148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freisites.com.br"; classtype:trojan-activity; sid:100004149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ftp.n3twork30cm.ml"; classtype:trojan-activity; sid:100004150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fullelectronica.com.ar"; classtype:trojan-activity; sid:100004151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"funletters.net"; classtype:trojan-activity; sid:100004152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fusionfiresolutions.com"; classtype:trojan-activity; sid:100004153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gametwogame.com"; classtype:trojan-activity; sid:100004154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garciadogshow.com"; classtype:trojan-activity; sid:100004155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow.myvnc.com"; classtype:trojan-activity; sid:100004156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow4.myvnc.com"; classtype:trojan-activity; sid:100004157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gbbulls.co.uk"; classtype:trojan-activity; sid:100004158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gcpc.co.id.chronoscurtain.com"; classtype:trojan-activity; sid:100004159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"generaldeviales.com"; classtype:trojan-activity; sid:100004160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfmodd1.webselffiles01.com"; classtype:trojan-activity; sid:100004161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfold1.webselffiles01.com"; classtype:trojan-activity; sid:100004162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghettohub.co.za"; classtype:trojan-activity; sid:100004163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghislain.dartois.pagesperso-orange.fr"; classtype:trojan-activity; sid:100004164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giadungg7.com"; classtype:trojan-activity; sid:100004165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giddos.ga"; classtype:trojan-activity; sid:100004166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"girotexuniformes.com"; classtype:trojan-activity; sid:100004167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giteletropical.com"; classtype:trojan-activity; sid:100004168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"globaltask.ar"; classtype:trojan-activity; sid:100004169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"glowinmedia.co.ke"; classtype:trojan-activity; sid:100004170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmtransformationacademy.com"; classtype:trojan-activity; sid:100004171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmvadmission.org"; classtype:trojan-activity; sid:100004172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnimelf.net"; classtype:trojan-activity; sid:100004173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnscrew.ro"; classtype:trojan-activity; sid:100004174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gold.investforex.id"; classtype:trojan-activity; sid:100004175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcake.co.id"; classtype:trojan-activity; sid:100004176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com"; classtype:trojan-activity; sid:100004177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com.au"; classtype:trojan-activity; sid:100004178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcupmortgage.com"; classtype:trojan-activity; sid:100004179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"golden-memories-funerals.yourpageserver.com"; classtype:trojan-activity; sid:100004180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldmen.in"; classtype:trojan-activity; sid:100004181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gracejukes.com"; classtype:trojan-activity; sid:100004182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"grupoinmare.com"; classtype:trojan-activity; sid:100004183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gruposelt.000webhostapp.com"; classtype:trojan-activity; sid:100004184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gs.monerorx.com"; classtype:trojan-activity; sid:100004185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gulfac-house.com"; classtype:trojan-activity; sid:100004186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gvpcdpgc.edu.in"; classtype:trojan-activity; sid:100004187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"habbotips.free.fr"; classtype:trojan-activity; sid:100004188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hagebakken.no"; classtype:trojan-activity; sid:100004189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"harshraval.in"; classtype:trojan-activity; sid:100004190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hd11315.com"; classtype:trojan-activity; sid:100004191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hdkamera2003.hu"; classtype:trojan-activity; sid:100004192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hdrest.fastlinktz.com"; classtype:trojan-activity; sid:100004193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hds.sz4h.com"; classtype:trojan-activity; sid:100004194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"healthy20.net"; classtype:trojan-activity; sid:100004195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"heavymaq.cl"; classtype:trojan-activity; sid:100004196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com"; classtype:trojan-activity; sid:100004197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hellogorgeous.com.au"; classtype:trojan-activity; sid:100004198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"help.hizuko.com"; classtype:trojan-activity; sid:100004199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"herchinfitout.com.sg"; classtype:trojan-activity; sid:100004200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hhaward.org"; classtype:trojan-activity; sid:100004201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandroadcoc.com"; classtype:trojan-activity; sid:100004202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandslasvegas.atakdev.com"; classtype:trojan-activity; sid:100004203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hindi.factsriver.com"; classtype:trojan-activity; sid:100004204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hiptool.net"; classtype:trojan-activity; sid:100004205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitpe.com"; classtype:trojan-activity; sid:100004206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitstation.nl"; classtype:trojan-activity; sid:100004207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hmpmall.co.kr"; classtype:trojan-activity; sid:100004208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoagietesting10.com"; classtype:trojan-activity; sid:100004209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoayeuthuong-my.sharepoint.com"; classtype:trojan-activity; sid:100004210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"homefindersolutions.com"; classtype:trojan-activity; sid:100004211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hongluosi.com"; classtype:trojan-activity; sid:100004212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hookedupboatclub.com"; classtype:trojan-activity; sid:100004213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostzaa.com"; classtype:trojan-activity; sid:100004214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"houstonshutters.site"; classtype:trojan-activity; sid:100004215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hr2019.vrcom7.com"; classtype:trojan-activity; sid:100004216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hseda.com"; classtype:trojan-activity; sid:100004217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hsmwebapp.com"; classtype:trojan-activity; sid:100004218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"htownbars.com"; classtype:trojan-activity; sid:100004219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hubtech.co.za"; classtype:trojan-activity; sid:100004220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hunggiang.vn"; classtype:trojan-activity; sid:100004221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"husamiyahschool.com"; classtype:trojan-activity; sid:100004222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iam313.com"; classtype:trojan-activity; sid:100004223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"icon.shatangmu.cn"; classtype:trojan-activity; sid:100004224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idea-secure-login.com"; classtype:trojan-activity; sid:100004225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idilsoft.com"; classtype:trojan-activity; sid:100004226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idj.no"; classtype:trojan-activity; sid:100004227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idvindia.com"; classtype:trojan-activity; sid:100004228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iesanjosemonitos.edu.co"; classtype:trojan-activity; sid:100004229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ikexpert.com"; classtype:trojan-activity; sid:100004230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ilrafrica.com"; classtype:trojan-activity; sid:100004231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"imbueautoworx.co.za"; classtype:trojan-activity; sid:100004232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incodimsa.com"; classtype:trojan-activity; sid:100004233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incrediblepixels.com"; classtype:trojan-activity; sid:100004234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incredicole.com"; classtype:trojan-activity; sid:100004235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infair.vn"; classtype:trojan-activity; sid:100004236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infovator.com"; classtype:trojan-activity; sid:100004237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"innatosbrand.com"; classtype:trojan-activity; sid:100004238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inodesthetotaldesigners.com"; classtype:trojan-activity; sid:100004239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inovations.searchkero.com"; classtype:trojan-activity; sid:100004240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inrajahmundry.co.in"; classtype:trojan-activity; sid:100004241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"insignificantfinecore.testmail4.repl.co"; classtype:trojan-activity; sid:100004242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"instantindialoan.com"; classtype:trojan-activity; sid:100004243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intellectsmart.in"; classtype:trojan-activity; sid:100004244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intersel-idf.org"; classtype:trojan-activity; sid:100004245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intuitiveideas.com.my"; classtype:trojan-activity; sid:100004246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inversiones.arrayanfinanciero.cl"; classtype:trojan-activity; sid:100004247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"invest.xpcorporative.com.br"; classtype:trojan-activity; sid:100004248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"investinae.com"; classtype:trojan-activity; sid:100004249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ipmes.ma"; classtype:trojan-activity; sid:100004250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iremart.es"; classtype:trojan-activity; sid:100004251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iris101.co.uk"; classtype:trojan-activity; sid:100004252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isaac.mikhailmotoringschool.com"; classtype:trojan-activity; sid:100004253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iscamenabe.com"; classtype:trojan-activity; sid:100004254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ismf.com.ng"; classtype:trojan-activity; sid:100004255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iso-dubai.net"; classtype:trojan-activity; sid:100004256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"israrulhaq.me"; classtype:trojan-activity; sid:100004257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isrorg.com"; classtype:trojan-activity; sid:100004258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isso.ps"; classtype:trojan-activity; sid:100004259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"it123.ru"; classtype:trojan-activity; sid:100004260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itc-demo.softgig.co.ke"; classtype:trojan-activity; sid:100004261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itconsultus.com.co"; classtype:trojan-activity; sid:100004262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamiekaylive.com"; classtype:trojan-activity; sid:100004263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamshed.pk"; classtype:trojan-activity; sid:100004264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jansen-heesch.nl"; classtype:trojan-activity; sid:100004265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jathra.co.uk"; classtype:trojan-activity; sid:100004266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jay.diamondrelationscrm.us"; classtype:trojan-activity; sid:100004267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jebs.net.au"; classtype:trojan-activity; sid:100004268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jeffdahlke.com"; classtype:trojan-activity; sid:100004269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jhayesconsulting.com"; classtype:trojan-activity; sid:100004270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jiaoyuzixun.cn"; classtype:trojan-activity; sid:100004271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jing-da.com.tw"; classtype:trojan-activity; sid:100004272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jmcomputacion.com.ar"; classtype:trojan-activity; sid:100004273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jmtc.91756.cn"; classtype:trojan-activity; sid:100004274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jnanbharati.com"; classtype:trojan-activity; sid:100004275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jobs.thebeessolution.com"; classtype:trojan-activity; sid:100004276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"joelbonissilver.com"; classtype:trojan-activity; sid:100004277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"join.cl8movement.co.za"; classtype:trojan-activity; sid:100004278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josegene.com"; classtype:trojan-activity; sid:100004279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josuarochoa.com"; classtype:trojan-activity; sid:100004280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jpwoodfordco.com"; classtype:trojan-activity; sid:100004281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jumpmanualjacobhiller.com"; classtype:trojan-activity; sid:100004282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jupiter.toxsl.in"; classtype:trojan-activity; sid:100004283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"justinscott.com.au"; classtype:trojan-activity; sid:100004284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalawatihomes.com"; classtype:trojan-activity; sid:100004285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalpataru-elitus-mulund.thakkers.in"; classtype:trojan-activity; sid:100004286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"karer.by"; classtype:trojan-activity; sid:100004287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"katanvetov.co.il"; classtype:trojan-activity; sid:100004288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kensingtondriving.com"; classtype:trojan-activity; sid:100004289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kevinjewelry.com.co"; classtype:trojan-activity; sid:100004290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"keywatch.yourpageserver.com"; classtype:trojan-activity; sid:100004291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kingssa.co.za"; classtype:trojan-activity; sid:100004292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kjcpromo.com"; classtype:trojan-activity; sid:100004293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kleinendeli.co.za"; classtype:trojan-activity; sid:100004294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"korrectconceptservices.com"; classtype:trojan-activity; sid:100004295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ktb.sch.id"; classtype:trojan-activity; sid:100004296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kubatoglubaklava.com.tr"; classtype:trojan-activity; sid:100004297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kumaralok.in"; classtype:trojan-activity; sid:100004298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kwanfromhongkong.com"; classtype:trojan-activity; sid:100004299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kz.sldov.ru"; classtype:trojan-activity; sid:100004300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lacasadelosalebrijes.com"; classtype:trojan-activity; sid:100004301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ladylabonde.com"; classtype:trojan-activity; sid:100004302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lameguard.ru"; classtype:trojan-activity; sid:100004303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laodongnhat.vn"; classtype:trojan-activity; sid:100004304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laravel.pointersoftwares.com.br"; classtype:trojan-activity; sid:100004305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lasermobilesounds.co.uk"; classtype:trojan-activity; sid:100004306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lauratomismith.com"; classtype:trojan-activity; sid:100004307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lautarosanmiguel.com"; classtype:trojan-activity; sid:100004308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawforall.edu.lk"; classtype:trojan-activity; sid:100004309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lceventos.net"; classtype:trojan-activity; sid:100004310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ld.mediaget.com"; classtype:trojan-activity; sid:100004311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ldgcorp.com"; classtype:trojan-activity; sid:100004312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"learning.real-academy.net"; classtype:trojan-activity; sid:100004313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leasiacherise.com"; classtype:trojan-activity; sid:100004314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leczkregoslup.acelero.pl"; classtype:trojan-activity; sid:100004315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"legend.nu"; classtype:trojan-activity; sid:100004316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leluibuffet.com.br"; classtype:trojan-activity; sid:100004317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lestesteux.ca"; classtype:trojan-activity; sid:100004318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"libantravel.pl"; classtype:trojan-activity; sid:100004319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.arihantmbainstitute.ac.in"; classtype:trojan-activity; sid:100004320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.uib.ac.id"; classtype:trojan-activity; sid:100004321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lidoraggiodisole.it"; classtype:trojan-activity; sid:100004322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lifebeam.elin.co.za"; classtype:trojan-activity; sid:100004323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lindnerelektroanlagen.de"; classtype:trojan-activity; sid:100004324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"linkintec.cn"; classtype:trojan-activity; sid:100004325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"livetrack.in"; classtype:trojan-activity; sid:100004326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lloydsindian.co.uk"; classtype:trojan-activity; sid:100004327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lm.stagingarea.co.za"; classtype:trojan-activity; sid:100004328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmaancha.co.il"; classtype:trojan-activity; sid:100004329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.cstdevs.com"; classtype:trojan-activity; sid:100004330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.login2.in"; classtype:trojan-activity; sid:100004331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmvirtualbookkeeping.com"; classtype:trojan-activity; sid:100004332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lnt-rejuve-360.thakkers.in"; classtype:trojan-activity; sid:100004333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"location-voitures.ma"; classtype:trojan-activity; sid:100004334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"login.trezor.com.stockfootagesindia.com"; classtype:trojan-activity; sid:100004335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"logotypfabriken.se"; classtype:trojan-activity; sid:100004336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotix.de"; classtype:trojan-activity; sid:100004337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotusanddragonfly.com"; classtype:trojan-activity; sid:100004338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.definerisco.com"; classtype:trojan-activity; sid:100004339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.difusodesign.com"; classtype:trojan-activity; sid:100004340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ltc.typoten.com"; classtype:trojan-activity; sid:100004341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luckybrownie.com"; classtype:trojan-activity; sid:100004342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luminouspneuma.com"; classtype:trojan-activity; sid:100004343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luxomodels.com"; classtype:trojan-activity; sid:100004344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m-technics.kz"; classtype:trojan-activity; sid:100004345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m.estudiomoros.com.ar"; classtype:trojan-activity; sid:100004346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"madicon.co.za"; classtype:trojan-activity; sid:100004347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"magianegramagiablancayamarres.com"; classtype:trojan-activity; sid:100004348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.bs-eiendomme.co.za"; classtype:trojan-activity; sid:100004349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.golimoapp.com"; classtype:trojan-activity; sid:100004350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.jeffsono.org"; classtype:trojan-activity; sid:100004351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maksi.feb.unib.ac.id"; classtype:trojan-activity; sid:100004352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malaya.tv"; classtype:trojan-activity; sid:100004353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malwarecoding.github.io"; classtype:trojan-activity; sid:100004354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managed.oss-cn-beijing.aliyuncs.com"; classtype:trojan-activity; sid:100004355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managemysalon.in"; classtype:trojan-activity; sid:100004356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manantialesdelnorte.uy"; classtype:trojan-activity; sid:100004357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manhtien.net"; classtype:trojan-activity; sid:100004358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marcapinyo.ru"; classtype:trojan-activity; sid:100004359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mario-sunjic.com"; classtype:trojan-activity; sid:100004360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariobrown.net"; classtype:trojan-activity; sid:100004361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariotessarollo.com"; classtype:trojan-activity; sid:100004362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketinfosales.com"; classtype:trojan-activity; sid:100004363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketing.enexusgroup.com.au"; classtype:trojan-activity; sid:100004364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marksidfgs.ug"; classtype:trojan-activity; sid:100004365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"masjidhabeebiyarazviya.mysunni.com"; classtype:trojan-activity; sid:100004366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"materialescantu.com"; classtype:trojan-activity; sid:100004367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"matruchhaya.co.in"; classtype:trojan-activity; sid:100004368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mattysplayground.com"; classtype:trojan-activity; sid:100004369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxiquim.cl"; classtype:trojan-activity; sid:100004370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxtox.com.pk"; classtype:trojan-activity; sid:100004371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbgrm.com"; classtype:trojan-activity; sid:100004372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbsolutions.ge"; classtype:trojan-activity; sid:100004373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mdasa.elin.co.za"; classtype:trojan-activity; sid:100004374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medevlb.org"; classtype:trojan-activity; sid:100004375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"media-server.skyinternet.com.pk"; classtype:trojan-activity; sid:100004376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mediamaster.co.za"; classtype:trojan-activity; sid:100004377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medianews.ge"; classtype:trojan-activity; sid:100004378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medistaffconsulting.com"; classtype:trojan-activity; sid:100004379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meditreat.itwebservice.in"; classtype:trojan-activity; sid:100004380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meeweb.com"; classtype:trojan-activity; sid:100004381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megamart.afnan-amc.com"; classtype:trojan-activity; sid:100004382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merbay.ru"; classtype:trojan-activity; sid:100004383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merkathink.com"; classtype:trojan-activity; sid:100004384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mertlog.com"; classtype:trojan-activity; sid:100004385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"metalin-cr.com"; classtype:trojan-activity; sid:100004386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mettaanand.org"; classtype:trojan-activity; sid:100004387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meuoculosnanet.com.br"; classtype:trojan-activity; sid:100004388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mfevr.com"; classtype:trojan-activity; sid:100004389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot.myvnc.com"; classtype:trojan-activity; sid:100004390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot80.myvnc.com"; classtype:trojan-activity; sid:100004391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"micalle.com.au"; classtype:trojan-activity; sid:100004392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michaelphilip.com"; classtype:trojan-activity; sid:100004393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michimal2.000webhostapp.com"; classtype:trojan-activity; sid:100004394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microblading.mirliandias.com.br"; classtype:trojan-activity; sid:100004395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microcomm-group.com"; classtype:trojan-activity; sid:100004396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mikhailmotoringschool.com"; classtype:trojan-activity; sid:100004397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mindfulbuildingandliving.com"; classtype:trojan-activity; sid:100004398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mingguanwms.com"; classtype:trojan-activity; sid:100004399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"minuevavida.org"; classtype:trojan-activity; sid:100004400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mirror.mypage.sk"; classtype:trojan-activity; sid:100004401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mis.nbcc.ac.th"; classtype:trojan-activity; sid:100004402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"misterson.com"; classtype:trojan-activity; sid:100004403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mixr.at"; classtype:trojan-activity; sid:100004404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mkontakt.az"; classtype:trojan-activity; sid:100004405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mktf.mx"; classtype:trojan-activity; sid:100004406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmogollon.com.mx"; classtype:trojan-activity; sid:100004407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mncarteam.com"; classtype:trojan-activity; sid:100004408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mobile.illumetechnology.com"; classtype:trojan-activity; sid:100004409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modelhouseturkey.com"; classtype:trojan-activity; sid:100004410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modernmanna.org"; classtype:trojan-activity; sid:100004411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"monetization.business"; classtype:trojan-activity; sid:100004412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moninediy.com"; classtype:trojan-activity; sid:100004413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mopai.sg"; classtype:trojan-activity; sid:100004414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"motorcomunicacion.com"; classtype:trojan-activity; sid:100004415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"msacontabil.com.br"; classtype:trojan-activity; sid:100004416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mtspsmjeli.sch.id"; classtype:trojan-activity; sid:100004417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"muzimbiti.xigubo.co.mz"; classtype:trojan-activity; sid:100004418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mxpiqw.am.files.1drv.com"; classtype:trojan-activity; sid:100004419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mydatebook.in"; classtype:trojan-activity; sid:100004420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mymlql.com"; classtype:trojan-activity; sid:100004421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myritz.vettickal.com"; classtype:trojan-activity; sid:100004422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myscape.in"; classtype:trojan-activity; sid:100004423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysura.it"; classtype:trojan-activity; sid:100004424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"namnyak.co.ke"; classtype:trojan-activity; sid:100004425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nap.mgsservers.com"; classtype:trojan-activity; sid:100004426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"navayurveda.in"; classtype:trojan-activity; sid:100004427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nbs.vizzhost.com"; classtype:trojan-activity; sid:100004428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nec-i.com"; classtype:trojan-activity; sid:100004429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nelitrianggraeni.000webhostapp.com"; classtype:trojan-activity; sid:100004430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nerve.untergrund.net"; classtype:trojan-activity; sid:100004431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nettube.com.br"; classtype:trojan-activity; sid:100004432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"networkwheels.co.za"; classtype:trojan-activity; sid:100004433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neuromedic.com.br"; classtype:trojan-activity; sid:100004434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neverseenshop.com.mx"; classtype:trojan-activity; sid:100004435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newinfinitysynergy.com"; classtype:trojan-activity; sid:100004436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"news.dbstrony.pl"; classtype:trojan-activity; sid:100004437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtreedesign.co.uk"; classtype:trojan-activity; sid:100004438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtrendeg.com"; classtype:trojan-activity; sid:100004439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newvisionopticallab.com"; classtype:trojan-activity; sid:100004440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newxing.com"; classtype:trojan-activity; sid:100004441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nextdigitalday.ru"; classtype:trojan-activity; sid:100004442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ngdaycare.co.za"; classtype:trojan-activity; sid:100004443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nguyenkekhuyen.com"; classtype:trojan-activity; sid:100004444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nhorangtreem.com"; classtype:trojan-activity; sid:100004445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nicolas.ug"; classtype:trojan-activity; sid:100004446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nidhi.iexist.in"; classtype:trojan-activity; sid:100004447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nikanpolimer.ir"; classtype:trojan-activity; sid:100004448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilehouse.co.ug"; classtype:trojan-activity; sid:100004449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilinkeji.com"; classtype:trojan-activity; sid:100004450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"njtiledesigncenter.com"; classtype:trojan-activity; sid:100004451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nobius.org"; classtype:trojan-activity; sid:100004452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nocalnoodle.elin.co.za"; classtype:trojan-activity; sid:100004453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nomadicbees.com"; classtype:trojan-activity; sid:100004454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nonnarina.ax"; classtype:trojan-activity; sid:100004455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"notamuzikaletleri.com"; classtype:trojan-activity; sid:100004456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ns1.the-widyantos.com"; classtype:trojan-activity; sid:100004457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsb.org.uk"; classtype:trojan-activity; sid:100004458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsheldon.co.uk"; classtype:trojan-activity; sid:100004459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nuthuassociates.com"; classtype:trojan-activity; sid:100004460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nuwagi.com"; classtype:trojan-activity; sid:100004461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyeh2o.com.au"; classtype:trojan-activity; sid:100004462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oakleyandfriends.co.uk"; classtype:trojan-activity; sid:100004463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"obseques-conseils.com"; classtype:trojan-activity; sid:100004464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohe.ie"; classtype:trojan-activity; sid:100004465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohsewgorgeous.co.uk"; classtype:trojan-activity; sid:100004466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oknoplastik.sk"; classtype:trojan-activity; sid:100004467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oleholeh.memangbeda.website"; classtype:trojan-activity; sid:100004468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"olirecords.mixture.ltd"; classtype:trojan-activity; sid:100004469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"olooom.com"; classtype:trojan-activity; sid:100004470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaia.org"; classtype:trojan-activity; sid:100004471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaromatic.com"; classtype:trojan-activity; sid:100004472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omega.az"; classtype:trojan-activity; sid:100004473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oms.pappai.com"; classtype:trojan-activity; sid:100004474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omscoc.pappai.com"; classtype:trojan-activity; sid:100004475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedigitalcard.granvizionnecorp.com"; classtype:trojan-activity; sid:100004476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedrive.listifyapp.co"; classtype:trojan-activity; sid:100004477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"online.creedglobal.in"; classtype:trojan-activity; sid:100004478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onlinestatis.bar"; classtype:trojan-activity; sid:100004479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ont.proman.id"; classtype:trojan-activity; sid:100004480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"open.warehousesaas.co.uk"; classtype:trojan-activity; sid:100004481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opolis.io"; classtype:trojan-activity; sid:100004482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opticaoptigral.cl"; classtype:trojan-activity; sid:100004483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optimus.com.sg"; classtype:trojan-activity; sid:100004484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optitechsa.co.za"; classtype:trojan-activity; sid:100004485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"order.bizpeed.com"; classtype:trojan-activity; sid:100004486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orientgatewayltd.com"; classtype:trojan-activity; sid:100004487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orion445.com"; classtype:trojan-activity; sid:100004488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orpod.ru"; classtype:trojan-activity; sid:100004489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oserve.pk"; classtype:trojan-activity; sid:100004490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ottimade.com"; classtype:trojan-activity; sid:100004491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ourteam.searchkero.com"; classtype:trojan-activity; sid:100004492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ozemag.com"; classtype:trojan-activity; sid:100004493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p1.lingpao8.com"; classtype:trojan-activity; sid:100004494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p3.zbjimg.com"; classtype:trojan-activity; sid:100004495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p6.zbjimg.com"; classtype:trojan-activity; sid:100004496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pablobrothel.com.ar"; classtype:trojan-activity; sid:100004497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacificgroup.ws"; classtype:trojan-activity; sid:100004498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacwebdesigns.com"; classtype:trojan-activity; sid:100004499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pagos.krayem.com.mx"; classtype:trojan-activity; sid:100004500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"palochusvet.szm.com"; classtype:trojan-activity; sid:100004501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parallel.rockvideos.at"; classtype:trojan-activity; sid:100004502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parejasfelices.mi-fs.com"; classtype:trojan-activity; sid:100004503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parkhussion.com"; classtype:trojan-activity; sid:100004504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pastorpaulocosta.com"; classtype:trojan-activity; sid:100004505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.51lg.com"; classtype:trojan-activity; sid:100004506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.99ddd.com"; classtype:trojan-activity; sid:100004507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch3.99ddd.com"; classtype:trojan-activity; sid:100004508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paths.elin.co.za"; classtype:trojan-activity; sid:100004509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paulmercier.biz"; classtype:trojan-activity; sid:100004510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payerrealty.com"; classtype:trojan-activity; sid:100004511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payments.atifsiddiqui.me"; classtype:trojan-activity; sid:100004512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pcsoori.com"; classtype:trojan-activity; sid:100004513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pd.oceaniarp.net"; classtype:trojan-activity; sid:100004514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpustekim.untirta.ac.id"; classtype:trojan-activity; sid:100004515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"petercollie.com"; classtype:trojan-activity; sid:100004516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ph4s.ru"; classtype:trojan-activity; sid:100004517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phasdesign.com"; classtype:trojan-activity; sid:100004518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phenhuong.sanpham.online"; classtype:trojan-activity; sid:100004519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phittc.com"; classtype:trojan-activity; sid:100004520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photo360.kubooking.com"; classtype:trojan-activity; sid:100004521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photographytipsclub.com"; classtype:trojan-activity; sid:100004522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pink99.com"; classtype:trojan-activity; sid:100004523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pizzabarletta.com.br"; classtype:trojan-activity; sid:100004524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"plasfan.ind.br"; classtype:trojan-activity; sid:100004525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pmglance.startwriteup.com"; classtype:trojan-activity; sid:100004526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pokojewewladyslawowie.pl"; classtype:trojan-activity; sid:100004527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pole.com.vc"; classtype:trojan-activity; sid:100004528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pool.phxdir.com"; classtype:trojan-activity; sid:100004529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pooltablemoversdenver.net"; classtype:trojan-activity; sid:100004530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"posmicrosystems.com"; classtype:trojan-activity; sid:100004531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"poulman.panagiotopoulos-tours.gr"; classtype:trojan-activity; sid:100004532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ppdb.smk-ciptaskill.sch.id"; classtype:trojan-activity; sid:100004533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pptvideotemplates.com"; classtype:trojan-activity; sid:100004534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestasicash.com.ar"; classtype:trojan-activity; sid:100004535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestigehomeautomation.net"; classtype:trojan-activity; sid:100004536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prishaartcreations.com"; classtype:trojan-activity; sid:100004537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"production.sparshims.com"; classtype:trojan-activity; sid:100004538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"programaoperadoronline.com.br"; classtype:trojan-activity; sid:100004539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"project.exquitec.com"; classtype:trojan-activity; sid:100004540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promotoradescomplica.com.br"; classtype:trojan-activity; sid:100004541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promoversdubai.com"; classtype:trojan-activity; sid:100004542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq.elin.co.za"; classtype:trojan-activity; sid:100004543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq2.elin.co.za"; classtype:trojan-activity; sid:100004544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosoc.nl"; classtype:trojan-activity; sid:100004545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosyarmakassar.com"; classtype:trojan-activity; sid:100004546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"provence.elin.co.za"; classtype:trojan-activity; sid:100004547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prueba.danielluza.com"; classtype:trojan-activity; sid:100004548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pujashoppe.in"; classtype:trojan-activity; sid:100004549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punchdialogues.com"; classtype:trojan-activity; sid:100004550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punjabdevelopersassociation.com.pk"; classtype:trojan-activity; sid:100004551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"purefoe.top"; classtype:trojan-activity; sid:100004552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pvcprinting.co.uk"; classtype:trojan-activity; sid:100004553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qadir.tickfa.ir"; classtype:trojan-activity; sid:100004554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qatarglobalconsulting.com"; classtype:trojan-activity; sid:100004555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qmsled.com"; classtype:trojan-activity; sid:100004556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"quartier-midi.be"; classtype:trojan-activity; sid:100004557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"querocar.com"; classtype:trojan-activity; sid:100004558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rachmat-assuhaimi.my.id"; classtype:trojan-activity; sid:100004559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rainbowisp.info"; classtype:trojan-activity; sid:100004560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raodigitalmedia.com"; classtype:trojan-activity; sid:100004561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rarlabarchiver.ac"; classtype:trojan-activity; sid:100004562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rasadbar.ir"; classtype:trojan-activity; sid:100004563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rashika.ascarvalho.co.za"; classtype:trojan-activity; sid:100004564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ratemyfenancialadvisor.com"; classtype:trojan-activity; sid:100004565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ravenproductionsltd.com"; classtype:trojan-activity; sid:100004566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rc.ixiaoyang.cn"; classtype:trojan-activity; sid:100004567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rcmesilva.charbelsales.com.br"; classtype:trojan-activity; sid:100004568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"readymmade.com"; classtype:trojan-activity; sid:100004569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redchillicrackers.com"; classtype:trojan-activity; sid:100004570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reifenquick.de"; classtype:trojan-activity; sid:100004571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"relaxindulge.co.nz"; classtype:trojan-activity; sid:100004572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"renehavis.com.ua"; classtype:trojan-activity; sid:100004573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"repatriacioncolombia.com"; classtype:trojan-activity; sid:100004574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"res.uf1.cn"; classtype:trojan-activity; sid:100004575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.digimitra.in"; classtype:trojan-activity; sid:100004576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"resuco.net"; classtype:trojan-activity; sid:100004577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rezkabum.ru"; classtype:trojan-activity; sid:100004578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rhema.com.sg"; classtype:trojan-activity; sid:100004579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richancyber.info"; classtype:trojan-activity; sid:100004580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richmondminerals.co.zm"; classtype:trojan-activity; sid:100004581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinaefoundation.org.za"; classtype:trojan-activity; sid:100004582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinkaisystem-ht.com"; classtype:trojan-activity; sid:100004583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"riverfox.co.za"; classtype:trojan-activity; sid:100004584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkcable.co.in"; classtype:trojan-activity; sid:100004585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkverify.securestudies.com"; classtype:trojan-activity; sid:100004586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roadfurylifts.com"; classtype:trojan-activity; sid:100004587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertmcardle.com"; classtype:trojan-activity; sid:100004588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertsinclair.net"; classtype:trojan-activity; sid:100004589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robinhood-sports.com"; classtype:trojan-activity; sid:100004590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"romanianpoints.com"; classtype:trojan-activity; sid:100004591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ronnietucker.co.uk"; classtype:trojan-activity; sid:100004592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roomsvc.servegate.kr"; classtype:trojan-activity; sid:100004593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshan.academy"; classtype:trojan-activity; sid:100004594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshnijewellery.com"; classtype:trojan-activity; sid:100004595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rs-toolkit.mikestclair.org"; classtype:trojan-activity; sid:100004596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rsgym.net"; classtype:trojan-activity; sid:100004597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubazar.pro"; classtype:trojan-activity; sid:100004598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubycityvietnam.com"; classtype:trojan-activity; sid:100004599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruisgood.ru"; classtype:trojan-activity; sid:100004600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruwadalkuwait.com"; classtype:trojan-activity; sid:100004601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rydchile.cl"; classtype:trojan-activity; sid:100004602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rzminc.com"; classtype:trojan-activity; sid:100004603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.51shijuan.com"; classtype:trojan-activity; sid:100004604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.thechinesemuslim.com"; classtype:trojan-activity; sid:100004605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sacredscentsonline.com"; classtype:trojan-activity; sid:100004606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safcol-colors.com"; classtype:trojan-activity; sid:100004607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safehubsecurity.ca"; classtype:trojan-activity; sid:100004608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safety.nanotechproautocare.com"; classtype:trojan-activity; sid:100004609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sahathaikasetpan.com"; classtype:trojan-activity; sid:100004610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"saisoftwareinc.com"; classtype:trojan-activity; sid:100004611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salecorner.yourpageserver.com"; classtype:trojan-activity; sid:100004612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sandovalgraphics.com"; classtype:trojan-activity; sid:100004613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"santyago.org"; classtype:trojan-activity; sid:100004614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sarakem.cl"; classtype:trojan-activity; sid:100004615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sasystemsuk.com"; classtype:trojan-activity; sid:100004616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"savasaachi.systems"; classtype:trojan-activity; sid:100004617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scarfaceindustries.com"; classtype:trojan-activity; sid:100004618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scglobal.co.th"; classtype:trojan-activity; sid:100004619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schalke04rss.de"; classtype:trojan-activity; sid:100004620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scheff.com"; classtype:trojan-activity; sid:100004621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schoolbustracker.softgig.co.ke"; classtype:trojan-activity; sid:100004622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sec-doc-w.com"; classtype:trojan-activity; sid:100004623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"secure-doc-reader.com"; classtype:trojan-activity; sid:100004624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"segalsmetals.elin.co.za"; classtype:trojan-activity; sid:100004625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sellmyphonela.com"; classtype:trojan-activity; sid:100004626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"selltechtoday.com"; classtype:trojan-activity; sid:100004627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"senbiaojita.com"; classtype:trojan-activity; sid:100004628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sentierodelviandante.ml"; classtype:trojan-activity; sid:100004629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serendibsourcing.com"; classtype:trojan-activity; sid:100004630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd.myvnc.com"; classtype:trojan-activity; sid:100004631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd80.myvnc.com"; classtype:trojan-activity; sid:100004632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serviciovirtual.com.ar"; classtype:trojan-activity; sid:100004633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"seyranikenger.com.tr"; classtype:trojan-activity; sid:100004634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sgessy.com.br"; classtype:trojan-activity; sid:100004635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shaheentbfoundation.com"; classtype:trojan-activity; sid:100004636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahikhana.cstdevs.com"; classtype:trojan-activity; sid:100004637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharkrigs.com"; classtype:trojan-activity; sid:100004638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharpelevators.in"; classtype:trojan-activity; sid:100004639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shembefoundation.com"; classtype:trojan-activity; sid:100004640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shivakunwar.com.np"; classtype:trojan-activity; sid:100004641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shoblasaathitrust.org"; classtype:trojan-activity; sid:100004642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shooka-co.com"; classtype:trojan-activity; sid:100004643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shop.goldspot.agency"; classtype:trojan-activity; sid:100004644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shopsofe.com"; classtype:trojan-activity; sid:100004645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shrushtiinfotech.com"; classtype:trojan-activity; sid:100004646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sibernetix.fr"; classtype:trojan-activity; sid:100004647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sige.brisainformatica.com.br"; classtype:trojan-activity; sid:100004648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"signatureads.co.in"; classtype:trojan-activity; sid:100004649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siili.net"; classtype:trojan-activity; sid:100004650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simoneporzi.it"; classtype:trojan-activity; sid:100004651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simplithy.co.uk"; classtype:trojan-activity; sid:100004652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindicato1ucm.cl"; classtype:trojan-activity; sid:100004653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindpol.tiejuris.com.br"; classtype:trojan-activity; sid:100004654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sinergidwireka.com"; classtype:trojan-activity; sid:100004655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sipahielektrik.com"; classtype:trojan-activity; sid:100004656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siperb.in"; classtype:trojan-activity; sid:100004657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sistelligent.com"; classtype:trojan-activity; sid:100004658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skkksolo.beweiretail.com"; classtype:trojan-activity; sid:100004659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyflyfares.com"; classtype:trojan-activity; sid:100004660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyscan.com"; classtype:trojan-activity; sid:100004661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarthouseforum.ru"; classtype:trojan-activity; sid:100004662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarts.tj"; classtype:trojan-activity; sid:100004663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smartzedu.com"; classtype:trojan-activity; sid:100004664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokeandgrowrichtour.com"; classtype:trojan-activity; sid:100004665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokesolutionindia.com"; classtype:trojan-activity; sid:100004666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobethuacademy.com"; classtype:trojan-activity; sid:100004667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.110route.com"; classtype:trojan-activity; sid:100004668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.officelabo.net"; classtype:trojan-activity; sid:100004669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sohs.conceptechs.info"; classtype:trojan-activity; sid:100004670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solar.amazingtribe.lk"; classtype:trojan-activity; sid:100004671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solo2.dbstrony.pl"; classtype:trojan-activity; sid:100004672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somcorbera.cat"; classtype:trojan-activity; sid:100004673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somir.com.mx"; classtype:trojan-activity; sid:100004674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soralapps.com"; classtype:trojan-activity; sid:100004675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sorteio.orgaostalita.com.br"; classtype:trojan-activity; sid:100004676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sota-france.fr"; classtype:trojan-activity; sid:100004677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sowingminerals.cl"; classtype:trojan-activity; sid:100004678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"space.proactint.org"; classtype:trojan-activity; sid:100004679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spaceframe.mobi.space-frame.co.za"; classtype:trojan-activity; sid:100004680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"special-key.cf"; classtype:trojan-activity; sid:100004681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spent.com.pl"; classtype:trojan-activity; sid:100004682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spetsesyachtcharter.gr"; classtype:trojan-activity; sid:100004683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spititourism.com"; classtype:trojan-activity; sid:100004684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spittinfire.com"; classtype:trojan-activity; sid:100004685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sports-net.de"; classtype:trojan-activity; sid:100004686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"src1.minibai.com"; classtype:trojan-activity; sid:100004687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sreenivasapaintingworks.com"; classtype:trojan-activity; sid:100004688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sriglobalit.com"; classtype:trojan-activity; sid:100004689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srvmanos.no-ip.info"; classtype:trojan-activity; sid:100004690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ss.monita.co.id"; classtype:trojan-activity; sid:100004691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"staging.apparelpunch.com"; classtype:trojan-activity; sid:100004692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"starcountry.net"; classtype:trojan-activity; sid:100004693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"static.3001.net"; classtype:trojan-activity; sid:100004694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statsres.com"; classtype:trojan-activity; sid:100004695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statssound.com"; classtype:trojan-activity; sid:100004696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statsspot.com"; classtype:trojan-activity; sid:100004697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statsvilla.com"; classtype:trojan-activity; sid:100004698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stemschool.net"; classtype:trojan-activity; sid:100004699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiepancasetia.ac.id"; classtype:trojan-activity; sid:100004700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stott-thompson.co.uk"; classtype:trojan-activity; sid:100004701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stratexec.co.za"; classtype:trojan-activity; sid:100004702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"streetdemo.yourpageserver.com"; classtype:trojan-activity; sid:100004703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"suboldesign.com"; classtype:trojan-activity; sid:100004704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sumerians.org"; classtype:trojan-activity; sid:100004705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunbrero.com.au"; classtype:trojan-activity; sid:100004706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunmarkholidays.com"; classtype:trojan-activity; sid:100004707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supermercadostia.com"; classtype:trojan-activity; sid:100004708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support-4-free.com"; classtype:trojan-activity; sid:100004709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support.clz.kr"; classtype:trojan-activity; sid:100004710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supportit.online"; classtype:trojan-activity; sid:100004711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sw.yourpageserver.com"; classtype:trojan-activity; sid:100004712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweaty.dk"; classtype:trojan-activity; sid:100004713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweet-diet.com"; classtype:trojan-activity; sid:100004714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swentsai.com"; classtype:trojan-activity; sid:100004715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swiftlogisticseg.com"; classtype:trojan-activity; sid:100004716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swwbia.com"; classtype:trojan-activity; sid:100004717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"syracusecoffee.com"; classtype:trojan-activity; sid:100004718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sys.pbmadu.co.id"; classtype:trojan-activity; sid:100004719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sytraders.co"; classtype:trojan-activity; sid:100004720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.honker.info"; classtype:trojan-activity; sid:100004721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.netcatkit.com"; classtype:trojan-activity; sid:100004722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tacticohosting.com"; classtype:trojan-activity; sid:100004723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tadoo.ca"; classtype:trojan-activity; sid:100004724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tafsantoursandtravels.com"; classtype:trojan-activity; sid:100004725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tallyinvoicecustomization.com"; classtype:trojan-activity; sid:100004726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taltus.co.uk"; classtype:trojan-activity; sid:100004727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tapalkoedacoffee.com"; classtype:trojan-activity; sid:100004728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tarravalleyfoods.com.au"; classtype:trojan-activity; sid:100004729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taurus.ug"; classtype:trojan-activity; sid:100004730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tavo.cl"; classtype:trojan-activity; sid:100004731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taxicabsrilanka.com"; classtype:trojan-activity; sid:100004732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taxpos.com"; classtype:trojan-activity; sid:100004733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tc.snpsresidential.com"; classtype:trojan-activity; sid:100004734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tcy.198424.com"; classtype:trojan-activity; sid:100004735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tdsp.yngw518.com"; classtype:trojan-activity; sid:100004736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"techgms.com"; classtype:trojan-activity; sid:100004737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"technogreen.crmmanivela.com"; classtype:trojan-activity; sid:100004738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"technohub.searchkero.com"; classtype:trojan-activity; sid:100004739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tecnicaencolectores.com.mx"; classtype:trojan-activity; sid:100004740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tecnologyschool.com"; classtype:trojan-activity; sid:100004741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teduae.com"; classtype:trojan-activity; sid:100004742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teleargentina.com"; classtype:trojan-activity; sid:100004743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telescopelms.com"; classtype:trojan-activity; sid:100004744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telmed.cl"; classtype:trojan-activity; sid:100004745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"temptmag.com"; classtype:trojan-activity; sid:100004746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tentandoserfitness.000webhostapp.com"; classtype:trojan-activity; sid:100004747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.adventser.com"; classtype:trojan-activity; sid:100004748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.letraele.es"; classtype:trojan-activity; sid:100004749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.typoten.com"; classtype:trojan-activity; sid:100004750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.wanepghana.org"; classtype:trojan-activity; sid:100004751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.asistencia247.com"; classtype:trojan-activity; sid:100004752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.milenial.id"; classtype:trojan-activity; sid:100004753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.tenplusone.my"; classtype:trojan-activity; sid:100004754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.basis-web.com"; classtype:trojan-activity; sid:100004755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.marrenconstruction.ie"; classtype:trojan-activity; sid:100004756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.clickitsolutionsmw.com"; classtype:trojan-activity; sid:100004757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.thinkingcorp.in"; classtype:trojan-activity; sid:100004758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testnew.yourpageserver.com"; classtype:trojan-activity; sid:100004759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teteaffiche.stephanebillon.com"; classtype:trojan-activity; sid:100004760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tewoerd.eu"; classtype:trojan-activity; sid:100004761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"textile.softberg.ro"; classtype:trojan-activity; sid:100004762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"texturesbyvinita.com"; classtype:trojan-activity; sid:100004763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tharringtonsponsorship.com"; classtype:trojan-activity; sid:100004764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecleaningladiespdx.com"; classtype:trojan-activity; sid:100004765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecreativecafe.co.uk"; classtype:trojan-activity; sid:100004766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefuturelife.in"; classtype:trojan-activity; sid:100004767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehighlightinterior.com"; classtype:trojan-activity; sid:100004768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehouseofpragya.com"; classtype:trojan-activity; sid:100004769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thekassia.co.uk"; classtype:trojan-activity; sid:100004770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thelaunchpadteam.com"; classtype:trojan-activity; sid:100004771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thesummitpc.net"; classtype:trojan-activity; sid:100004772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theurbantutors.com"; classtype:trojan-activity; sid:100004773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thosewebbs.com"; classtype:trojan-activity; sid:100004774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tianangdep.com"; classtype:trojan-activity; sid:100004775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickfood.tickme.lk"; classtype:trojan-activity; sid:100004776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickjobs.tickme.lk"; classtype:trojan-activity; sid:100004777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickmart.tickme.lk"; classtype:trojan-activity; sid:100004778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"timegonebuy.com"; classtype:trojan-activity; sid:100004779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tksb.net"; classtype:trojan-activity; sid:100004780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tlcc.com.gt"; classtype:trojan-activity; sid:100004781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"todoapp.cstdevs.com"; classtype:trojan-activity; sid:100004782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonydong.com"; classtype:trojan-activity; sid:100004783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonyzone.com"; classtype:trojan-activity; sid:100004784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tooba.tenplusone.my"; classtype:trojan-activity; sid:100004785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topcell9.com"; classtype:trojan-activity; sid:100004786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topicsnepal.com"; classtype:trojan-activity; sid:100004787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toplevel.com.br"; classtype:trojan-activity; sid:100004788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"torresquinterocorp.com"; classtype:trojan-activity; sid:100004789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"towme.services"; classtype:trojan-activity; sid:100004790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toyotacollege.ac.th"; classtype:trojan-activity; sid:100004791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpef.lsoftdemo.com"; classtype:trojan-activity; sid:100004792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpke.hu"; classtype:trojan-activity; sid:100004793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tradezone.ejuicysolutions.com"; classtype:trojan-activity; sid:100004794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"translaterjemah.com"; classtype:trojan-activity; sid:100004795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"travelwithmanta.co.za"; classtype:trojan-activity; sid:100004796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trezors.io.mahlongwa.com"; classtype:trojan-activity; sid:100004797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"triplonet.com.br"; classtype:trojan-activity; sid:100004798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"troki.com.co"; classtype:trojan-activity; sid:100004799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tropics.codeleek.net"; classtype:trojan-activity; sid:100004800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trucks.softwarenecessities.com"; classtype:trojan-activity; sid:100004801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trudelfavreau.com"; classtype:trojan-activity; sid:100004802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tsd.jxwan.com"; classtype:trojan-activity; sid:100004803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tulli.info"; classtype:trojan-activity; sid:100004804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tupperware.michaelroberge.ca"; classtype:trojan-activity; sid:100004805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"turanggaresources.com"; classtype:trojan-activity; sid:100004806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uat.indianfilmzone.com"; classtype:trojan-activity; sid:100004807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ublretailerdemo.cstdevs.com"; classtype:trojan-activity; sid:100004808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uc-56.ru"; classtype:trojan-activity; sid:100004809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"udesk.searchkero.com"; classtype:trojan-activity; sid:100004810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ugprs-ubih.org"; classtype:trojan-activity; sid:100004811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ultimate-24.de"; classtype:trojan-activity; sid:100004812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"umwelt-kirchhof.de"; classtype:trojan-activity; sid:100004813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unicorpbrunei.com"; classtype:trojan-activity; sid:100004814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uniengrisb.com"; classtype:trojan-activity; sid:100004815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unisoftcc.com"; classtype:trojan-activity; sid:100004816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unyazitelecom.com"; classtype:trojan-activity; sid:100004817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"upcbpta.com"; classtype:trojan-activity; sid:100004818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"urbantrapfest.cl"; classtype:trojan-activity; sid:100004819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"useformoney.000webhostapp.com"; classtype:trojan-activity; sid:100004820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"usmadetshirts.com"; classtype:trojan-activity; sid:100004821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uss.ac.th"; classtype:trojan-activity; sid:100004822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uzzepay.com.br"; classtype:trojan-activity; sid:100004823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vbcargo.hu"; classtype:trojan-activity; sid:100004824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vcah.co.uk"; classtype:trojan-activity; sid:100004825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vegadelcasero.cl"; classtype:trojan-activity; sid:100004826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vendas.lidiacarmeli.com.br"; classtype:trojan-activity; sid:100004827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vfocus.net"; classtype:trojan-activity; sid:100004828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vidmattic.com"; classtype:trojan-activity; sid:100004829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vienen.gblix.srv.br"; classtype:trojan-activity; sid:100004830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villamarand.com"; classtype:trojan-activity; sid:100004831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villatera.com"; classtype:trojan-activity; sid:100004832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"violinstop.com"; classtype:trojan-activity; sid:100004833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viraltalking.com"; classtype:trojan-activity; sid:100004834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visions.alnisamart.com"; classtype:trojan-activity; sid:100004835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visualhome.cl"; classtype:trojan-activity; sid:100004836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vitoriamodaintima.com.br"; classtype:trojan-activity; sid:100004837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vivationdesign.com"; classtype:trojan-activity; sid:100004838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viveirodoiscorregos.com.br"; classtype:trojan-activity; sid:100004839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vksales.com"; classtype:trojan-activity; sid:100004840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vladimirinternational.com"; classtype:trojan-activity; sid:100004841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vokasi.ub.ac.id"; classtype:trojan-activity; sid:100004842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vologroup.com.br"; classtype:trojan-activity; sid:100004843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"voteyouramerica.dekitout.com"; classtype:trojan-activity; sid:100004844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vpinversiones.cl"; classtype:trojan-activity; sid:100004845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vstsample.com"; classtype:trojan-activity; sid:100004846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vtube.fadlymotivator.com"; classtype:trojan-activity; sid:100004847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vvsskmodinationalschool.com"; classtype:trojan-activity; sid:100004848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepliberia.org"; classtype:trojan-activity; sid:100004849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepniger.org"; classtype:trojan-activity; sid:100004850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weareactum.com"; classtype:trojan-activity; sid:100004851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.eng.ubu.ac.th"; classtype:trojan-activity; sid:100004852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geetle.ga"; classtype:trojan-activity; sid:100004853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geomegasoft.net"; classtype:trojan-activity; sid:100004854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.newinnovationtechnology.com"; classtype:trojan-activity; sid:100004855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.smarts-works.com"; classtype:trojan-activity; sid:100004856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.thebeessolution.com"; classtype:trojan-activity; sid:100004857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webgis.perumdasolo.com"; classtype:trojan-activity; sid:100004858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; classtype:trojan-activity; sid:100004859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webpresario.com"; classtype:trojan-activity; sid:100004860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"website-work.com"; classtype:trojan-activity; sid:100004861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weinsteincounseling.com"; classtype:trojan-activity; sid:100004862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wexfashion.com"; classtype:trojan-activity; sid:100004863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whcms.yourpageserver.com"; classtype:trojan-activity; sid:100004864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteglovetailgate.com"; classtype:trojan-activity; sid:100004865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteresponse.com"; classtype:trojan-activity; sid:100004866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wi522012.ferozo.com"; classtype:trojan-activity; sid:100004867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wikalen.co.za"; classtype:trojan-activity; sid:100004868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildnights.co.uk"; classtype:trojan-activity; sid:100004869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildtrust.mediadevstaging.com"; classtype:trojan-activity; sid:100004870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wimbamusica.com"; classtype:trojan-activity; sid:100004871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"windcomtechnologies.com"; classtype:trojan-activity; sid:100004872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wishesconcierge.com"; classtype:trojan-activity; sid:100004873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woezon.agency"; classtype:trojan-activity; sid:100004874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wolfgang-brodte.de"; classtype:trojan-activity; sid:100004875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woodsytech.com"; classtype:trojan-activity; sid:100004876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wordpress.saleensuporte.com.br"; classtype:trojan-activity; sid:100004877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wozata.000webhostapp.com"; classtype:trojan-activity; sid:100004878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wp.readhere.in"; classtype:trojan-activity; sid:100004879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wpdemo.101clients.com.au"; classtype:trojan-activity; sid:100004880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"writtendeer.com"; classtype:trojan-activity; sid:100004881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ws5588.f3322.net"; classtype:trojan-activity; sid:100004882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wyklej.pl"; classtype:trojan-activity; sid:100004883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"x2vn.com"; classtype:trojan-activity; sid:100004884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xia.beihaixue.com"; classtype:trojan-activity; sid:100004885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xixaoclothing.com"; classtype:trojan-activity; sid:100004886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xk.996is.com"; classtype:trojan-activity; sid:100004887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--80akinnkiib6h.xn--90ais"; classtype:trojan-activity; sid:100004888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--polimerbizmimarlk-rvc.com"; classtype:trojan-activity; sid:100004889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ybom.urbanolab.com"; classtype:trojan-activity; sid:100004890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yeichner.com"; classtype:trojan-activity; sid:100004891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ylfpremium.com"; classtype:trojan-activity; sid:100004892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yoast.yourpageserver.com"; classtype:trojan-activity; sid:100004893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yourtopdog.com.au"; classtype:trojan-activity; sid:100004894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"youtubetrainingacademy.com"; classtype:trojan-activity; sid:100004895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yp.hnggzyjy.cn"; classtype:trojan-activity; sid:100004896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yskadvisors.com"; classtype:trojan-activity; sid:100004897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yummyyogaudaipur.com"; classtype:trojan-activity; sid:100004898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yzkzixun.com"; classtype:trojan-activity; sid:100004899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zytrox.tk"; classtype:trojan-activity; sid:100004900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zz.690tx.com"; classtype:trojan-activity; sid:100004901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; endswith; nocase; http.host; content:"amumufree.weebly.com"; classtype:trojan-activity; sid:100004902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/proxyi.exe"; endswith; nocase; http.host; content:"analogx.com"; classtype:trojan-activity; sid:100004903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ww/setup.exe"; endswith; nocase; http.host; content:"b4ad7b79-534a-4e83-953e-c36da8cf27d9.s3.amazonaws.com"; classtype:trojan-activity; sid:100004904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvdfv/anjj/downloads/jami.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/4.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/6.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr3.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/instaler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/installer.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatej.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatev.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/work.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/component.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/regsvc.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skygaming/updates/downloads/update.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/001.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1488.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1_cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1fc2d.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/26a5.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/abjects.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/attached.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/b7f2c.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/battletext.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_makros.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_silent.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_sup.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildss.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientnik.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientrevers.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dcrat.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hans.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hulu.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfive.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfour.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelone.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelthree.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/inteltwo.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/kleiman.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/notepadplus.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/putty.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/rockethcd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/scvhost900.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/sessionwin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/siliculose.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/statemobi.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stgedo.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/svcperf.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurjok.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurusbabac.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/telekiller.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateanddr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateandr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/vhajeja.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/word.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/www.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/xlsd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmatrix/data/hack1226.exe"; endswith; nocase; http.host; content:"cd.textfiles.com"; classtype:trojan-activity; sid:100004984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100004985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/816070119281131570/816070273254162442/all.txt"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100004986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/821809080812437507/824392185902006272/mmp1_1.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100004987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100004988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/823810712891555890/824413943526195210/runpetest.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100004989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/824689793140129857/824690065988386816/sendhookfile.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100004990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/824689793140129857/824691026852970496/photo.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100004991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razor/rzr-winner_intro.zip"; endswith; nocase; http.host; content:"chiptune.com"; classtype:trojan-activity; sid:100004992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100004993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100004994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meteoradminz/hidden-tear/zip/master"; endswith; nocase; http.host; content:"codeload.github.com"; classtype:trojan-activity; sid:100004995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; endswith; nocase; http.host; content:"colfincas.com"; classtype:trojan-activity; sid:100004996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qz0h69.pdf"; endswith; nocase; http.host; content:"deepfreedom.org"; classtype:trojan-activity; sid:100004997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hold/schost.exe"; endswith; nocase; http.host; content:"digitalassets.ams3.digitaloceanspaces.com"; classtype:trojan-activity; sid:100004998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/modern/five.exe"; endswith; nocase; http.host; content:"digitalassets.ams3.digitaloceanspaces.com"; classtype:trojan-activity; sid:100004999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=11jnyjpzkjiie_rzc4xwa2feok3x__yvc"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=151uxflny3vqh_lmghrkgjhhsqxi163sh"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=15iwonkjkhyvri_okkc_llq56aasvnvb9"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1ak46tqftzejmq-og_ky2oupgpmkgujtm"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1brsmnj6g0lxa44ixkypvg5tcxkvi5gjt"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1by_s4vv8gdmmz8wl-lbpjbjy5adcrjk1"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1dpsxfbptpyl-zegto9t29vvcku2rjm9u"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1dwb7nww_ahtjfeed-afxl4hvm_xqkx-h"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1e7t_hnuohxuziwcxihocdievcj5_dsgj"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1erajjbz6gdxhsvvorlykzxyeoq-xu7wn"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1ev7gkzwjgtv2vlbbisg1ragd7nf0-xog"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1ey8zl85vszh-gdmubkoudacqs6zv2dup"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1gq_jf503du9oip5bwzcoi6_kgolr3kx2"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1imrv00kqbfz4ljzwq5qdau1to0zlmaqy"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1j6pvg1rznjh9pkldcyjiogo8ysiyl8_y"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1jlcqojhfhgifmirrsv0o5t-2rl-hblai"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1k6sh5h-nptesem_jsnuxmhzntnvdlgxz"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1lk6n-xrtv0dvdqljl26pzebxzp8tladk"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1lkcqgpimry4yp8grinnhsotnawquozcz"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1m34mp1cggxz-cz3a5ipjrgfog_qx8myx"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1m6kdawqt1fwxea6epcae6t1qevfhl0-5"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1m8w1y1-mxxa2pktrzkwfetwjxrlw1alo"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1m9jxzqcbnb8j8uph1qfcas8b9pngcogj"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1mdnlxs6vy5qk-u4dxz9movem4j3a3o-8"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1od6gtslxvylgyeujmrbvm9yhupmq_1lv"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1ozpasp-mr-e-ui4lshy4qy4a2pl8pxsi"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1q0edpjr7vgo_ytns7dgjcav6317juz9y"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1q5gqeinogsri3i-ynlgvu88ajqnn9siq"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1quyiobd7-d-vcddlhxiqbqrwxyg7ongo"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1rrtyvouwizor2icbcoywdid4w9rwngxi"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1sao6yxf-a0t6wdgdr36srwlju57vigx_"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1st5mtgqyofsskuhlomfihfmz_qx-i32o"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1u5q84w84g_x98ti4uflzhrgvzzfyj_qi"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1umz5zjobot9__v2jxdutyborb2az90hz"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1we-h5qtxj9czhkhzvzg0qqpxufgu_v__"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1wurpipyf0s__fqtn1ov619nx7v1-tcy3"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1wwkqbfluu4qusqz26ewulr48zh9vzq-w"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=1yyuejm8cerrq2tctsibww4uetepcmh4i"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100005037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; endswith; nocase; http.host; content:"drive.google.com.it-barcelona.com"; classtype:trojan-activity; sid:100005038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/1zilg/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100005064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/qcgfmfvh/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100005065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/emclick.zip"; endswith; nocase; http.host; content:"e-mudhra.com"; classtype:trojan-activity; sid:100005066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100005067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100005068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; endswith; nocase; http.host; content:"file.elecfans.com"; classtype:trojan-activity; sid:100005076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100005077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100005078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; endswith; nocase; http.host; content:"gist.githubusercontent.com"; classtype:trojan-activity; sid:100005079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; endswith; nocase; http.host; content:"hqdecig.com"; classtype:trojan-activity; sid:100005080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/suy/"; endswith; nocase; http.host; content:"hsecaravans.co.uk"; classtype:trojan-activity; sid:100005081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19/items/startup_20210219/startup.txt"; endswith; nocase; http.host; content:"ia801802.us.archive.org"; classtype:trojan-activity; sid:100005082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/online-timer-kvhxz/ilxl/"; endswith; nocase; http.host; content:"ie-best.net"; classtype:trojan-activity; sid:100005083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100005084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100005085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebook/cs17.exe"; endswith; nocase; http.host; content:"jcedu.org"; classtype:trojan-activity; sid:100005086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/jl01o54yy09qrzg/fac215.tgz/file"; endswith; nocase; http.host; content:"justlficante.mediafire.com"; classtype:trojan-activity; sid:100005090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; endswith; nocase; http.host; content:"karmakoincodes.weebly.com"; classtype:trojan-activity; sid:100005091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; endswith; nocase; http.host; content:"ksh.hu"; classtype:trojan-activity; sid:100005092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/affiliate/kuaizip_setup_10029.exe"; endswith; nocase; http.host; content:"kuaizip.com"; classtype:trojan-activity; sid:100005093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linuxforensicscode.zip"; endswith; nocase; http.host; content:"linuxforensicsbook.com.s3.amazonaws.com"; classtype:trojan-activity; sid:100005094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k/big5/1giof6/"; endswith; nocase; http.host; content:"minpic.de"; classtype:trojan-activity; sid:100005095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-contentbak/t9m/"; endswith; nocase; http.host; content:"morrobaydrugandgift.com"; classtype:trojan-activity; sid:100005096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; endswith; nocase; http.host; content:"my.cloudme.com"; classtype:trojan-activity; sid:100005097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/aacenc.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100005098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/doxillionsetup.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100005099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/4/1/6/6/4166984/keygen.exe"; endswith; nocase; http.host; content:"newyarlfm.weebly.com"; classtype:trojan-activity; sid:100005100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; endswith; nocase; http.host; content:"nhipcauytevietnhat.com"; classtype:trojan-activity; sid:100005101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; endswith; nocase; http.host; content:"note.youdao.com"; classtype:trojan-activity; sid:100005102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; endswith; nocase; http.host; content:"oldschoolvalue.s3.amazonaws.com"; classtype:trojan-activity; sid:100005103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!296&authkey=adsdrrjllbu1nwa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!297&authkey=am7nspchat4aqtw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21296&authkey=adsdrrjllbu1nwa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=80dabacd46496407&resid=80dabacd46496407%21124&authkey=abnj7t59iwijpdy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1045&authkey=aetgoeo_eku-6ba"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211045&authkey=aetgoeo_eku-6ba"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21122&authkey=ajqq2okqxfq8iuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774!124&authkey=afq42wqejwvcv8o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774%21124&authkey=afq42wqejwvcv8o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4a3bd996f92bf71&resid=e4a3bd996f92bf71%211944&authkey=ao3lztaialsza88"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f8d2350982acb14f&resid=f8d2350982acb14f%21140&authkey=ajo86idqg2jvzfq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!196&authkey=amm2av5ubkbhoru"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!197&authkey=apnt4trskzjga_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21196&authkey=amm2av5ubkbhoru"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21197&authkey=apnt4trskzjga_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/yqvsvlvq"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100005676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/llc/mwcacs65xienqdp/"; endswith; nocase; http.host; content:"pierreconsulting.info"; classtype:trojan-activity; sid:100005677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; endswith; nocase; http.host; content:"pioneiraagronegocio.com.br"; classtype:trojan-activity; sid:100005678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skoda22.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100005679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100005680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; endswith; nocase; http.host; content:"qjbutterflyevents.co.za"; classtype:trojan-activity; sid:100005681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maersk-bl+draft-copy-shipping-documents.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100005682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100005683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/purchasing+ordersigned+contractinv-30067121.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100005684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myqseeaccount/one/main/one.htm"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tennc/webshell/master/other/small_shell.txt"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; endswith; nocase; http.host; content:"res.yeshen.com"; classtype:trojan-activity; sid:100005696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/q05z91"; endswith; nocase; http.host; content:"sendspace.com"; classtype:trojan-activity; sid:100005697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; endswith; nocase; http.host; content:"sites.google.com"; classtype:trojan-activity; sid:100005698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-nurse-ss8d9/z/"; endswith; nocase; http.host; content:"technologydistilled.com"; classtype:trojan-activity; sid:100005709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/databases/merit.php"; endswith; nocase; http.host; content:"truemerit.io"; classtype:trojan-activity; sid:100005710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23.exe"; endswith; nocase; http.host; content:"tsrv4.ws"; classtype:trojan-activity; sid:100005711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crisanar/defis/jek_crackme1.7.zip"; endswith; nocase; http.host; content:"users.skynet.be"; classtype:trojan-activity; sid:100005712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/amowvegfrt9ja/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100005713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100005714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100005715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100005716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb%5efr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb^fr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/151_155/tidex_-_short_stuff.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syria-files/attach/222/222051_instruction.zip"; endswith; nocase; http.host; content:"wikileaks.org"; classtype:trojan-activity; sid:100005722; rev:1;)
diff --git a/urlhaus-filter-unbound-online.conf b/urlhaus-filter-unbound-online.conf
index dec5ca38..fede69db 100644
--- a/urlhaus-filter-unbound-online.conf
+++ b/urlhaus-filter-unbound-online.conf
@@ -1,5 +1,5 @@
 # Title: Online Malicious Domains Unbound Blocklist
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -13,11 +13,13 @@ local-zone: "1am.co.nz" always_nxdomain
 local-zone: "20.dbstrony.pl" always_nxdomain
 local-zone: "21robo.com" always_nxdomain
 local-zone: "24.dbstrony.pl" always_nxdomain
+local-zone: "32792.prolocksmithwinterpark.com" always_nxdomain
 local-zone: "360.lcy2zzx.pw" always_nxdomain
 local-zone: "360down7.miiyun.cn" always_nxdomain
+local-zone: "68468438438.xyz" always_nxdomain
 local-zone: "8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com" always_nxdomain
+local-zone: "87du.vip" always_nxdomain
 local-zone: "8poieq.bn.files.1drv.com" always_nxdomain
-local-zone: "99centsdigitals.com" always_nxdomain
 local-zone: "abcd.bg" always_nxdomain
 local-zone: "abclicks.in" always_nxdomain
 local-zone: "abissnet.net" always_nxdomain
@@ -25,6 +27,7 @@ local-zone: "aboveandbelow.com.au" always_nxdomain
 local-zone: "absoftechworld.com" always_nxdomain
 local-zone: "absupplies.co.uk" always_nxdomain
 local-zone: "abyssos.eu" always_nxdomain
+local-zone: "academyshademani.com" always_nxdomain
 local-zone: "acbick.com" always_nxdomain
 local-zone: "accounts.thesmarttechhub.com" always_nxdomain
 local-zone: "aceeprc.com.aceeprc.com" always_nxdomain
@@ -53,7 +56,9 @@ local-zone: "agmcarpetcare.co.uk" always_nxdomain
 local-zone: "aiqtest.com" always_nxdomain
 local-zone: "ajpharmaholding.com" always_nxdomain
 local-zone: "ajstudiollc.com" always_nxdomain
+local-zone: "akauk09.top" always_nxdomain
 local-zone: "akivj07.top" always_nxdomain
+local-zone: "akpgi08.top" always_nxdomain
 local-zone: "al-wahd.com" always_nxdomain
 local-zone: "alasdemariposas.org" always_nxdomain
 local-zone: "alemelektronik.com" always_nxdomain
@@ -87,6 +92,7 @@ local-zone: "api-ms.cobainaja.id" always_nxdomain
 local-zone: "api.cstdevs.com" always_nxdomain
 local-zone: "api.quocbao.biz" always_nxdomain
 local-zone: "api.sampy.io" always_nxdomain
+local-zone: "aplicativoparasindicato.com.br" always_nxdomain
 local-zone: "apoolcondo.com" always_nxdomain
 local-zone: "app.adsensearticle.com" always_nxdomain
 local-zone: "app.explicitsurveys.co.uk" always_nxdomain
@@ -94,7 +100,6 @@ local-zone: "app.prerana.info" always_nxdomain
 local-zone: "apps.saintsoporte.com" always_nxdomain
 local-zone: "aqv.news" always_nxdomain
 local-zone: "areyoulivingwell.com" always_nxdomain
-local-zone: "arsapetrolab.com" always_nxdomain
 local-zone: "artedibujoyarquitectura.com" always_nxdomain
 local-zone: "ask-regard.call-save.biz" always_nxdomain
 local-zone: "atfile.com" always_nxdomain
@@ -105,10 +110,8 @@ local-zone: "attach.66rpg.com" always_nxdomain
 local-zone: "atteuqpotentialunlimited.com" always_nxdomain
 local-zone: "augustair.com" always_nxdomain
 local-zone: "aulist.com" always_nxdomain
-local-zone: "australiafashions.com" always_nxdomain
 local-zone: "automaticrefreshments.com" always_nxdomain
 local-zone: "avadhanagames.com" always_nxdomain
-local-zone: "avissrilanka.com" always_nxdomain
 local-zone: "ayamallah.com" always_nxdomain
 local-zone: "azmeasurement.com" always_nxdomain
 local-zone: "azraktours.com" always_nxdomain
@@ -146,12 +149,12 @@ local-zone: "blog.callensaxen.com" always_nxdomain
 local-zone: "blog.oyinblogs.com" always_nxdomain
 local-zone: "blog.takbelit.com" always_nxdomain
 local-zone: "bmlifestyle.co.uk" always_nxdomain
-local-zone: "bnrbook.com" always_nxdomain
 local-zone: "bnrnews.id" always_nxdomain
 local-zone: "bodenstein.co.za" always_nxdomain
 local-zone: "booksearch.com" always_nxdomain
 local-zone: "bounces.mi-fs.com" always_nxdomain
 local-zone: "bpo.correct.go.th" always_nxdomain
+local-zone: "bradleyinstitute.co.za" always_nxdomain
 local-zone: "brandtrust.com.pk" always_nxdomain
 local-zone: "brendanquine.com" always_nxdomain
 local-zone: "brideofmessiah.com" always_nxdomain
@@ -162,8 +165,6 @@ local-zone: "brightstarshop.com" always_nxdomain
 local-zone: "browardinsurancemiami.solucioneslink.com" always_nxdomain
 local-zone: "bt2.elin.co.za" always_nxdomain
 local-zone: "btdapi.robotake.com" always_nxdomain
-local-zone: "bucrinsuranlceonlines.com" always_nxdomain
-local-zone: "buenavista.co" always_nxdomain
 local-zone: "buigiaphat.com.vn" always_nxdomain
 local-zone: "bullseyemedia.in" always_nxdomain
 local-zone: "busandvanrentalmalaysia.com" always_nxdomain
@@ -188,6 +189,7 @@ local-zone: "cazyacustomfurniture.com" always_nxdomain
 local-zone: "ccauthority.net" always_nxdomain
 local-zone: "cdaonline.com.ar" always_nxdomain
 local-zone: "cec.asso.ac-amiens.fr" always_nxdomain
+local-zone: "cecra.cl" always_nxdomain
 local-zone: "cellas.sk" always_nxdomain
 local-zone: "cendekiabinaaksara.com" always_nxdomain
 local-zone: "cespol-bote.com.mx" always_nxdomain
@@ -195,8 +197,6 @@ local-zone: "cfs5.tistory.com" always_nxdomain
 local-zone: "ch.rmu.ac.th" always_nxdomain
 local-zone: "changematterscounselling.com" always_nxdomain
 local-zone: "chardhamdodham.com" always_nxdomain
-local-zone: "cheacrilnsurances.com" always_nxdomain
-local-zone: "chealablilitycarinsurances.com" always_nxdomain
 local-zone: "chezalice.co.za" always_nxdomain
 local-zone: "childselect.com" always_nxdomain
 local-zone: "chinhdropfile.myvnc.com" always_nxdomain
@@ -216,11 +216,9 @@ local-zone: "config.cqhbkjzx.com" always_nxdomain
 local-zone: "constructoralyon.com" always_nxdomain
 local-zone: "consulateins.solucioneslink.com" always_nxdomain
 local-zone: "contributeindustry.com" always_nxdomain
-local-zone: "controladoradeplagasmm.com" always_nxdomain
 local-zone: "controleautomacao.com.br" always_nxdomain
 local-zone: "copelandscapes.com" always_nxdomain
 local-zone: "coulsongraphics.com" always_nxdomain
-local-zone: "coutler.newreadermedia.net" always_nxdomain
 local-zone: "covid19.cyberschool.or.id" always_nxdomain
 local-zone: "cr-sq.com" always_nxdomain
 local-zone: "craftnesia.id" always_nxdomain
@@ -272,14 +270,14 @@ local-zone: "despertaresi.com.br" always_nxdomain
 local-zone: "destinymc.co.za" always_nxdomain
 local-zone: "detorre.es" always_nxdomain
 local-zone: "dev-interestingtech.pantheonsite.io" always_nxdomain
-local-zone: "dev.sayse-tienda.com" always_nxdomain
 local-zone: "dev.sebpo.net" always_nxdomain
+local-zone: "dezcom.com" always_nxdomain
 local-zone: "dfcf.91756.cn" always_nxdomain
-local-zone: "dfsfcsfcdsfsdvcfsvcscv.com" always_nxdomain
 local-zone: "diamantenegro.mi-fs.com" always_nxdomain
 local-zone: "dienmayminhhung.com" always_nxdomain
 local-zone: "digilib.dianhusada.ac.id" always_nxdomain
 local-zone: "djking.f3322.net" always_nxdomain
+local-zone: "dl-link.link" always_nxdomain
 local-zone: "dl.1003b.56a.com" always_nxdomain
 local-zone: "dl.198424.com" always_nxdomain
 local-zone: "dl.installcdn-aws.com" always_nxdomain
@@ -302,7 +300,6 @@ local-zone: "dosman.pl" always_nxdomain
 local-zone: "dovberger.com" always_nxdomain
 local-zone: "down.flash-plays.com" always_nxdomain
 local-zone: "down.pcclear.com" always_nxdomain
-local-zone: "down.udashi.com" always_nxdomain
 local-zone: "down.webbora.com" always_nxdomain
 local-zone: "down1.arpun.com" always_nxdomain
 local-zone: "download.caihong.com" always_nxdomain
@@ -322,6 +319,7 @@ local-zone: "drsha.innovativesolutions.mobi" always_nxdomain
 local-zone: "dsenterprize.co.za" always_nxdomain
 local-zone: "dsspainting.com" always_nxdomain
 local-zone: "du-wizards.com" always_nxdomain
+local-zone: "duckrambo.com" always_nxdomain
 local-zone: "duque.guantanameratravel.com" always_nxdomain
 local-zone: "dutapp.wisolve.co.za" always_nxdomain
 local-zone: "duvalcharter.dekitout.com" always_nxdomain
@@ -332,7 +330,6 @@ local-zone: "e.sldov.ru" always_nxdomain
 local-zone: "ebruyatkin.com" always_nxdomain
 local-zone: "econews.treegle.org" always_nxdomain
 local-zone: "efficientegroup.com" always_nxdomain
-local-zone: "elliot.newreadermedia.net" always_nxdomain
 local-zone: "en.baoend.com" always_nxdomain
 local-zone: "enc-tech.com" always_nxdomain
 local-zone: "endurotanzania.co.tz" always_nxdomain
@@ -348,7 +345,6 @@ local-zone: "evidencemarketing.ca" always_nxdomain
 local-zone: "exilum.com" always_nxdomain
 local-zone: "exitoalfaomega.co" always_nxdomain
 local-zone: "extrovertoffers.com" always_nxdomain
-local-zone: "f1sol.com" always_nxdomain
 local-zone: "familydentist.site" always_nxdomain
 local-zone: "farmaciasdrogaminas.com.br" always_nxdomain
 local-zone: "fate3.xyz" always_nxdomain
@@ -359,6 +355,7 @@ local-zone: "fi.bonitastores.com" always_nxdomain
 local-zone: "files.martellexpress.us" always_nxdomain
 local-zone: "final.makkahkmcc.com" always_nxdomain
 local-zone: "fineartgallerym.com" always_nxdomain
+local-zone: "fixauto.illumetechnology.com" always_nxdomain
 local-zone: "fkd.derpcity.ru" always_nxdomain
 local-zone: "flintspin.com" always_nxdomain
 local-zone: "flyingbuddhadesign.com" always_nxdomain
@@ -368,7 +365,6 @@ local-zone: "foothills.com.br" always_nxdomain
 local-zone: "footweardirect.elin.co.za" always_nxdomain
 local-zone: "forum.mdb.nu" always_nxdomain
 local-zone: "fotoobjetivo.com" always_nxdomain
-local-zone: "foundationrepairhoustontx.net" always_nxdomain
 local-zone: "foxeps.com.br" always_nxdomain
 local-zone: "freecnetdownload.com" always_nxdomain
 local-zone: "freedombookshop.tickme.lk" always_nxdomain
@@ -390,7 +386,6 @@ local-zone: "ghettohub.co.za" always_nxdomain
 local-zone: "ghislain.dartois.pagesperso-orange.fr" always_nxdomain
 local-zone: "giadungg7.com" always_nxdomain
 local-zone: "giddos.ga" always_nxdomain
-local-zone: "gilliem.com" always_nxdomain
 local-zone: "girotexuniformes.com" always_nxdomain
 local-zone: "giteletropical.com" always_nxdomain
 local-zone: "globaltask.ar" always_nxdomain
@@ -406,6 +401,7 @@ local-zone: "goldcoastoffice365.com.au" always_nxdomain
 local-zone: "goldcupmortgage.com" always_nxdomain
 local-zone: "golden-memories-funerals.yourpageserver.com" always_nxdomain
 local-zone: "goldmen.in" always_nxdomain
+local-zone: "gracejukes.com" always_nxdomain
 local-zone: "grupoinmare.com" always_nxdomain
 local-zone: "gruposelt.000webhostapp.com" always_nxdomain
 local-zone: "gs.monerorx.com" always_nxdomain
@@ -416,6 +412,7 @@ local-zone: "hagebakken.no" always_nxdomain
 local-zone: "harshraval.in" always_nxdomain
 local-zone: "hd11315.com" always_nxdomain
 local-zone: "hdkamera2003.hu" always_nxdomain
+local-zone: "hdrest.fastlinktz.com" always_nxdomain
 local-zone: "hds.sz4h.com" always_nxdomain
 local-zone: "healthy20.net" always_nxdomain
 local-zone: "heavymaq.cl" always_nxdomain
@@ -436,7 +433,6 @@ local-zone: "hoayeuthuong-my.sharepoint.com" always_nxdomain
 local-zone: "homefindersolutions.com" always_nxdomain
 local-zone: "hongluosi.com" always_nxdomain
 local-zone: "hookedupboatclub.com" always_nxdomain
-local-zone: "hostelkielce.com" always_nxdomain
 local-zone: "hostzaa.com" always_nxdomain
 local-zone: "houstonshutters.site" always_nxdomain
 local-zone: "hr2019.vrcom7.com" always_nxdomain
@@ -455,7 +451,6 @@ local-zone: "idvindia.com" always_nxdomain
 local-zone: "iesanjosemonitos.edu.co" always_nxdomain
 local-zone: "ikexpert.com" always_nxdomain
 local-zone: "ilrafrica.com" always_nxdomain
-local-zone: "images.jermiau.com" always_nxdomain
 local-zone: "imbueautoworx.co.za" always_nxdomain
 local-zone: "incodimsa.com" always_nxdomain
 local-zone: "incrediblepixels.com" always_nxdomain
@@ -473,8 +468,10 @@ local-zone: "intersel-idf.org" always_nxdomain
 local-zone: "intuitiveideas.com.my" always_nxdomain
 local-zone: "inversiones.arrayanfinanciero.cl" always_nxdomain
 local-zone: "invest.xpcorporative.com.br" always_nxdomain
+local-zone: "investinae.com" always_nxdomain
 local-zone: "ipmes.ma" always_nxdomain
 local-zone: "iremart.es" always_nxdomain
+local-zone: "iris101.co.uk" always_nxdomain
 local-zone: "isaac.mikhailmotoringschool.com" always_nxdomain
 local-zone: "iscamenabe.com" always_nxdomain
 local-zone: "ismf.com.ng" always_nxdomain
@@ -485,7 +482,6 @@ local-zone: "isso.ps" always_nxdomain
 local-zone: "it123.ru" always_nxdomain
 local-zone: "itc-demo.softgig.co.ke" always_nxdomain
 local-zone: "itconsultus.com.co" always_nxdomain
-local-zone: "jamesjorgensen.newreadermedia.net" always_nxdomain
 local-zone: "jamiekaylive.com" always_nxdomain
 local-zone: "jamshed.pk" always_nxdomain
 local-zone: "jansen-heesch.nl" always_nxdomain
@@ -493,7 +489,6 @@ local-zone: "jathra.co.uk" always_nxdomain
 local-zone: "jay.diamondrelationscrm.us" always_nxdomain
 local-zone: "jebs.net.au" always_nxdomain
 local-zone: "jeffdahlke.com" always_nxdomain
-local-zone: "jewsjuice.com" always_nxdomain
 local-zone: "jhayesconsulting.com" always_nxdomain
 local-zone: "jiaoyuzixun.cn" always_nxdomain
 local-zone: "jing-da.com.tw" always_nxdomain
@@ -508,14 +503,11 @@ local-zone: "josuarochoa.com" always_nxdomain
 local-zone: "jpwoodfordco.com" always_nxdomain
 local-zone: "jumpmanualjacobhiller.com" always_nxdomain
 local-zone: "jupiter.toxsl.in" always_nxdomain
-local-zone: "jurgensen.newreadermedia.net" always_nxdomain
 local-zone: "justinscott.com.au" always_nxdomain
-local-zone: "kaizenjanitorial.com" always_nxdomain
 local-zone: "kalawatihomes.com" always_nxdomain
 local-zone: "kalpataru-elitus-mulund.thakkers.in" always_nxdomain
 local-zone: "karer.by" always_nxdomain
 local-zone: "katanvetov.co.il" always_nxdomain
-local-zone: "kbdom.com" always_nxdomain
 local-zone: "kensingtondriving.com" always_nxdomain
 local-zone: "kevinjewelry.com.co" always_nxdomain
 local-zone: "keywatch.yourpageserver.com" always_nxdomain
@@ -553,7 +545,6 @@ local-zone: "lidoraggiodisole.it" always_nxdomain
 local-zone: "lifebeam.elin.co.za" always_nxdomain
 local-zone: "lindnerelektroanlagen.de" always_nxdomain
 local-zone: "linkintec.cn" always_nxdomain
-local-zone: "litroxlitro.com" always_nxdomain
 local-zone: "livetrack.in" always_nxdomain
 local-zone: "lloydsindian.co.uk" always_nxdomain
 local-zone: "lm.stagingarea.co.za" always_nxdomain
@@ -567,11 +558,8 @@ local-zone: "login.trezor.com.stockfootagesindia.com" always_nxdomain
 local-zone: "logotypfabriken.se" always_nxdomain
 local-zone: "lotix.de" always_nxdomain
 local-zone: "lotusanddragonfly.com" always_nxdomain
-local-zone: "lp.carrduci.com" always_nxdomain
 local-zone: "lp.definerisco.com" always_nxdomain
 local-zone: "lp.difusodesign.com" always_nxdomain
-local-zone: "lp.juancamilogarciareyes.com" always_nxdomain
-local-zone: "lp.tecnimasdecolombia.com.co" always_nxdomain
 local-zone: "ltc.typoten.com" always_nxdomain
 local-zone: "luckybrownie.com" always_nxdomain
 local-zone: "luminouspneuma.com" always_nxdomain
@@ -601,6 +589,7 @@ local-zone: "masjidhabeebiyarazviya.mysunni.com" always_nxdomain
 local-zone: "materialescantu.com" always_nxdomain
 local-zone: "matruchhaya.co.in" always_nxdomain
 local-zone: "mattysplayground.com" always_nxdomain
+local-zone: "maxiquim.cl" always_nxdomain
 local-zone: "maxtox.com.pk" always_nxdomain
 local-zone: "mbgrm.com" always_nxdomain
 local-zone: "mbsolutions.ge" always_nxdomain
@@ -610,6 +599,7 @@ local-zone: "media-server.skyinternet.com.pk" always_nxdomain
 local-zone: "mediamaster.co.za" always_nxdomain
 local-zone: "medianews.ge" always_nxdomain
 local-zone: "medistaffconsulting.com" always_nxdomain
+local-zone: "meditreat.itwebservice.in" always_nxdomain
 local-zone: "meeweb.com" always_nxdomain
 local-zone: "megamart.afnan-amc.com" always_nxdomain
 local-zone: "merbay.ru" always_nxdomain
@@ -680,7 +670,6 @@ local-zone: "nidhi.iexist.in" always_nxdomain
 local-zone: "nikanpolimer.ir" always_nxdomain
 local-zone: "nilehouse.co.ug" always_nxdomain
 local-zone: "nilinkeji.com" always_nxdomain
-local-zone: "nisacooks.com" always_nxdomain
 local-zone: "njtiledesigncenter.com" always_nxdomain
 local-zone: "nobius.org" always_nxdomain
 local-zone: "nocalnoodle.elin.co.za" always_nxdomain
@@ -695,7 +684,6 @@ local-zone: "nuwagi.com" always_nxdomain
 local-zone: "nyeh2o.com.au" always_nxdomain
 local-zone: "oakleyandfriends.co.uk" always_nxdomain
 local-zone: "obseques-conseils.com" always_nxdomain
-local-zone: "ocean.tecnasulstore.com.br" always_nxdomain
 local-zone: "ohe.ie" always_nxdomain
 local-zone: "ohsewgorgeous.co.uk" always_nxdomain
 local-zone: "oknoplastik.sk" always_nxdomain
@@ -746,7 +734,6 @@ local-zone: "payerrealty.com" always_nxdomain
 local-zone: "payments.atifsiddiqui.me" always_nxdomain
 local-zone: "pcsoori.com" always_nxdomain
 local-zone: "pd.oceaniarp.net" always_nxdomain
-local-zone: "perpus.onlineman7-jombang.sch.id" always_nxdomain
 local-zone: "perpustekim.untirta.ac.id" always_nxdomain
 local-zone: "petercollie.com" always_nxdomain
 local-zone: "ph4s.ru" always_nxdomain
@@ -767,6 +754,7 @@ local-zone: "posmicrosystems.com" always_nxdomain
 local-zone: "poulman.panagiotopoulos-tours.gr" always_nxdomain
 local-zone: "ppdb.smk-ciptaskill.sch.id" always_nxdomain
 local-zone: "pptvideotemplates.com" always_nxdomain
+local-zone: "prestasicash.com.ar" always_nxdomain
 local-zone: "prestigehomeautomation.net" always_nxdomain
 local-zone: "prishaartcreations.com" always_nxdomain
 local-zone: "production.sparshims.com" always_nxdomain
@@ -780,7 +768,6 @@ local-zone: "prosoc.nl" always_nxdomain
 local-zone: "prosyarmakassar.com" always_nxdomain
 local-zone: "provence.elin.co.za" always_nxdomain
 local-zone: "prueba.danielluza.com" always_nxdomain
-local-zone: "ptpmeccatronica.eu" always_nxdomain
 local-zone: "pujashoppe.in" always_nxdomain
 local-zone: "punchdialogues.com" always_nxdomain
 local-zone: "punjabdevelopersassociation.com.pk" always_nxdomain
@@ -832,7 +819,6 @@ local-zone: "rs-toolkit.mikestclair.org" always_nxdomain
 local-zone: "rsgym.net" always_nxdomain
 local-zone: "rubazar.pro" always_nxdomain
 local-zone: "rubycityvietnam.com" always_nxdomain
-local-zone: "ruch.newreadermedia.net" always_nxdomain
 local-zone: "ruisgood.ru" always_nxdomain
 local-zone: "ruwadalkuwait.com" always_nxdomain
 local-zone: "rydchile.cl" always_nxdomain
@@ -866,6 +852,7 @@ local-zone: "sentierodelviandante.ml" always_nxdomain
 local-zone: "serendibsourcing.com" always_nxdomain
 local-zone: "servicemhkd.myvnc.com" always_nxdomain
 local-zone: "servicemhkd80.myvnc.com" always_nxdomain
+local-zone: "serviciovirtual.com.ar" always_nxdomain
 local-zone: "seyranikenger.com.tr" always_nxdomain
 local-zone: "sgessy.com.br" always_nxdomain
 local-zone: "shaheentbfoundation.com" always_nxdomain
@@ -880,7 +867,6 @@ local-zone: "shop.goldspot.agency" always_nxdomain
 local-zone: "shopsofe.com" always_nxdomain
 local-zone: "shrushtiinfotech.com" always_nxdomain
 local-zone: "sibernetix.fr" always_nxdomain
-local-zone: "siddharthpanditpautra.com" always_nxdomain
 local-zone: "sige.brisainformatica.com.br" always_nxdomain
 local-zone: "signatureads.co.in" always_nxdomain
 local-zone: "siili.net" always_nxdomain
@@ -931,7 +917,8 @@ local-zone: "static.3001.net" always_nxdomain
 local-zone: "statsres.com" always_nxdomain
 local-zone: "statssound.com" always_nxdomain
 local-zone: "statsspot.com" always_nxdomain
-local-zone: "stattilion.bar" always_nxdomain
+local-zone: "statsvilla.com" always_nxdomain
+local-zone: "stemschool.net" always_nxdomain
 local-zone: "stiepancasetia.ac.id" always_nxdomain
 local-zone: "stott-thompson.co.uk" always_nxdomain
 local-zone: "stratexec.co.za" always_nxdomain
@@ -943,13 +930,13 @@ local-zone: "sunmarkholidays.com" always_nxdomain
 local-zone: "supermercadostia.com" always_nxdomain
 local-zone: "support-4-free.com" always_nxdomain
 local-zone: "support.clz.kr" always_nxdomain
+local-zone: "supportit.online" always_nxdomain
 local-zone: "sw.yourpageserver.com" always_nxdomain
 local-zone: "sweaty.dk" always_nxdomain
 local-zone: "sweet-diet.com" always_nxdomain
 local-zone: "swentsai.com" always_nxdomain
 local-zone: "swiftlogisticseg.com" always_nxdomain
 local-zone: "swwbia.com" always_nxdomain
-local-zone: "syedpro.dezinetimes.com" always_nxdomain
 local-zone: "syracusecoffee.com" always_nxdomain
 local-zone: "sys.pbmadu.co.id" always_nxdomain
 local-zone: "sytraders.co" always_nxdomain
@@ -963,6 +950,7 @@ local-zone: "taltus.co.uk" always_nxdomain
 local-zone: "tapalkoedacoffee.com" always_nxdomain
 local-zone: "tarravalleyfoods.com.au" always_nxdomain
 local-zone: "taurus.ug" always_nxdomain
+local-zone: "tavo.cl" always_nxdomain
 local-zone: "taxicabsrilanka.com" always_nxdomain
 local-zone: "taxpos.com" always_nxdomain
 local-zone: "tc.snpsresidential.com" always_nxdomain
@@ -983,6 +971,7 @@ local-zone: "test.adventser.com" always_nxdomain
 local-zone: "test.letraele.es" always_nxdomain
 local-zone: "test.typoten.com" always_nxdomain
 local-zone: "test.wanepghana.org" always_nxdomain
+local-zone: "test1.asistencia247.com" always_nxdomain
 local-zone: "test1.milenial.id" always_nxdomain
 local-zone: "test1.tenplusone.my" always_nxdomain
 local-zone: "test2.basis-web.com" always_nxdomain
@@ -1049,7 +1038,7 @@ local-zone: "uniengrisb.com" always_nxdomain
 local-zone: "unisoftcc.com" always_nxdomain
 local-zone: "unyazitelecom.com" always_nxdomain
 local-zone: "upcbpta.com" always_nxdomain
-local-zone: "urbane.dezinetimes.com" always_nxdomain
+local-zone: "urbantrapfest.cl" always_nxdomain
 local-zone: "useformoney.000webhostapp.com" always_nxdomain
 local-zone: "usmadetshirts.com" always_nxdomain
 local-zone: "uss.ac.th" always_nxdomain
@@ -1058,7 +1047,6 @@ local-zone: "vbcargo.hu" always_nxdomain
 local-zone: "vcah.co.uk" always_nxdomain
 local-zone: "vegadelcasero.cl" always_nxdomain
 local-zone: "vendas.lidiacarmeli.com.br" always_nxdomain
-local-zone: "verify.aicosoft.com" always_nxdomain
 local-zone: "vfocus.net" always_nxdomain
 local-zone: "vidmattic.com" always_nxdomain
 local-zone: "vienen.gblix.srv.br" always_nxdomain
@@ -1076,6 +1064,7 @@ local-zone: "vladimirinternational.com" always_nxdomain
 local-zone: "vokasi.ub.ac.id" always_nxdomain
 local-zone: "vologroup.com.br" always_nxdomain
 local-zone: "voteyouramerica.dekitout.com" always_nxdomain
+local-zone: "vpinversiones.cl" always_nxdomain
 local-zone: "vstsample.com" always_nxdomain
 local-zone: "vtube.fadlymotivator.com" always_nxdomain
 local-zone: "vvsskmodinationalschool.com" always_nxdomain
@@ -1130,6 +1119,5 @@ local-zone: "yp.hnggzyjy.cn" always_nxdomain
 local-zone: "yskadvisors.com" always_nxdomain
 local-zone: "yummyyogaudaipur.com" always_nxdomain
 local-zone: "yzkzixun.com" always_nxdomain
-local-zone: "zakra.tecnasulstore.com.br" always_nxdomain
 local-zone: "zytrox.tk" always_nxdomain
 local-zone: "zz.690tx.com" always_nxdomain
diff --git a/urlhaus-filter-unbound.conf b/urlhaus-filter-unbound.conf
index 3f253d6d..9e5779f6 100644
--- a/urlhaus-filter-unbound.conf
+++ b/urlhaus-filter-unbound.conf
@@ -1,5 +1,5 @@
 # Title: Malicious Domains Unbound Blocklist
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1453,6 +1453,7 @@ local-zone: "6735a55d.ngrok.io" always_nxdomain
 local-zone: "67373.vip" always_nxdomain
 local-zone: "67lget9865181258.freebackup.fun" always_nxdomain
 local-zone: "67ms.top" always_nxdomain
+local-zone: "68468438438.xyz" always_nxdomain
 local-zone: "68h7.com" always_nxdomain
 local-zone: "695c0lock1.com" always_nxdomain
 local-zone: "69market2.com" always_nxdomain
@@ -1775,6 +1776,7 @@ local-zone: "998awol.com" always_nxdomain
 local-zone: "999.buzz" always_nxdomain
 local-zone: "999.co.id" always_nxdomain
 local-zone: "999.rajaojek.com" always_nxdomain
+local-zone: "999080321newfolder1002002131-service1002.space" always_nxdomain
 local-zone: "999102com.cn" always_nxdomain
 local-zone: "99bkx.com" always_nxdomain
 local-zone: "99centsdigitals.com" always_nxdomain
@@ -3272,6 +3274,7 @@ local-zone: "adventuredsocks.com" always_nxdomain
 local-zone: "adventureexplorer.in" always_nxdomain
 local-zone: "adventurehr.com" always_nxdomain
 local-zone: "adventureitdate.com" always_nxdomain
+local-zone: "adventureits.com" always_nxdomain
 local-zone: "adventuremania.com" always_nxdomain
 local-zone: "adventurersafaris.com" always_nxdomain
 local-zone: "adventuresofarchibald.com" always_nxdomain
@@ -4300,6 +4303,7 @@ local-zone: "akasyahediyelik.com" always_nxdomain
 local-zone: "akatanomastos.net" always_nxdomain
 local-zone: "akatlot.com" always_nxdomain
 local-zone: "akatsolution.net" always_nxdomain
+local-zone: "akauk09.top" always_nxdomain
 local-zone: "akaunting.redocom.com" always_nxdomain
 local-zone: "akawork.io" always_nxdomain
 local-zone: "akbaara.com" always_nxdomain
@@ -4383,6 +4387,7 @@ local-zone: "akouzelis-patra.gr" always_nxdomain
 local-zone: "akowa.projet-test.com" always_nxdomain
 local-zone: "akowalska.ecrm.pl" always_nxdomain
 local-zone: "akpeugono.com" always_nxdomain
+local-zone: "akpgi08.top" always_nxdomain
 local-zone: "akpp-service.top" always_nxdomain
 local-zone: "akppservis30.ru" always_nxdomain
 local-zone: "akprokonaija.com" always_nxdomain
@@ -16335,6 +16340,7 @@ local-zone: "camelliia.com" always_nxdomain
 local-zone: "camelmorocco.com" always_nxdomain
 local-zone: "camelotbrasil.com" always_nxdomain
 local-zone: "camelotorganics.com" always_nxdomain
+local-zone: "cameltrektours.com" always_nxdomain
 local-zone: "camenisch-software.ch" always_nxdomain
 local-zone: "camera.risami.net" always_nxdomain
 local-zone: "camera88.vn" always_nxdomain
@@ -26356,6 +26362,7 @@ local-zone: "dl-45538429.onedrives-en-live.com" always_nxdomain
 local-zone: "dl-675423.store-downloads.com" always_nxdomain
 local-zone: "dl-80076342.md-downloads.com" always_nxdomain
 local-zone: "dl-97674424.md-downloads.com" always_nxdomain
+local-zone: "dl-link.link" always_nxdomain
 local-zone: "dl-link.live" always_nxdomain
 local-zone: "dl-link.network" always_nxdomain
 local-zone: "dl-rw.com" always_nxdomain
@@ -28027,6 +28034,7 @@ local-zone: "duck.org" always_nxdomain
 local-zone: "duckhouse.org" always_nxdomain
 local-zone: "duckiesplumbing.com.au" always_nxdomain
 local-zone: "duckpvp.xyz" always_nxdomain
+local-zone: "duckrambo.com" always_nxdomain
 local-zone: "ducks.org.tw" always_nxdomain
 local-zone: "ducontcl.esy.es" always_nxdomain
 local-zone: "ducro.nl" always_nxdomain
@@ -35221,6 +35229,7 @@ local-zone: "freedomlifestyleprogram.com" always_nxdomain
 local-zone: "freedomsec.com.br" always_nxdomain
 local-zone: "freedomsolutionsuk.co.uk" always_nxdomain
 local-zone: "freedomtoshine.co" always_nxdomain
+local-zone: "freedomwellnesstherapy.com" always_nxdomain
 local-zone: "freedownloadbravebrowser.com" always_nxdomain
 local-zone: "freeeeweb-com.umbler.net" always_nxdomain
 local-zone: "freeezguru.com" always_nxdomain
@@ -43176,6 +43185,7 @@ local-zone: "iapp-hml.adttemp.com.br" always_nxdomain
 local-zone: "iappco.ir" always_nxdomain
 local-zone: "iar.webprojemiz.com" always_nxdomain
 local-zone: "iarpp.ro" always_nxdomain
+local-zone: "iasdcentralbucaramanga.com" always_nxdomain
 local-zone: "iasgoogle.com" always_nxdomain
 local-zone: "iashelpdesk.in" always_nxdomain
 local-zone: "iasira.dm.files.1drv.com" always_nxdomain
@@ -45480,6 +45490,7 @@ local-zone: "investicon.in" always_nxdomain
 local-zone: "investigadoresforenses-abcjuris.com" always_nxdomain
 local-zone: "investigatorsnorthwest.co.uk" always_nxdomain
 local-zone: "investime.info" always_nxdomain
+local-zone: "investinae.com" always_nxdomain
 local-zone: "investingbazar.com" always_nxdomain
 local-zone: "investingpivot.co.uk" always_nxdomain
 local-zone: "investinscs.com" always_nxdomain
@@ -47703,6 +47714,7 @@ local-zone: "joespoolandspaservice.com" always_nxdomain
 local-zone: "joeundrosky.com" always_nxdomain
 local-zone: "joezer-online.com" always_nxdomain
 local-zone: "jofox.nl" always_nxdomain
+local-zone: "jofre.eu" always_nxdomain
 local-zone: "jogaae.jfoaigh.com" always_nxdomain
 local-zone: "joghataisalam.ir" always_nxdomain
 local-zone: "joghatay.ir" always_nxdomain
@@ -52147,7 +52159,6 @@ local-zone: "laparomc.com" always_nxdomain
 local-zone: "laparoscopysales.com" always_nxdomain
 local-zone: "lapartenza-khl.com" always_nxdomain
 local-zone: "lapc.com.pk" always_nxdomain
-local-zone: "lapcare.com" always_nxdomain
 local-zone: "lapcentervn.xyz" always_nxdomain
 local-zone: "lapchallenge.co.uk" always_nxdomain
 local-zone: "lapelimmortelle.com.au" always_nxdomain
@@ -53213,7 +53224,6 @@ local-zone: "lgjmcaz.cn" always_nxdomain
 local-zone: "lglab.co.uk" always_nxdomain
 local-zone: "lgmi.org.uk" always_nxdomain
 local-zone: "lgonlinecenter.com" always_nxdomain
-local-zone: "lgpass.com" always_nxdomain
 local-zone: "lgrp35.vatelstudents.fr" always_nxdomain
 local-zone: "lgs.ec" always_nxdomain
 local-zone: "lgservis.net" always_nxdomain
@@ -60571,7 +60581,6 @@ local-zone: "moitruongtunglam.com" always_nxdomain
 local-zone: "mojang.com.br" always_nxdomain
 local-zone: "mojehaftom.com" always_nxdomain
 local-zone: "mojewnetrza.pl" always_nxdomain
-local-zone: "mojno--vse.ru" always_nxdomain
 local-zone: "mojo-studios.co.uk" always_nxdomain
 local-zone: "mojorockstar.com" always_nxdomain
 local-zone: "mojstudent.net" always_nxdomain
@@ -61098,7 +61107,6 @@ local-zone: "motus.co.rs" always_nxdomain
 local-zone: "motzadministraties.nl" always_nxdomain
 local-zone: "mouas.xyz" always_nxdomain
 local-zone: "mouaysha.com" always_nxdomain
-local-zone: "moufed.com" always_nxdomain
 local-zone: "moulin-de-la-hunelle.be" always_nxdomain
 local-zone: "mouni11.xyz" always_nxdomain
 local-zone: "mounicmadiraju.com" always_nxdomain
@@ -62406,6 +62414,7 @@ local-zone: "mytelegramapi.ml" always_nxdomain
 local-zone: "mytemplate.ro" always_nxdomain
 local-zone: "mytempucheck.com" always_nxdomain
 local-zone: "mytest.alessioatzeni.com" always_nxdomain
+local-zone: "mytestingserver.ml" always_nxdomain
 local-zone: "mytestwp.cf" always_nxdomain
 local-zone: "mytex.pe" always_nxdomain
 local-zone: "mythelxis.gr" always_nxdomain
@@ -64598,6 +64607,7 @@ local-zone: "no18balloonroom.co.uk" always_nxdomain
 local-zone: "no1angelsescort.com" always_nxdomain
 local-zone: "no1spinningfields.90degrees.digital" always_nxdomain
 local-zone: "no1websitedesigner.com" always_nxdomain
+local-zone: "no2politics.com" always_nxdomain
 local-zone: "no70.fun" always_nxdomain
 local-zone: "noabuseshere.top" always_nxdomain
 local-zone: "noach.nl" always_nxdomain
@@ -66021,6 +66031,7 @@ local-zone: "okz.wloclawek.pl" always_nxdomain
 local-zone: "ol.cognitiononline.in" always_nxdomain
 local-zone: "olacabattachment.com" always_nxdomain
 local-zone: "oladi.sulinet.hu" always_nxdomain
+local-zone: "olafyoutrue.xyz" always_nxdomain
 local-zone: "olahnyomda.hu" always_nxdomain
 local-zone: "olairdryport.com" always_nxdomain
 local-zone: "olalekan419.000webhostapp.com" always_nxdomain
@@ -67151,6 +67162,7 @@ local-zone: "ostappapa.ru" always_nxdomain
 local-zone: "ostappnp.myjino.ru" always_nxdomain
 local-zone: "ostaz.ml" always_nxdomain
 local-zone: "osteklenie-balkonov.tomsk.ru" always_nxdomain
+local-zone: "ostemeda.lt" always_nxdomain
 local-zone: "osteoliv.com" always_nxdomain
 local-zone: "osteopatasitgesblog.es" always_nxdomain
 local-zone: "osteopathin-husum.de" always_nxdomain
@@ -69550,6 +69562,7 @@ local-zone: "physicaltrainernearme.com" always_nxdomain
 local-zone: "physicianmedical-legalconsulting.com" always_nxdomain
 local-zone: "physicscafe.com.sg" always_nxdomain
 local-zone: "physio-bo.de" always_nxdomain
+local-zone: "physio-svdh.ch" always_nxdomain
 local-zone: "physio-veda.de" always_nxdomain
 local-zone: "physionize.com" always_nxdomain
 local-zone: "physiotherapeutinnen.at" always_nxdomain
@@ -73651,6 +73664,7 @@ local-zone: "radioinspiraciontv.com" always_nxdomain
 local-zone: "radiolajee.com" always_nxdomain
 local-zone: "radioland.eu" always_nxdomain
 local-zone: "radiolavariada.net" always_nxdomain
+local-zone: "radiolevi.ro" always_nxdomain
 local-zone: "radiomaismg.com.br" always_nxdomain
 local-zone: "radiomaxima.cl" always_nxdomain
 local-zone: "radiomega-hit.com" always_nxdomain
@@ -76913,6 +76927,7 @@ local-zone: "s-tech.hu" always_nxdomain
 local-zone: "s-vrach.com.ua" always_nxdomain
 local-zone: "s-zone.uz" always_nxdomain
 local-zone: "s.51shijuan.com" always_nxdomain
+local-zone: "s.lletlee.com" always_nxdomain
 local-zone: "s.oooooooooo.ga" always_nxdomain
 local-zone: "s.put.re" always_nxdomain
 local-zone: "s.thechinesemuslim.com" always_nxdomain
@@ -79056,6 +79071,7 @@ local-zone: "seiomon.eu" always_nxdomain
 local-zone: "seioodsoi.club" always_nxdomain
 local-zone: "seis.me" always_nxdomain
 local-zone: "seismophonic.com" always_nxdomain
+local-zone: "seitaiken.net" always_nxdomain
 local-zone: "seitenstreifen.ch" always_nxdomain
 local-zone: "seivenco.com" always_nxdomain
 local-zone: "seiz-ib.de" always_nxdomain
@@ -93513,7 +93529,6 @@ local-zone: "url-update.com" always_nxdomain
 local-zone: "url-validation-clients.com" always_nxdomain
 local-zone: "url.246546.com" always_nxdomain
 local-zone: "url.57569.fr.snd52.ch" always_nxdomain
-local-zone: "url.sg" always_nxdomain
 local-zone: "url3.mailanyone.net" always_nxdomain
 local-zone: "url5459.41southbar.com" always_nxdomain
 local-zone: "url675.textilmallorca.com" always_nxdomain
diff --git a/urlhaus-filter-vivaldi-online.txt b/urlhaus-filter-vivaldi-online.txt
index 6cfcb729..7f4472ff 100644
--- a/urlhaus-filter-vivaldi-online.txt
+++ b/urlhaus-filter-vivaldi-online.txt
@@ -1,5 +1,5 @@
 ! Title: Online Malicious URL Blocklist (Vivaldi)
-! Updated: Sat, 27 Mar 2021 12:12:22 UTC
+! Updated: Sun, 28 Mar 2021 00:12:34 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -7,19 +7,20 @@
 ||0-24bpautomentes.hu$document
 ||0cl.sldov.ru$document
 ||1.11.234.99$document
+||1.186.151.219$document
 ||1.222.140.251$document
-||1.222.166.69$document
 ||1.222.196.60$document
 ||1.245.4.163$document
 ||1.246.222.107$document
 ||1.246.222.109$document
 ||1.246.222.113$document
 ||1.246.222.127$document
-||1.246.222.134$document
+||1.246.222.14$document
 ||1.246.222.153$document
 ||1.246.222.16$document
 ||1.246.222.165$document
 ||1.246.222.228$document
+||1.246.222.232$document
 ||1.246.222.234$document
 ||1.246.222.237$document
 ||1.246.222.245$document
@@ -33,6 +34,7 @@
 ||1.246.222.69$document
 ||1.246.222.8$document
 ||1.246.222.80$document
+||1.246.222.94$document
 ||1.246.222.98$document
 ||1.246.223.10$document
 ||1.246.223.103$document
@@ -48,9 +50,9 @@
 ||1.246.223.32$document
 ||1.246.223.35$document
 ||1.246.223.4$document
-||1.246.223.48$document
 ||1.246.223.49$document
 ||1.246.223.54$document
+||1.246.223.58$document
 ||1.246.223.59$document
 ||1.246.223.6$document
 ||1.246.223.61$document
@@ -70,7 +72,6 @@
 ||100.8.77.4$document
 ||1008691.com$document
 ||101.108.130.108$document
-||101.109.246.33$document
 ||101.16.183.179$document
 ||101.16.98.170$document
 ||101.229.85.127$document
@@ -83,35 +84,40 @@
 ||101.30.38.204$document
 ||101.64.119.250$document
 ||101.64.161.70$document
+||101.66.81.70$document
 ||101.75.157.99$document
 ||102.130.115.14$document
 ||102.141.240.139$document
 ||103.107.113.22$document
 ||103.124.104.118$document
 ||103.125.218.107$document
+||103.126.35.40$document
 ||103.139.89.205$document
 ||103.141.138.12$document
 ||103.145.13.24$document
 ||103.146.174.208$document
+||103.153.92.76$document
 ||103.156.221.66$document
 ||103.159.155.214$document
 ||103.16.145.25$document
 ||103.207.1.146$document
+||103.214.191.141$document
 ||103.217.215.21$document
 ||103.224.200.40$document
 ||103.238.228.3$document
 ||103.238.228.4$document
 ||103.240.249.121$document
+||103.245.49.180$document
 ||103.4.117.26$document
 ||103.66.78.171$document
 ||103.79.112.254$document
-||103.82.145.111$document
 ||103.82.98.170$document
 ||103.84.240.130$document
 ||103.84.240.228$document
 ||103.84.241.123$document
 ||103.84.241.94$document
 ||103.91.245.12$document
+||103.91.245.14$document
 ||103.91.245.16$document
 ||103.91.245.17$document
 ||103.91.245.19$document
@@ -123,6 +129,9 @@
 ||103.91.245.36$document
 ||103.91.245.41$document
 ||103.91.245.46$document
+||103.91.245.49$document
+||103.91.245.54$document
+||103.91.245.58$document
 ||103.92.25.90$document
 ||103.92.25.95$document
 ||104.184.75.123$document
@@ -155,7 +164,6 @@
 ||109.124.90.229$document
 ||109.233.196.232$document
 ||109.235.7.228$document
-||109.248.58.238$document
 ||109.86.85.253$document
 ||109.95.200.102$document
 ||109.95.200.230$document
@@ -181,14 +189,12 @@
 ||110.255.101.184$document
 ||110.255.167.147$document
 ||110.35.145.127$document
-||110.35.208.21$document
+||110.35.209.175$document
 ||110.35.221.77$document
-||110.35.223.92$document
-||110.35.225.24$document
-||110.35.233.147$document
 ||110.35.235.57$document
 ||110.35.4.2$document
 ||110fss.net$document
+||111.118.111.207$document
 ||111.118.88.61$document
 ||111.119.245.114$document
 ||111.125.67.125$document
@@ -228,17 +234,15 @@
 ||111.38.26.243$document
 ||111.38.8.81$document
 ||111.61.52.53$document
-||112.105.117.227$document
-||112.111.100.236$document
 ||112.111.108.184$document
 ||112.111.31.175$document
 ||112.122.62.224$document
-||112.123.200.47$document
+||112.122.63.70$document
 ||112.132.134.106$document
 ||112.132.147.102$document
 ||112.159.108.96$document
+||112.167.165.139$document
 ||112.170.124.75$document
-||112.170.219.168$document
 ||112.170.233.9$document
 ||112.186.210.211$document
 ||112.186.96.252$document
@@ -250,10 +254,8 @@
 ||112.225.52.145$document
 ||112.225.82.4$document
 ||112.226.118.229$document
-||112.226.176.167$document
 ||112.226.195.104$document
 ||112.226.202.111$document
-||112.226.205.96$document
 ||112.226.67.193$document
 ||112.226.92.34$document
 ||112.228.180.95$document
@@ -263,7 +265,6 @@
 ||112.229.188.28$document
 ||112.229.199.19$document
 ||112.230.251.85$document
-||112.234.121.107$document
 ||112.234.134.244$document
 ||112.234.16.252$document
 ||112.234.194.178$document
@@ -293,18 +294,21 @@
 ||112.242.106.228$document
 ||112.242.18.128$document
 ||112.242.2.247$document
+||112.242.97.131$document
 ||112.243.115.183$document
 ||112.245.12.89$document
+||112.245.178.153$document
 ||112.245.5.141$document
 ||112.245.8.24$document
 ||112.246.162.50$document
 ||112.246.180.49$document
 ||112.247.100.14$document
-||112.247.14.135$document
+||112.247.16.222$document
 ||112.247.161.45$document
 ||112.247.191.118$document
 ||112.247.214.146$document
 ||112.247.240.226$document
+||112.247.25.42$document
 ||112.247.81.173$document
 ||112.247.82.122$document
 ||112.248.148.90$document
@@ -329,6 +333,8 @@
 ||112.252.239.103$document
 ||112.252.245.249$document
 ||112.252.46.212$document
+||112.254.128.160$document
+||112.254.188.228$document
 ||112.254.208.123$document
 ||112.254.32.5$document
 ||112.255.127.212$document
@@ -344,7 +350,6 @@
 ||112.27.124.113$document
 ||112.27.124.117$document
 ||112.27.124.119$document
-||112.27.124.120$document
 ||112.27.124.122$document
 ||112.27.124.124$document
 ||112.27.124.127$document
@@ -356,7 +361,6 @@
 ||112.27.124.136$document
 ||112.27.124.138$document
 ||112.27.124.139$document
-||112.27.124.140$document
 ||112.27.124.142$document
 ||112.27.124.143$document
 ||112.27.124.146$document
@@ -372,6 +376,7 @@
 ||112.27.124.168$document
 ||112.27.124.171$document
 ||112.27.124.172$document
+||112.27.124.174$document
 ||112.27.124.175$document
 ||112.27.124.176$document
 ||112.27.124.178$document
@@ -390,16 +395,19 @@
 ||112.27.88.116$document
 ||112.27.91.212$document
 ||112.27.91.247$document
+||112.30.1.133$document
 ||112.30.1.149$document
 ||112.30.1.150$document
 ||112.30.1.158$document
-||112.30.1.159$document
+||112.30.1.164$document
 ||112.30.1.168$document
 ||112.30.1.177$document
 ||112.30.1.178$document
 ||112.30.1.181$document
+||112.30.1.182$document
 ||112.30.1.188$document
 ||112.30.1.190$document
+||112.30.1.194$document
 ||112.30.1.197$document
 ||112.30.1.211$document
 ||112.30.1.219$document
@@ -414,15 +422,15 @@
 ||112.30.1.90$document
 ||112.30.1.91$document
 ||112.30.100.228$document
-||112.30.110.27$document
 ||112.30.110.30$document
 ||112.30.110.31$document
+||112.30.110.36$document
 ||112.30.110.37$document
 ||112.30.110.38$document
 ||112.30.110.41$document
 ||112.30.110.42$document
 ||112.30.110.43$document
-||112.30.110.45$document
+||112.30.110.51$document
 ||112.30.110.52$document
 ||112.30.110.57$document
 ||112.30.110.58$document
@@ -438,6 +446,7 @@
 ||112.30.4.136$document
 ||112.30.4.37$document
 ||112.30.4.52$document
+||112.30.4.53$document
 ||112.30.4.57$document
 ||112.30.4.61$document
 ||112.30.4.70$document
@@ -447,6 +456,7 @@
 ||112.31.176.16$document
 ||112.31.211.135$document
 ||112.31.82.160$document
+||112.31.87.98$document
 ||112.53.224.79$document
 ||112.65.53.175$document
 ||112.72.153.37$document
@@ -455,6 +465,8 @@
 ||112.72.162.53$document
 ||112.72.176.112$document
 ||112.72.176.84$document
+||112.72.226.202$document
+||112.72.231.35$document
 ||112.78.45.158$document
 ||112.80.118.16$document
 ||112.80.127.91$document
@@ -473,31 +485,24 @@
 ||112.9.140.247$document
 ||112.91.219.195$document
 ||112.93.29.211$document
-||112.95.80.165$document
 ||113.0.74.25$document
 ||113.11.95.254$document
 ||113.110.204.254$document
-||113.110.243.79$document
-||113.116.150.147$document
-||113.116.176.26$document
-||113.116.44.33$document
-||113.116.89.82$document
 ||113.118.13.194$document
-||113.118.133.113$document
-||113.118.250.227$document
-||113.118.6.104$document
+||113.118.159.178$document
+||113.119.37.141$document
 ||113.122.238.68$document
 ||113.122.59.84$document
 ||113.161.58.249$document
 ||113.172.250.35$document
 ||113.189.243.248$document
+||113.193.29.42$document
 ||113.194.133.9$document
 ||113.194.135.154$document
 ||113.195.163.26$document
 ||113.195.166.46$document
 ||113.195.168.190$document
 ||113.201.219.47$document
-||113.225.171.27$document
 ||113.226.42.250$document
 ||113.227.128.9$document
 ||113.227.169.170$document
@@ -505,28 +510,22 @@
 ||113.227.35.229$document
 ||113.231.211.131$document
 ||113.231.93.142$document
-||113.232.211.182$document
+||113.232.156.157$document
 ||113.234.224.130$document
 ||113.235.116.209$document
 ||113.253.144.141$document
 ||113.254.169.251$document
 ||113.59.128.133$document
-||113.59.133.16$document
-||113.59.144.42$document
 ||113.59.154.21$document
 ||113.59.191.47$document
 ||113.61.204.205$document
 ||113.86.204.13$document
 ||113.87.203.239$document
-||113.87.227.222$document
-||113.88.100.120$document
-||113.88.104.194$document
-||113.88.111.36$document
-||113.88.209.47$document
 ||113.88.232.36$document
 ||113.88.38.232$document
+||113.88.39.21$document
+||113.90.27.218$document
 ||113.92.93.208$document
-||114.199.204.37$document
 ||114.199.253.235$document
 ||114.224.203.128$document
 ||114.226.100.56$document
@@ -537,7 +536,6 @@
 ||114.229.52.14$document
 ||114.234.189.154$document
 ||114.235.115.236$document
-||114.30.54.64$document
 ||114.79.161.94$document
 ||114.79.172.42$document
 ||115.165.216.112$document
@@ -545,45 +543,49 @@
 ||115.193.83.0$document
 ||115.201.38.185$document
 ||115.201.98.176$document
+||115.205.197.221$document
 ||115.208.97.42$document
 ||115.209.234.226$document
 ||115.223.159.80$document
 ||115.229.250.130$document
-||115.23.88.135$document
 ||115.42.47.36$document
 ||115.48.163.47$document
 ||115.48.179.43$document
 ||115.48.188.17$document
-||115.48.200.115$document
-||115.48.49.84$document
+||115.48.201.26$document
+||115.48.41.101$document
 ||115.49.124.80$document
 ||115.49.158.175$document
+||115.49.24.63$document
 ||115.49.36.220$document
-||115.49.43.52$document
-||115.49.80.117$document
-||115.49.96.88$document
-||115.50.15.24$document
+||115.49.79.131$document
+||115.50.1.41$document
+||115.50.168.160$document
+||115.50.171.192$document
+||115.50.175.205$document
 ||115.50.19.136$document
 ||115.50.20.73$document
 ||115.50.206.128$document
-||115.50.226.30$document
-||115.50.228.168$document
+||115.50.211.74$document
 ||115.50.238.227$document
 ||115.50.239.77$document
-||115.50.240.72$document
+||115.50.242.7$document
+||115.50.247.46$document
 ||115.50.61.82$document
+||115.50.79.78$document
 ||115.50.91.30$document
 ||115.50.96.254$document
-||115.51.104.85$document
-||115.51.106.209$document
+||115.51.7.254$document
 ||115.52.17.196$document
+||115.52.172.72$document
 ||115.53.200.130$document
 ||115.53.224.134$document
 ||115.53.234.210$document
-||115.53.238.224$document
+||115.53.58.228$document
+||115.54.113.49$document
 ||115.54.123.147$document
-||115.54.70.108$document
-||115.55.105.154$document
+||115.54.158.251$document
+||115.55.127.0$document
 ||115.55.144.42$document
 ||115.55.145.147$document
 ||115.55.157.96$document
@@ -591,64 +593,67 @@
 ||115.55.158.250$document
 ||115.55.161.38$document
 ||115.55.179.168$document
+||115.55.198.105$document
 ||115.55.206.35$document
 ||115.55.206.78$document
 ||115.55.26.94$document
 ||115.55.42.200$document
+||115.55.52.17$document
 ||115.56.111.63$document
 ||115.56.114.17$document
-||115.56.132.61$document
+||115.56.131.150$document
 ||115.56.133.96$document
 ||115.56.134.79$document
+||115.56.135.255$document
 ||115.56.137.48$document
 ||115.56.139.122$document
-||115.56.143.241$document
+||115.56.142.45$document
 ||115.56.145.102$document
 ||115.56.148.22$document
+||115.56.150.149$document
 ||115.56.151.65$document
 ||115.56.151.68$document
 ||115.56.154.147$document
-||115.56.175.2$document
+||115.56.155.50$document
 ||115.56.189.162$document
+||115.56.31.11$document
 ||115.56.31.54$document
 ||115.56.98.205$document
 ||115.56.99.235$document
 ||115.58.132.199$document
 ||115.58.134.143$document
-||115.58.161.17$document
+||115.58.86.217$document
 ||115.58.90.143$document
+||115.58.91.65$document
 ||115.59.198.69$document
-||115.59.209.196$document
 ||115.59.212.193$document
 ||115.59.214.107$document
 ||115.59.228.237$document
-||115.59.235.229$document
 ||115.59.253.202$document
 ||115.59.57.171$document
 ||115.59.82.123$document
-||115.61.102.110$document
+||115.61.103.197$document
+||115.61.112.159$document
 ||115.61.118.201$document
 ||115.61.118.90$document
-||115.61.139.74$document
-||115.62.152.207$document
+||115.61.158.98$document
 ||115.62.155.83$document
+||115.62.171.143$document
 ||115.62.26.39$document
+||115.63.131.173$document
 ||115.63.139.175$document
 ||115.63.141.147$document
 ||115.63.180.149$document
 ||115.63.189.77$document
 ||115.63.21.130$document
-||115.63.37.6$document
 ||115.63.53.188$document
 ||115.73.3.11$document
 ||115.75.217.79$document
 ||115.78.133.146$document
 ||115.92.174.231$document
-||115.96.61.246$document
-||115.97.136.10$document
+||115.97.139.32$document
 ||116.124.219.2$document
 ||116.149.243.14$document
-||116.2.100.221$document
 ||116.206.164.46$document
 ||116.207.71.237$document
 ||116.211.100.26$document
@@ -656,22 +661,27 @@
 ||116.212.142.215$document
 ||116.30.4.2$document
 ||116.30.95.156$document
-||116.72.51.230$document
-||116.73.222.118$document
-||116.75.199.105$document
-||116.75.212.119$document
+||116.72.28.239$document
+||116.73.52.125$document
+||116.74.101.150$document
+||116.74.17.122$document
+||116.75.193.33$document
+||116.75.198.85$document
+||116.75.212.81$document
 ||116.76.114.71$document
+||116.9.43.220$document
 ||117.11.234.35$document
 ||117.12.48.157$document
 ||117.156.69.22$document
-||117.192.224.103$document
-||117.192.225.161$document
-||117.192.225.195$document
-||117.192.227.137$document
-||117.194.160.78$document
-||117.194.163.210$document
-||117.194.166.103$document
-||117.194.166.20$document
+||117.194.148.198$document
+||117.194.160.203$document
+||117.194.164.123$document
+||117.194.167.131$document
+||117.196.48.148$document
+||117.196.48.181$document
+||117.196.50.154$document
+||117.196.50.239$document
+||117.196.50.76$document
 ||117.20.204.138$document
 ||117.20.204.5$document
 ||117.20.210.52$document
@@ -679,43 +689,17 @@
 ||117.20.243.40$document
 ||117.200.76.54$document
 ||117.200.76.60$document
-||117.202.67.238$document
-||117.202.67.246$document
-||117.202.67.4$document
-||117.202.70.96$document
-||117.202.71.179$document
-||117.207.5.156$document
-||117.208.134.226$document
-||117.208.134.64$document
-||117.213.11.104$document
-||117.213.14.17$document
-||117.213.14.30$document
-||117.213.14.62$document
-||117.213.15.179$document
-||117.213.43.219$document
-||117.213.44.116$document
-||117.213.46.160$document
-||117.213.47.183$document
-||117.213.8.163$document
-||117.215.248.14$document
-||117.215.251.253$document
-||117.222.160.108$document
-||117.222.162.50$document
-||117.222.164.19$document
-||117.222.164.21$document
-||117.222.169.141$document
-||117.222.172.16$document
-||117.222.174.16$document
+||117.202.67.92$document
+||117.208.132.10$document
+||117.208.132.45$document
+||117.213.44.102$document
+||117.222.161.42$document
+||117.222.164.100$document
+||117.222.164.189$document
+||117.222.173.218$document
+||117.222.175.120$document
 ||117.241.64.105$document
-||117.241.67.141$document
-||117.242.208.153$document
-||117.242.208.95$document
-||117.247.200.129$document
-||117.247.202.150$document
-||117.247.203.156$document
-||117.247.204.118$document
-||117.247.204.66$document
-||117.251.60.194$document
+||117.248.62.29$document
 ||117.26.235.164$document
 ||117.27.10.73$document
 ||117.60.204.190$document
@@ -727,7 +711,8 @@
 ||117.91.240.50$document
 ||117.93.115.242$document
 ||117.93.79.40$document
-||118.172.80.79$document
+||118.114.84.237$document
+||118.172.176.41$document
 ||118.176.104.35$document
 ||118.176.157.64$document
 ||118.176.7.132$document
@@ -749,10 +734,8 @@
 ||118.250.51.192$document
 ||118.42.125.246$document
 ||118.43.180.33$document
-||118.68.245.69$document
 ||118.70.83.140$document
 ||118.75.120.136$document
-||118.75.200.198$document
 ||118.75.240.136$document
 ||118.75.240.239$document
 ||118.75.50.253$document
@@ -763,23 +746,21 @@
 ||118.79.218.157$document
 ||118.79.50.203$document
 ||118.79.58.82$document
+||118.79.96.11$document
 ||118.83.79.43$document
-||118.91.24.27$document
+||118.91.41.135$document
 ||118.99.179.164$document
 ||118.99.183.235$document
 ||118.99.239.217$document
 ||119.100.40.250$document
 ||119.108.251.176$document
-||119.109.34.245$document
 ||119.112.22.58$document
-||119.112.27.20$document
 ||119.115.247.23$document
+||119.118.150.84$document
+||119.119.176.198$document
 ||119.119.52.202$document
-||119.123.125.139$document
-||119.123.216.42$document
-||119.123.218.76$document
-||119.123.221.158$document
-||119.123.237.218$document
+||119.123.173.95$document
+||119.123.175.210$document
 ||119.14.143.145$document
 ||119.147.213.57$document
 ||119.162.109.111$document
@@ -837,7 +818,6 @@
 ||119.189.227.244$document
 ||119.190.211.99$document
 ||119.190.234.181$document
-||119.190.240.238$document
 ||119.191.150.85$document
 ||119.191.187.206$document
 ||119.191.215.221$document
@@ -849,13 +829,12 @@
 ||119.251.12.85$document
 ||119.251.14.251$document
 ||119.56.131.155$document
+||119.56.140.73$document
 ||119.56.143.46$document
 ||119.56.143.71$document
-||119.56.144.75$document
 ||119.56.148.115$document
 ||119.56.155.57$document
 ||119.56.172.28$document
-||119.56.195.90$document
 ||119.96.37.55$document
 ||119.96.70.116$document
 ||119.99.188.187$document
@@ -870,6 +849,7 @@
 ||12.207.39.227$document
 ||120.12.153.54$document
 ||120.12.212.5$document
+||120.12.231.61$document
 ||120.142.222.22$document
 ||120.150.213.110$document
 ||120.151.248.134$document
@@ -892,6 +872,7 @@
 ||120.193.91.201$document
 ||120.193.91.202$document
 ||120.193.91.204$document
+||120.193.91.205$document
 ||120.193.91.207$document
 ||120.193.91.208$document
 ||120.193.91.212$document
@@ -913,31 +894,28 @@
 ||120.5.15.95$document
 ||120.50.66.60$document
 ||120.50.93.115$document
+||120.57.214.228$document
 ||120.57.98.208$document
 ||120.6.141.142$document
+||120.6.241.130$document
 ||120.6.8.11$document
 ||120.69.131.51$document
 ||120.7.75.99$document
 ||120.7.90.104$document
 ||120.83.189.232$document
 ||120.85.165.112$document
-||120.85.169.113$document
-||120.85.170.109$document
-||120.85.173.234$document
 ||120.85.185.141$document
-||120.85.236.95$document
+||120.85.196.211$document
+||120.85.208.107$document
 ||120.85.238.10$document
-||120.85.238.244$document
 ||120.9.32.51$document
 ||121.100.114.164$document
 ||121.100.96.8$document
 ||121.121.44.222$document
 ||121.123.53.25$document
 ||121.127.155.220$document
-||121.136.249.5$document
 ||121.141.11.56$document
 ||121.15.142.137$document
-||121.151.78.190$document
 ||121.159.22.144$document
 ||121.17.103.176$document
 ||121.170.234.142$document
@@ -955,32 +933,25 @@
 ||121.25.101.86$document
 ||121.254.43.215$document
 ||121.254.76.17$document
-||121.61.101.93$document
 ||121.61.102.1$document
 ||121.61.107.189$document
 ||121.61.97.195$document
 ||121.61.98.151$document
 ||121.88.99.236$document
 ||122.100.150.204$document
-||122.137.52.122$document
 ||122.160.147.53$document
 ||122.176.44.34$document
 ||122.188.86.225$document
-||122.190.19.204$document
-||122.192.190.203$document
 ||122.199.66.28$document
 ||122.199.72.23$document
 ||122.199.79.27$document
 ||122.202.37.85$document
 ||122.202.41.23$document
 ||122.252.199.3$document
-||122.252.250.22$document
 ||122.254.183.207$document
 ||122.254.29.37$document
 ||122.254.33.214$document
 ||123.0.240.58$document
-||123.10.131.225$document
-||123.10.41.32$document
 ||123.10.83.136$document
 ||123.11.11.207$document
 ||123.11.4.168$document
@@ -993,16 +964,19 @@
 ||123.110.19.248$document
 ||123.110.200.98$document
 ||123.110.238.188$document
-||123.12.7.82$document
+||123.12.189.247$document
+||123.12.225.70$document
+||123.12.235.159$document
+||123.12.243.85$document
 ||123.128.128.205$document
 ||123.128.133.91$document
 ||123.128.177.161$document
 ||123.129.84.36$document
 ||123.129.88.123$document
-||123.13.44.60$document
 ||123.130.202.8$document
 ||123.130.208.52$document
 ||123.130.23.110$document
+||123.130.27.19$document
 ||123.130.37.182$document
 ||123.130.61.210$document
 ||123.130.77.225$document
@@ -1014,16 +988,19 @@
 ||123.133.98.135$document
 ||123.134.14.130$document
 ||123.134.50.186$document
-||123.135.157.193$document
 ||123.135.39.36$document
 ||123.135.71.150$document
-||123.14.172.149$document
-||123.14.86.82$document
+||123.14.127.238$document
+||123.14.173.199$document
+||123.14.249.33$document
+||123.14.34.240$document
+||123.14.37.32$document
+||123.14.50.214$document
 ||123.14.93.154$document
 ||123.144.211.86$document
 ||123.152.42.4$document
-||123.152.43.21$document
 ||123.153.80.178$document
+||123.154.116.116$document
 ||123.154.236.114$document
 ||123.154.94.1$document
 ||123.155.118.36$document
@@ -1060,22 +1037,23 @@
 ||123.28.217.23$document
 ||123.4.11.40$document
 ||123.4.166.2$document
-||123.4.176.22$document
 ||123.4.177.93$document
-||123.4.193.171$document
+||123.4.194.152$document
 ||123.4.209.154$document
 ||123.4.241.118$document
+||123.4.45.31$document
 ||123.4.76.117$document
 ||123.4.83.66$document
 ||123.4.85.149$document
-||123.5.123.60$document
 ||123.5.143.203$document
 ||123.5.146.238$document
 ||123.5.190.167$document
 ||123.5.5.242$document
 ||123.5.8.211$document
 ||123.8.56.94$document
+||123.8.71.27$document
 ||123.9.194.169$document
+||123.9.240.115$document
 ||123.9.245.207$document
 ||124.105.105.222$document
 ||124.129.162.169$document
@@ -1087,7 +1065,9 @@
 ||124.131.130.95$document
 ||124.131.131.71$document
 ||124.131.136.75$document
+||124.131.137.147$document
 ||124.131.151.135$document
+||124.131.24.185$document
 ||124.131.26.243$document
 ||124.131.26.78$document
 ||124.131.41.48$document
@@ -1111,7 +1091,6 @@
 ||124.199.56.198$document
 ||124.226.24.117$document
 ||124.230.174.233$document
-||124.234.6.130$document
 ||124.254.254.61$document
 ||124.5.92.20$document
 ||124.6.0.4$document
@@ -1119,8 +1098,8 @@
 ||124.7.254.85$document
 ||124.80.46.73$document
 ||124.91.237.147$document
+||124.92.135.37$document
 ||124.93.94.207$document
-||124.95.17.41$document
 ||125.105.219.169$document
 ||125.126.69.95$document
 ||125.128.28.161$document
@@ -1131,65 +1110,64 @@
 ||125.36.148.42$document
 ||125.40.1.127$document
 ||125.40.113.66$document
-||125.40.160.116$document
-||125.40.17.14$document
-||125.40.237.130$document
 ||125.40.25.140$document
 ||125.40.65.120$document
 ||125.40.73.6$document
 ||125.40.74.153$document
 ||125.40.75.22$document
+||125.41.141.41$document
+||125.41.164.60$document
+||125.41.185.186$document
+||125.41.196.114$document
 ||125.41.208.139$document
-||125.41.244.43$document
 ||125.41.6.192$document
 ||125.41.7.204$document
 ||125.41.74.22$document
 ||125.41.96.238$document
 ||125.41.96.33$document
+||125.41.97.231$document
 ||125.41.97.81$document
 ||125.42.107.136$document
 ||125.42.124.114$document
-||125.42.98.24$document
-||125.42.98.35$document
 ||125.43.112.123$document
 ||125.43.112.182$document
 ||125.43.133.130$document
 ||125.43.167.192$document
-||125.43.2.169$document
-||125.43.21.157$document
 ||125.43.215.244$document
-||125.43.26.36$document
 ||125.43.33.20$document
-||125.43.37.138$document
 ||125.43.53.50$document
 ||125.43.53.9$document
+||125.43.6.186$document
 ||125.43.60.218$document
-||125.43.73.19$document
-||125.43.92.62$document
+||125.43.63.47$document
 ||125.44.10.125$document
 ||125.44.107.182$document
 ||125.44.175.118$document
 ||125.44.198.62$document
+||125.44.208.152$document
 ||125.44.212.131$document
-||125.44.243.220$document
-||125.44.31.79$document
+||125.44.227.51$document
+||125.44.70.64$document
 ||125.44.8.227$document
 ||125.45.153.91$document
+||125.45.43.63$document
 ||125.45.55.146$document
-||125.46.138.117$document
+||125.46.166.112$document
 ||125.46.166.125$document
 ||125.46.205.88$document
 ||125.46.206.160$document
 ||125.46.217.52$document
 ||125.46.241.237$document
+||125.47.125.16$document
 ||125.47.241.188$document
 ||125.47.245.200$document
+||125.47.248.131$document
 ||125.47.250.98$document
-||125.47.252.106$document
-||125.47.254.154$document
 ||125.47.254.44$document
 ||125.47.28.18$document
+||125.47.38.142$document
 ||125.47.45.218$document
+||125.47.47.212$document
 ||125.47.57.80$document
 ||125.47.91.51$document
 ||125.79.192.197$document
@@ -1202,12 +1180,13 @@
 ||139.159.226.180$document
 ||139.170.173.198$document
 ||139.170.174.162$document
+||139.213.97.191$document
 ||139.216.102.151$document
 ||139.227.46.137$document
 ||14.102.17.222$document
 ||14.102.97.204$document
+||14.109.126.96$document
 ||14.136.80.242$document
-||14.138.109.129$document
 ||14.138.109.26$document
 ||14.138.8.215$document
 ||14.138.8.51$document
@@ -1225,27 +1204,25 @@
 ||14.55.29.2$document
 ||14.98.184.178$document
 ||140.237.30.113$document
+||140.237.30.172$document
 ||140.237.5.43$document
+||140.240.151.177$document
 ||142.11.216.5$document
 ||142.177.56.127$document
 ||146.71.79.230$document
 ||148.69.108.177$document
 ||149.20.176.179$document
-||149.255.15.112$document
 ||149.255.15.134$document
+||149.255.15.172$document
 ||149.255.15.180$document
 ||149.255.15.182$document
 ||149.255.15.184$document
-||149.255.15.191$document
 ||149.255.15.213$document
-||149.255.15.235$document
-||149.255.15.27$document
 ||149.255.15.43$document
 ||149.255.15.87$document
 ||149.255.15.99$document
 ||149.3.124.194$document
-||149.3.36.210$document
-||149.3.85.55$document
+||149.3.73.210$document
 ||150.116.207.99$document
 ||151.177.163.87$document
 ||151.33.230.191$document
@@ -1258,7 +1235,6 @@
 ||153.34.135.92$document
 ||153.34.23.76$document
 ||153.34.29.28$document
-||153.35.111.46$document
 ||153.35.27.49$document
 ||153.36.126.35$document
 ||158.101.165.14$document
@@ -1269,27 +1245,28 @@
 ||162.191.205.175$document
 ||162.194.28.60$document
 ||162.209.98.174$document
-||163.125.125.6$document
-||163.125.157.64$document
+||162.212.203.250$document
 ||163.125.18.93$document
 ||163.125.193.148$document
-||163.125.195.248$document
-||163.125.200.199$document
+||163.125.200.118$document
+||163.125.200.242$document
 ||163.125.202.193$document
-||163.125.202.195$document
-||163.125.202.21$document
+||163.125.202.255$document
+||163.125.202.87$document
 ||163.125.203.198$document
+||163.125.203.236$document
 ||163.125.204.156$document
-||163.125.204.244$document
 ||163.125.204.34$document
-||163.125.207.61$document
-||163.125.243.131$document
+||163.125.206.16$document
 ||163.125.255.165$document
 ||163.204.208.169$document
+||163.204.211.136$document
 ||163.204.211.228$document
 ||163.204.211.58$document
 ||163.53.206.228$document
 ||165.90.16.5$document
+||168.194.146.145$document
+||168.205.223.254$document
 ||168.90.204.207$document
 ||170.81.238.178$document
 ||171.113.36.216$document
@@ -1303,11 +1280,13 @@
 ||171.120.125.147$document
 ||171.121.6.162$document
 ||171.123.134.239$document
+||171.125.122.91$document
 ||171.125.242.71$document
 ||171.125.30.233$document
 ||171.125.30.93$document
 ||171.125.64.223$document
 ||171.125.65.22$document
+||171.125.65.89$document
 ||171.125.75.68$document
 ||171.126.70.133$document
 ||171.223.72.123$document
@@ -1321,7 +1300,6 @@
 ||171.36.249.91$document
 ||171.38.145.146$document
 ||171.38.148.69$document
-||171.38.217.222$document
 ||171.38.219.189$document
 ||171.38.223.110$document
 ||171.38.223.213$document
@@ -1353,12 +1331,13 @@
 ||175.145.200.216$document
 ||175.146.17.227$document
 ||175.150.168.92$document
-||175.153.144.2$document
 ||175.162.137.166$document
 ||175.162.195.27$document
 ||175.162.69.13$document
+||175.164.61.215$document
 ||175.165.90.198$document
 ||175.168.139.182$document
+||175.169.13.182$document
 ||175.17.90.14$document
 ||175.174.93.57$document
 ||175.199.33.139$document
@@ -1375,10 +1354,8 @@
 ||176.111.174.67$document
 ||176.113.161.104$document
 ||176.113.161.113$document
-||176.113.161.120$document
 ||176.113.161.128$document
-||176.113.161.138$document
-||176.113.161.59$document
+||176.113.161.60$document
 ||176.113.161.65$document
 ||176.113.161.66$document
 ||176.113.161.76$document
@@ -1392,37 +1369,36 @@
 ||176.123.7.127$document
 ||176.123.9.243$document
 ||176.124.7.225$document
+||176.221.251.238$document
 ||176.240.40.142$document
 ||176.240.84.106$document
 ||177.11.92.78$document
 ||177.131.226.235$document
 ||177.229.64.218$document
-||177.44.61.243$document
-||177.86.235.143$document
+||177.54.82.154$document
 ||178.124.182.187$document
-||178.141.125.98$document
+||178.134.185.112$document
 ||178.141.25.82$document
+||178.141.44.152$document
 ||178.141.45.2$document
 ||178.141.57.166$document
 ||178.150.174.65$document
 ||178.151.143.2$document
 ||178.165.122.141$document
 ||178.175.0.140$document
-||178.175.0.42$document
-||178.175.0.47$document
 ||178.175.1.139$document
-||178.175.1.143$document
 ||178.175.1.153$document
+||178.175.1.176$document
 ||178.175.1.182$document
-||178.175.1.224$document
 ||178.175.1.244$document
-||178.175.1.247$document
 ||178.175.1.249$document
 ||178.175.1.250$document
 ||178.175.1.252$document
+||178.175.1.44$document
 ||178.175.1.80$document
-||178.175.1.99$document
-||178.175.10.102$document
+||178.175.10.104$document
+||178.175.10.121$document
+||178.175.10.178$document
 ||178.175.10.34$document
 ||178.175.10.42$document
 ||178.175.10.71$document
@@ -1430,118 +1406,117 @@
 ||178.175.100.110$document
 ||178.175.100.129$document
 ||178.175.100.180$document
-||178.175.100.187$document
-||178.175.100.190$document
+||178.175.100.191$document
 ||178.175.100.218$document
 ||178.175.100.34$document
 ||178.175.100.4$document
-||178.175.100.87$document
+||178.175.100.52$document
 ||178.175.101.110$document
-||178.175.101.243$document
+||178.175.101.173$document
+||178.175.101.191$document
 ||178.175.102.134$document
-||178.175.102.152$document
-||178.175.102.190$document
+||178.175.102.14$document
 ||178.175.102.221$document
-||178.175.102.228$document
 ||178.175.102.245$document
 ||178.175.102.35$document
 ||178.175.102.53$document
 ||178.175.103.172$document
-||178.175.103.195$document
+||178.175.103.24$document
+||178.175.103.246$document
 ||178.175.103.27$document
 ||178.175.104.106$document
 ||178.175.104.110$document
 ||178.175.104.120$document
 ||178.175.104.140$document
+||178.175.104.151$document
 ||178.175.104.155$document
 ||178.175.104.16$document
-||178.175.104.169$document
-||178.175.104.183$document
-||178.175.104.196$document
+||178.175.104.199$document
 ||178.175.104.206$document
+||178.175.104.239$document
 ||178.175.104.49$document
+||178.175.105.122$document
 ||178.175.105.125$document
 ||178.175.105.146$document
 ||178.175.105.197$document
 ||178.175.105.217$document
-||178.175.105.220$document
+||178.175.105.240$document
 ||178.175.105.245$document
+||178.175.105.248$document
 ||178.175.106.104$document
 ||178.175.106.106$document
 ||178.175.106.118$document
+||178.175.106.149$document
 ||178.175.106.18$document
 ||178.175.106.193$document
+||178.175.106.36$document
 ||178.175.106.37$document
 ||178.175.106.77$document
+||178.175.106.83$document
 ||178.175.107.0$document
 ||178.175.107.133$document
 ||178.175.107.149$document
 ||178.175.107.240$document
 ||178.175.107.245$document
 ||178.175.107.83$document
+||178.175.108.65$document
 ||178.175.108.87$document
 ||178.175.108.94$document
 ||178.175.109.132$document
 ||178.175.109.140$document
+||178.175.109.227$document
 ||178.175.109.37$document
 ||178.175.109.77$document
-||178.175.11.109$document
+||178.175.11.155$document
 ||178.175.11.165$document
 ||178.175.11.176$document
-||178.175.11.184$document
 ||178.175.11.204$document
+||178.175.11.241$document
 ||178.175.11.57$document
 ||178.175.11.6$document
 ||178.175.110.155$document
 ||178.175.110.169$document
+||178.175.110.194$document
 ||178.175.110.197$document
 ||178.175.110.198$document
 ||178.175.110.221$document
-||178.175.110.250$document
 ||178.175.111.105$document
 ||178.175.111.159$document
 ||178.175.111.187$document
 ||178.175.111.190$document
-||178.175.111.203$document
+||178.175.111.195$document
 ||178.175.111.206$document
-||178.175.111.36$document
 ||178.175.111.98$document
 ||178.175.112.139$document
 ||178.175.112.147$document
 ||178.175.112.159$document
 ||178.175.112.4$document
 ||178.175.112.46$document
-||178.175.112.59$document
-||178.175.112.66$document
 ||178.175.112.85$document
-||178.175.113.174$document
 ||178.175.114.200$document
 ||178.175.114.254$document
-||178.175.114.29$document
-||178.175.114.51$document
 ||178.175.114.55$document
 ||178.175.114.63$document
 ||178.175.114.90$document
 ||178.175.114.99$document
-||178.175.115.138$document
+||178.175.115.147$document
+||178.175.115.175$document
 ||178.175.115.206$document
 ||178.175.115.208$document
+||178.175.115.88$document
+||178.175.116.101$document
+||178.175.116.170$document
 ||178.175.116.188$document
-||178.175.116.200$document
 ||178.175.116.227$document
 ||178.175.116.48$document
 ||178.175.116.64$document
-||178.175.117.209$document
-||178.175.117.215$document
+||178.175.117.12$document
 ||178.175.117.39$document
-||178.175.117.51$document
 ||178.175.118.112$document
 ||178.175.118.113$document
-||178.175.118.165$document
 ||178.175.118.192$document
 ||178.175.118.198$document
 ||178.175.118.47$document
-||178.175.118.60$document
 ||178.175.119.215$document
 ||178.175.119.237$document
 ||178.175.119.26$document
@@ -1553,53 +1528,45 @@
 ||178.175.12.40$document
 ||178.175.12.53$document
 ||178.175.12.70$document
+||178.175.12.93$document
 ||178.175.12.97$document
-||178.175.120.133$document
-||178.175.120.162$document
 ||178.175.120.184$document
-||178.175.120.196$document
 ||178.175.120.203$document
 ||178.175.120.231$document
 ||178.175.120.4$document
+||178.175.120.5$document
+||178.175.121.104$document
 ||178.175.121.116$document
-||178.175.121.122$document
 ||178.175.121.123$document
 ||178.175.121.155$document
-||178.175.121.190$document
+||178.175.121.19$document
+||178.175.121.192$document
+||178.175.121.193$document
 ||178.175.121.229$document
-||178.175.121.63$document
-||178.175.121.83$document
-||178.175.122.123$document
-||178.175.122.130$document
-||178.175.122.168$document
+||178.175.122.199$document
 ||178.175.122.201$document
+||178.175.122.208$document
 ||178.175.122.217$document
 ||178.175.122.245$document
 ||178.175.122.26$document
 ||178.175.122.28$document
 ||178.175.123.191$document
-||178.175.123.196$document
 ||178.175.123.2$document
+||178.175.123.26$document
 ||178.175.123.30$document
-||178.175.123.40$document
 ||178.175.123.56$document
 ||178.175.123.7$document
 ||178.175.123.90$document
 ||178.175.124.109$document
 ||178.175.124.122$document
-||178.175.124.131$document
 ||178.175.124.197$document
 ||178.175.124.4$document
 ||178.175.124.79$document
 ||178.175.124.89$document
-||178.175.124.9$document
 ||178.175.125.14$document
 ||178.175.125.153$document
-||178.175.125.174$document
-||178.175.125.227$document
-||178.175.125.39$document
+||178.175.125.56$document
 ||178.175.126.167$document
-||178.175.126.171$document
 ||178.175.126.220$document
 ||178.175.126.222$document
 ||178.175.126.237$document
@@ -1608,27 +1575,26 @@
 ||178.175.126.83$document
 ||178.175.126.93$document
 ||178.175.127.10$document
-||178.175.127.119$document
 ||178.175.127.122$document
 ||178.175.127.15$document
 ||178.175.127.159$document
 ||178.175.127.166$document
+||178.175.127.168$document
 ||178.175.127.176$document
+||178.175.127.219$document
 ||178.175.127.230$document
 ||178.175.127.231$document
 ||178.175.127.236$document
-||178.175.127.237$document
+||178.175.127.43$document
 ||178.175.127.63$document
 ||178.175.127.64$document
 ||178.175.127.75$document
-||178.175.13.1$document
-||178.175.13.157$document
+||178.175.127.97$document
 ||178.175.13.19$document
 ||178.175.13.220$document
 ||178.175.13.237$document
-||178.175.13.250$document
+||178.175.14.131$document
 ||178.175.14.178$document
-||178.175.14.185$document
 ||178.175.14.230$document
 ||178.175.14.60$document
 ||178.175.14.69$document
@@ -1636,11 +1602,9 @@
 ||178.175.15.199$document
 ||178.175.15.215$document
 ||178.175.15.217$document
-||178.175.15.253$document
 ||178.175.15.35$document
 ||178.175.15.45$document
 ||178.175.15.5$document
-||178.175.15.85$document
 ||178.175.16.1$document
 ||178.175.16.108$document
 ||178.175.16.114$document
@@ -1648,11 +1612,11 @@
 ||178.175.16.179$document
 ||178.175.16.221$document
 ||178.175.16.49$document
-||178.175.16.59$document
 ||178.175.16.73$document
 ||178.175.16.97$document
+||178.175.17.118$document
 ||178.175.17.245$document
-||178.175.18.93$document
+||178.175.17.66$document
 ||178.175.19.163$document
 ||178.175.19.174$document
 ||178.175.19.229$document
@@ -1660,6 +1624,7 @@
 ||178.175.2.108$document
 ||178.175.2.110$document
 ||178.175.2.123$document
+||178.175.2.186$document
 ||178.175.2.188$document
 ||178.175.2.237$document
 ||178.175.2.41$document
@@ -1668,22 +1633,21 @@
 ||178.175.2.54$document
 ||178.175.20.117$document
 ||178.175.20.170$document
-||178.175.20.225$document
 ||178.175.20.237$document
 ||178.175.20.24$document
 ||178.175.20.70$document
+||178.175.20.97$document
 ||178.175.21.149$document
-||178.175.21.170$document
 ||178.175.21.184$document
 ||178.175.21.233$document
 ||178.175.21.238$document
+||178.175.21.28$document
 ||178.175.21.76$document
 ||178.175.21.8$document
 ||178.175.22.110$document
 ||178.175.22.147$document
 ||178.175.22.237$document
 ||178.175.22.247$document
-||178.175.23.102$document
 ||178.175.23.156$document
 ||178.175.23.228$document
 ||178.175.23.250$document
@@ -1693,24 +1657,22 @@
 ||178.175.24.171$document
 ||178.175.24.172$document
 ||178.175.24.177$document
-||178.175.24.216$document
+||178.175.24.198$document
 ||178.175.24.218$document
 ||178.175.24.238$document
 ||178.175.24.243$document
 ||178.175.24.77$document
 ||178.175.25.113$document
 ||178.175.25.117$document
-||178.175.25.169$document
+||178.175.25.148$document
 ||178.175.25.177$document
 ||178.175.25.28$document
 ||178.175.25.46$document
 ||178.175.25.56$document
-||178.175.25.64$document
 ||178.175.25.75$document
 ||178.175.25.77$document
 ||178.175.26.112$document
 ||178.175.26.116$document
-||178.175.26.164$document
 ||178.175.26.165$document
 ||178.175.26.209$document
 ||178.175.26.215$document
@@ -1719,7 +1681,7 @@
 ||178.175.26.246$document
 ||178.175.26.34$document
 ||178.175.27.106$document
-||178.175.27.122$document
+||178.175.27.137$document
 ||178.175.27.138$document
 ||178.175.27.14$document
 ||178.175.27.167$document
@@ -1727,43 +1689,50 @@
 ||178.175.27.177$document
 ||178.175.27.179$document
 ||178.175.27.199$document
-||178.175.27.202$document
 ||178.175.27.215$document
 ||178.175.27.225$document
 ||178.175.27.233$document
 ||178.175.27.239$document
+||178.175.27.244$document
 ||178.175.27.32$document
 ||178.175.27.37$document
 ||178.175.27.46$document
 ||178.175.27.48$document
-||178.175.27.68$document
 ||178.175.27.69$document
 ||178.175.28.102$document
 ||178.175.28.199$document
+||178.175.28.200$document
+||178.175.28.51$document
+||178.175.28.69$document
 ||178.175.29.16$document
 ||178.175.29.173$document
 ||178.175.29.174$document
 ||178.175.29.2$document
 ||178.175.29.201$document
 ||178.175.29.207$document
+||178.175.29.208$document
 ||178.175.29.220$document
+||178.175.29.7$document
 ||178.175.3.116$document
-||178.175.3.130$document
 ||178.175.3.166$document
 ||178.175.3.172$document
 ||178.175.3.190$document
 ||178.175.3.196$document
 ||178.175.3.214$document
+||178.175.3.66$document
+||178.175.3.87$document
 ||178.175.30.0$document
 ||178.175.30.135$document
 ||178.175.30.213$document
-||178.175.30.252$document
 ||178.175.30.70$document
 ||178.175.30.93$document
 ||178.175.30.96$document
 ||178.175.31.171$document
 ||178.175.31.251$document
+||178.175.31.252$document
 ||178.175.31.6$document
+||178.175.31.99$document
+||178.175.32.14$document
 ||178.175.32.197$document
 ||178.175.32.198$document
 ||178.175.32.2$document
@@ -1771,36 +1740,38 @@
 ||178.175.32.211$document
 ||178.175.32.229$document
 ||178.175.32.243$document
+||178.175.32.244$document
 ||178.175.32.89$document
-||178.175.32.95$document
 ||178.175.33.112$document
 ||178.175.33.141$document
 ||178.175.33.162$document
 ||178.175.33.173$document
 ||178.175.33.181$document
-||178.175.33.2$document
+||178.175.33.196$document
 ||178.175.33.208$document
+||178.175.33.21$document
 ||178.175.33.215$document
 ||178.175.33.228$document
 ||178.175.33.234$document
+||178.175.33.245$document
 ||178.175.33.26$document
-||178.175.33.28$document
-||178.175.33.63$document
 ||178.175.34.1$document
 ||178.175.34.2$document
 ||178.175.34.200$document
-||178.175.34.243$document
-||178.175.35.144$document
+||178.175.34.53$document
 ||178.175.35.21$document
 ||178.175.35.38$document
 ||178.175.35.83$document
+||178.175.35.91$document
 ||178.175.36.0$document
 ||178.175.36.127$document
 ||178.175.36.129$document
+||178.175.36.184$document
 ||178.175.36.218$document
 ||178.175.36.231$document
 ||178.175.36.245$document
 ||178.175.36.33$document
+||178.175.36.5$document
 ||178.175.37.107$document
 ||178.175.37.135$document
 ||178.175.37.153$document
@@ -1809,25 +1780,26 @@
 ||178.175.37.38$document
 ||178.175.37.56$document
 ||178.175.37.6$document
+||178.175.37.71$document
 ||178.175.37.81$document
 ||178.175.37.83$document
 ||178.175.38.1$document
 ||178.175.38.132$document
-||178.175.38.141$document
 ||178.175.38.165$document
-||178.175.38.191$document
-||178.175.38.28$document
 ||178.175.38.98$document
+||178.175.39.110$document
+||178.175.39.129$document
 ||178.175.39.158$document
 ||178.175.39.245$document
 ||178.175.39.57$document
+||178.175.39.63$document
 ||178.175.4.144$document
+||178.175.4.192$document
 ||178.175.4.219$document
-||178.175.4.222$document
 ||178.175.4.231$document
+||178.175.4.233$document
 ||178.175.4.95$document
 ||178.175.40.155$document
-||178.175.40.166$document
 ||178.175.40.226$document
 ||178.175.40.228$document
 ||178.175.40.41$document
@@ -1837,12 +1809,14 @@
 ||178.175.41.203$document
 ||178.175.41.34$document
 ||178.175.42.171$document
+||178.175.42.228$document
+||178.175.42.240$document
+||178.175.42.25$document
 ||178.175.43.1$document
 ||178.175.43.106$document
 ||178.175.43.121$document
 ||178.175.43.138$document
 ||178.175.43.147$document
-||178.175.43.217$document
 ||178.175.43.30$document
 ||178.175.43.33$document
 ||178.175.43.69$document
@@ -1850,7 +1824,6 @@
 ||178.175.44.134$document
 ||178.175.44.143$document
 ||178.175.44.155$document
-||178.175.44.186$document
 ||178.175.44.197$document
 ||178.175.44.217$document
 ||178.175.44.22$document
@@ -1859,11 +1832,9 @@
 ||178.175.44.89$document
 ||178.175.44.90$document
 ||178.175.44.95$document
-||178.175.44.96$document
-||178.175.45.191$document
 ||178.175.45.205$document
+||178.175.45.25$document
 ||178.175.45.6$document
-||178.175.45.87$document
 ||178.175.46.119$document
 ||178.175.46.187$document
 ||178.175.46.224$document
@@ -1871,28 +1842,34 @@
 ||178.175.47.11$document
 ||178.175.47.141$document
 ||178.175.47.151$document
+||178.175.47.16$document
 ||178.175.47.168$document
 ||178.175.47.245$document
 ||178.175.48.110$document
 ||178.175.48.168$document
 ||178.175.49.139$document
+||178.175.49.214$document
 ||178.175.49.247$document
+||178.175.49.252$document
 ||178.175.49.3$document
 ||178.175.5.17$document
 ||178.175.5.51$document
+||178.175.5.79$document
 ||178.175.50.131$document
+||178.175.50.168$document
 ||178.175.50.177$document
 ||178.175.50.22$document
 ||178.175.50.236$document
 ||178.175.50.237$document
-||178.175.50.27$document
+||178.175.50.32$document
 ||178.175.51.137$document
 ||178.175.51.160$document
 ||178.175.51.202$document
 ||178.175.51.66$document
+||178.175.52.146$document
 ||178.175.52.161$document
+||178.175.52.21$document
 ||178.175.52.212$document
-||178.175.52.71$document
 ||178.175.52.94$document
 ||178.175.53.135$document
 ||178.175.53.151$document
@@ -1903,16 +1880,16 @@
 ||178.175.53.56$document
 ||178.175.53.58$document
 ||178.175.53.79$document
+||178.175.54.15$document
 ||178.175.54.158$document
 ||178.175.54.163$document
+||178.175.54.167$document
 ||178.175.54.205$document
-||178.175.54.214$document
 ||178.175.54.225$document
 ||178.175.54.64$document
 ||178.175.55.103$document
 ||178.175.55.14$document
 ||178.175.55.163$document
-||178.175.55.181$document
 ||178.175.55.25$document
 ||178.175.55.29$document
 ||178.175.55.38$document
@@ -1922,122 +1899,114 @@
 ||178.175.56.103$document
 ||178.175.56.11$document
 ||178.175.56.120$document
-||178.175.56.18$document
-||178.175.56.196$document
 ||178.175.56.24$document
 ||178.175.56.252$document
 ||178.175.56.33$document
 ||178.175.56.37$document
 ||178.175.56.50$document
+||178.175.56.52$document
 ||178.175.56.54$document
 ||178.175.56.72$document
 ||178.175.56.75$document
 ||178.175.57.10$document
 ||178.175.57.141$document
 ||178.175.57.179$document
+||178.175.57.99$document
 ||178.175.58.28$document
-||178.175.58.29$document
 ||178.175.58.74$document
 ||178.175.58.79$document
 ||178.175.59.161$document
+||178.175.59.241$document
 ||178.175.59.33$document
-||178.175.59.47$document
 ||178.175.59.54$document
 ||178.175.6.134$document
 ||178.175.6.157$document
 ||178.175.6.189$document
+||178.175.6.89$document
 ||178.175.60.209$document
 ||178.175.60.212$document
-||178.175.60.251$document
+||178.175.60.76$document
 ||178.175.61.156$document
 ||178.175.61.163$document
 ||178.175.61.17$document
 ||178.175.61.171$document
+||178.175.61.178$document
 ||178.175.61.219$document
 ||178.175.61.237$document
+||178.175.61.95$document
 ||178.175.62.111$document
 ||178.175.62.115$document
+||178.175.62.141$document
 ||178.175.62.166$document
 ||178.175.62.168$document
-||178.175.62.208$document
 ||178.175.62.42$document
 ||178.175.62.43$document
 ||178.175.62.70$document
 ||178.175.62.8$document
 ||178.175.62.84$document
-||178.175.63.167$document
+||178.175.63.192$document
 ||178.175.63.21$document
-||178.175.63.73$document
+||178.175.63.230$document
+||178.175.63.78$document
 ||178.175.63.96$document
 ||178.175.64.12$document
+||178.175.64.155$document
 ||178.175.64.156$document
 ||178.175.64.158$document
 ||178.175.64.187$document
+||178.175.64.190$document
 ||178.175.64.22$document
-||178.175.64.30$document
-||178.175.64.50$document
-||178.175.65.115$document
+||178.175.64.231$document
+||178.175.65.19$document
 ||178.175.65.202$document
 ||178.175.65.236$document
-||178.175.66.105$document
-||178.175.66.123$document
 ||178.175.66.186$document
 ||178.175.66.192$document
 ||178.175.66.199$document
 ||178.175.66.211$document
 ||178.175.66.228$document
-||178.175.66.43$document
 ||178.175.66.54$document
 ||178.175.66.93$document
 ||178.175.67.0$document
 ||178.175.67.36$document
 ||178.175.67.51$document
-||178.175.67.8$document
+||178.175.67.55$document
 ||178.175.67.81$document
 ||178.175.67.83$document
 ||178.175.67.89$document
-||178.175.68.109$document
+||178.175.68.116$document
 ||178.175.68.44$document
 ||178.175.68.66$document
 ||178.175.68.85$document
 ||178.175.69.111$document
-||178.175.69.112$document
 ||178.175.69.119$document
 ||178.175.69.128$document
 ||178.175.69.18$document
-||178.175.69.4$document
-||178.175.69.96$document
 ||178.175.7.6$document
 ||178.175.7.60$document
 ||178.175.7.71$document
+||178.175.70.10$document
 ||178.175.70.109$document
-||178.175.70.12$document
-||178.175.70.147$document
-||178.175.70.18$document
 ||178.175.70.196$document
 ||178.175.70.218$document
 ||178.175.70.246$document
-||178.175.70.38$document
 ||178.175.70.5$document
 ||178.175.70.50$document
-||178.175.70.64$document
 ||178.175.70.71$document
 ||178.175.70.83$document
-||178.175.71.202$document
+||178.175.70.93$document
+||178.175.71.160$document
 ||178.175.71.45$document
-||178.175.71.55$document
 ||178.175.71.84$document
 ||178.175.72.108$document
-||178.175.72.13$document
 ||178.175.72.222$document
 ||178.175.72.30$document
 ||178.175.72.37$document
-||178.175.73.127$document
-||178.175.73.77$document
+||178.175.72.47$document
 ||178.175.73.96$document
 ||178.175.74.182$document
+||178.175.74.205$document
 ||178.175.74.48$document
-||178.175.75.130$document
 ||178.175.75.181$document
 ||178.175.75.19$document
 ||178.175.75.84$document
@@ -2049,97 +2018,101 @@
 ||178.175.76.217$document
 ||178.175.76.83$document
 ||178.175.76.9$document
+||178.175.77.248$document
+||178.175.77.34$document
 ||178.175.77.46$document
 ||178.175.77.47$document
-||178.175.77.71$document
-||178.175.78.118$document
 ||178.175.78.198$document
 ||178.175.78.243$document
-||178.175.78.46$document
+||178.175.78.57$document
 ||178.175.78.97$document
 ||178.175.79.17$document
 ||178.175.79.244$document
 ||178.175.79.247$document
 ||178.175.79.69$document
 ||178.175.8.100$document
+||178.175.8.227$document
+||178.175.8.64$document
 ||178.175.80.100$document
-||178.175.80.114$document
 ||178.175.80.129$document
-||178.175.80.17$document
+||178.175.80.197$document
 ||178.175.80.20$document
-||178.175.80.35$document
 ||178.175.80.41$document
 ||178.175.80.61$document
+||178.175.80.68$document
 ||178.175.80.79$document
 ||178.175.80.86$document
-||178.175.81.17$document
+||178.175.80.89$document
+||178.175.81.19$document
 ||178.175.81.192$document
 ||178.175.81.226$document
 ||178.175.81.232$document
 ||178.175.81.244$document
 ||178.175.81.253$document
-||178.175.81.50$document
-||178.175.82.137$document
-||178.175.82.32$document
+||178.175.82.23$document
+||178.175.82.73$document
+||178.175.83.144$document
 ||178.175.83.2$document
+||178.175.83.20$document
 ||178.175.83.247$document
 ||178.175.84.102$document
-||178.175.84.109$document
 ||178.175.84.159$document
+||178.175.84.17$document
 ||178.175.84.215$document
+||178.175.84.28$document
 ||178.175.84.42$document
 ||178.175.85.153$document
 ||178.175.85.183$document
 ||178.175.85.23$document
-||178.175.85.55$document
+||178.175.85.230$document
 ||178.175.85.57$document
 ||178.175.86.119$document
+||178.175.86.122$document
 ||178.175.86.36$document
 ||178.175.86.59$document
 ||178.175.87.126$document
 ||178.175.87.139$document
 ||178.175.87.144$document
 ||178.175.87.253$document
-||178.175.87.68$document
-||178.175.88.127$document
-||178.175.88.140$document
+||178.175.88.160$document
 ||178.175.88.166$document
 ||178.175.88.181$document
 ||178.175.88.182$document
+||178.175.88.24$document
+||178.175.88.248$document
 ||178.175.88.69$document
 ||178.175.89.157$document
 ||178.175.89.169$document
-||178.175.89.24$document
+||178.175.89.30$document
 ||178.175.9.125$document
 ||178.175.9.139$document
 ||178.175.9.175$document
 ||178.175.9.179$document
-||178.175.9.183$document
 ||178.175.9.198$document
 ||178.175.9.210$document
 ||178.175.9.215$document
 ||178.175.9.225$document
+||178.175.9.64$document
 ||178.175.9.84$document
 ||178.175.9.95$document
 ||178.175.90.122$document
 ||178.175.90.167$document
 ||178.175.90.172$document
+||178.175.90.185$document
 ||178.175.90.21$document
-||178.175.90.212$document
-||178.175.90.244$document
 ||178.175.90.4$document
 ||178.175.90.74$document
+||178.175.90.81$document
+||178.175.90.90$document
 ||178.175.91.108$document
 ||178.175.91.13$document
 ||178.175.91.15$document
 ||178.175.91.244$document
 ||178.175.91.253$document
-||178.175.91.40$document
 ||178.175.91.96$document
-||178.175.92.128$document
 ||178.175.92.132$document
-||178.175.92.141$document
 ||178.175.92.186$document
+||178.175.92.200$document
 ||178.175.92.215$document
 ||178.175.92.231$document
 ||178.175.92.253$document
@@ -2148,37 +2121,32 @@
 ||178.175.93.143$document
 ||178.175.93.150$document
 ||178.175.93.159$document
-||178.175.93.34$document
-||178.175.93.45$document
+||178.175.93.199$document
+||178.175.93.44$document
 ||178.175.93.62$document
-||178.175.93.93$document
 ||178.175.94.195$document
 ||178.175.94.200$document
+||178.175.94.27$document
 ||178.175.94.40$document
 ||178.175.94.55$document
+||178.175.95.116$document
 ||178.175.95.141$document
+||178.175.95.163$document
 ||178.175.95.17$document
 ||178.175.95.227$document
-||178.175.95.237$document
 ||178.175.95.4$document
 ||178.175.95.56$document
-||178.175.96.169$document
-||178.175.96.192$document
-||178.175.97.1$document
+||178.175.96.81$document
 ||178.175.97.128$document
 ||178.175.97.135$document
-||178.175.97.143$document
-||178.175.97.78$document
+||178.175.98.216$document
 ||178.175.98.228$document
 ||178.175.98.254$document
 ||178.175.98.29$document
-||178.175.98.36$document
+||178.175.98.44$document
 ||178.175.98.68$document
 ||178.175.99.123$document
 ||178.175.99.130$document
-||178.175.99.22$document
-||178.175.99.45$document
-||178.175.99.88$document
 ||178.175.99.91$document
 ||178.19.183.14$document
 ||178.205.101.33$document
@@ -2193,6 +2161,7 @@
 ||178.95.136.35$document
 ||179.159.58.134$document
 ||179.4.187.39$document
+||179.42.107.139$document
 ||179.43.157.173$document
 ||179.60.84.7$document
 ||179.99.210.161$document
@@ -2205,7 +2174,6 @@
 ||180.125.44.194$document
 ||180.157.66.204$document
 ||180.175.236.209$document
-||180.175.93.52$document
 ||180.176.105.41$document
 ||180.176.110.243$document
 ||180.176.165.230$document
@@ -2216,6 +2184,7 @@
 ||180.177.242.73$document
 ||180.218.5.171$document
 ||180.248.80.38$document
+||180.253.99.109$document
 ||180.66.111.36$document
 ||180.66.53.93$document
 ||180.94.170.166$document
@@ -2226,123 +2195,131 @@
 ||181.193.107.10$document
 ||181.199.170.222$document
 ||181.199.170.230$document
-||181.199.170.240$document
 ||181.210.45.42$document
 ||181.215.47.82$document
 ||181.224.242.131$document
 ||181.49.236.4$document
 ||181.49.59.162$document
+||182.112.28.118$document
+||182.112.34.220$document
 ||182.112.43.249$document
 ||182.112.52.131$document
+||182.113.238.197$document
+||182.113.29.28$document
+||182.114.105.40$document
 ||182.114.111.64$document
-||182.114.24.20$document
-||182.114.49.104$document
 ||182.114.64.27$document
+||182.114.76.42$document
 ||182.114.79.103$document
 ||182.114.83.88$document
 ||182.114.92.90$document
 ||182.114.93.96$document
-||182.116.101.82$document
-||182.116.103.234$document
 ||182.116.104.106$document
-||182.116.108.180$document
+||182.116.105.208$document
 ||182.116.108.244$document
+||182.116.116.70$document
 ||182.116.118.250$document
+||182.116.119.66$document
+||182.116.36.175$document
 ||182.116.60.73$document
 ||182.116.61.252$document
 ||182.116.80.107$document
 ||182.116.94.196$document
 ||182.116.99.150$document
+||182.117.13.57$document
 ||182.117.15.172$document
 ||182.117.25.120$document
 ||182.117.26.235$document
 ||182.117.29.220$document
 ||182.117.39.51$document
 ||182.117.43.27$document
+||182.117.49.127$document
 ||182.118.146.181$document
+||182.118.166.128$document
 ||182.119.100.135$document
 ||182.119.109.173$document
 ||182.119.118.218$document
 ||182.119.14.252$document
+||182.119.15.78$document
 ||182.119.166.208$document
-||182.119.176.209$document
+||182.119.166.76$document
+||182.119.179.193$document
+||182.119.197.123$document
+||182.119.202.180$document
+||182.119.21.68$document
 ||182.119.211.69$document
 ||182.119.214.120$document
 ||182.119.221.141$document
-||182.119.225.30$document
+||182.119.226.84$document
 ||182.119.255.115$document
 ||182.119.7.54$document
+||182.119.89.107$document
 ||182.120.16.22$document
 ||182.120.16.46$document
-||182.120.33.117$document
 ||182.120.37.251$document
 ||182.120.43.0$document
-||182.121.11.43$document
 ||182.121.129.163$document
-||182.121.130.67$document
-||182.121.133.46$document
 ||182.121.134.70$document
-||182.121.158.141$document
+||182.121.15.223$document
+||182.121.157.35$document
 ||182.121.205.201$document
 ||182.121.205.237$document
 ||182.121.207.195$document
-||182.121.40.234$document
-||182.121.50.111$document
+||182.121.254.147$document
+||182.121.55.106$document
 ||182.121.66.189$document
 ||182.121.9.117$document
 ||182.121.94.13$document
-||182.122.181.105$document
 ||182.122.202.18$document
 ||182.123.203.21$document
 ||182.123.211.239$document
+||182.123.241.195$document
 ||182.124.123.107$document
 ||182.124.177.48$document
 ||182.124.19.87$document
+||182.124.201.207$document
 ||182.124.88.122$document
 ||182.126.113.127$document
-||182.126.120.66$document
+||182.126.123.19$document
 ||182.126.126.203$document
 ||182.126.127.254$document
-||182.126.181.121$document
-||182.126.52.233$document
 ||182.126.67.24$document
-||182.126.80.108$document
 ||182.126.83.79$document
 ||182.126.88.138$document
+||182.127.0.16$document
 ||182.127.103.79$document
 ||182.127.104.235$document
-||182.127.110.147$document
+||182.127.106.43$document
 ||182.127.152.3$document
 ||182.127.155.157$document
-||182.127.209.26$document
 ||182.127.221.243$document
+||182.127.93.38$document
 ||182.160.98.250$document
 ||182.172.36.164$document
 ||182.233.0.252$document
 ||182.235.252.31$document
 ||182.53.197.62$document
-||182.58.219.8$document
+||182.56.193.251$document
+||182.59.235.150$document
 ||183.105.104.83$document
 ||183.105.225.154$document
 ||183.109.169.45$document
 ||183.11.238.228$document
 ||183.136.252.233$document
-||183.150.138.131$document
 ||183.150.244.122$document
 ||183.16.208.30$document
 ||183.185.112.19$document
+||183.185.162.225$document
 ||183.187.163.176$document
 ||183.188.151.225$document
 ||183.188.180.116$document
 ||183.188.188.186$document
 ||183.188.228.38$document
+||183.188.93.116$document
 ||183.83.105.21$document
-||183.83.125.235$document
 ||183.83.127.89$document
 ||183.83.26.115$document
-||183.83.99.87$document
 ||183.92.195.140$document
-||183.95.147.102$document
 ||183.97.22.14$document
 ||184.164.185.41$document
 ||184.175.115.10$document
@@ -2384,14 +2361,11 @@
 ||186.225.120.173$document
 ||186.232.44.86$document
 ||186.28.60.184$document
-||186.33.112.218$document
-||186.33.112.228$document
-||186.33.112.66$document
-||186.33.113.241$document
 ||186.33.113.77$document
 ||186.4.125.48$document
 ||186.73.188.132$document
 ||187.12.10.98$document
+||187.188.124.229$document
 ||187.212.200.162$document
 ||187.233.208.103$document
 ||187.33.71.68$document
@@ -2399,12 +2373,12 @@
 ||188.10.231.246$document
 ||188.113.102.18$document
 ||188.113.81.17$document
+||188.119.45.194$document
 ||188.13.179.87$document
 ||188.138.200.32$document
 ||188.152.41.141$document
 ||188.169.178.50$document
-||188.169.199.59$document
-||188.169.36.163$document
+||188.169.179.151$document
 ||188.169.45.140$document
 ||188.242.167.159$document
 ||188.242.242.144$document
@@ -2438,6 +2412,7 @@
 ||190.216.140.123$document
 ||190.35.225.36$document
 ||190.65.206.162$document
+||190.73.12.149$document
 ||190.92.4.231$document
 ||190.98.37.135$document
 ||190.98.37.200$document
@@ -2445,7 +2420,6 @@
 ||191.255.248.220$document
 ||192.210.175.130$document
 ||192.210.241.200$document
-||192.227.185.106$document
 ||192.227.209.27$document
 ||192.227.220.55$document
 ||192.227.228.67$document
@@ -2454,6 +2428,7 @@
 ||192.99.240.77$document
 ||193.142.146.25$document
 ||193.228.135.144$document
+||193.38.55.9$document
 ||193.91.131.237$document
 ||194.147.142.230$document
 ||194.15.36.167$document
@@ -2470,7 +2445,6 @@
 ||197.50.27.115$document
 ||198.23.133.218$document
 ||198.23.207.121$document
-||198.23.213.57$document
 ||198.23.251.105$document
 ||198.251.72.110$document
 ||198.46.201.76$document
@@ -2482,7 +2456,9 @@
 ||2.45.111.158$document
 ||2.45.4.24$document
 ||2.55.125.182$document
+||2.58.69.44$document
 ||2.83.152.16$document
+||20.185.42.197$document
 ||20.dbstrony.pl$document
 ||200.105.167.98$document
 ||200.111.189.70$document
@@ -2495,17 +2471,16 @@
 ||201.187.102.73$document
 ||201.200.254.86$document
 ||201.203.221.20$document
+||201.203.27.37$document
 ||201.215.84.97$document
 ||201.218.97.142$document
 ||202.107.233.41$document
+||202.150.176.100$document
 ||202.164.153.80$document
 ||202.166.217.54$document
 ||202.169.234.22$document
 ||202.169.234.37$document
-||202.169.234.47$document
 ||202.169.234.52$document
-||202.169.234.55$document
-||202.169.234.9$document
 ||202.29.95.12$document
 ||202.4.124.58$document
 ||202.51.176.114$document
@@ -2513,12 +2488,10 @@
 ||202.74.236.9$document
 ||203.109.201.243$document
 ||203.130.69.205$document
-||203.170.115.82$document
 ||203.189.156.107$document
 ||203.204.232.18$document
 ||203.229.21.56$document
 ||203.236.190.28$document
-||203.238.86.202$document
 ||203.70.166.107$document
 ||203.77.80.159$document
 ||203.80.119.166$document
@@ -2528,7 +2501,6 @@
 ||203.93.6.28$document
 ||204.195.116.171$document
 ||205.185.115.74$document
-||205.185.123.217$document
 ||206.248.137.132$document
 ||206.47.41.166$document
 ||207.5.32.6$document
@@ -2540,6 +2512,7 @@
 ||210.124.149.19$document
 ||210.216.152.122$document
 ||210.216.153.142$document
+||210.57.234.131$document
 ||210.57.234.93$document
 ||210.57.237.70$document
 ||210.57.245.109$document
@@ -2561,6 +2534,7 @@
 ||211.247.113.49$document
 ||211.247.5.96$document
 ||211.36.174.137$document
+||211.47.102.51$document
 ||211.51.174.149$document
 ||212.122.86.105$document
 ||212.143.227.22$document
@@ -2575,11 +2549,11 @@
 ||213.149.190.193$document
 ||213.163.104.12$document
 ||213.163.104.138$document
-||213.163.104.160$document
+||213.163.104.7$document
 ||213.163.104.99$document
+||213.163.113.100$document
 ||213.163.113.135$document
 ||213.163.113.225$document
-||213.163.113.23$document
 ||213.163.113.237$document
 ||213.163.113.51$document
 ||213.163.114.155$document
@@ -2591,7 +2565,9 @@
 ||213.163.115.33$document
 ||213.163.115.71$document
 ||213.163.116.132$document
+||213.163.116.181$document
 ||213.163.116.192$document
+||213.163.116.197$document
 ||213.163.116.203$document
 ||213.163.116.33$document
 ||213.163.116.85$document
@@ -2600,21 +2576,21 @@
 ||213.163.117.97$document
 ||213.163.118.129$document
 ||213.163.118.144$document
+||213.163.118.236$document
 ||213.163.118.238$document
-||213.163.118.65$document
 ||213.163.119.24$document
 ||213.163.119.240$document
-||213.163.126.104$document
 ||213.163.126.20$document
 ||213.163.126.243$document
+||213.163.126.249$document
 ||213.163.126.60$document
 ||213.163.126.7$document
 ||213.163.126.84$document
 ||213.163.127.204$document
 ||213.163.127.217$document
+||213.163.127.242$document
 ||213.163.127.46$document
 ||213.189.178.163$document
-||213.226.140.23$document
 ||213.240.218.15$document
 ||213.249.156.189$document
 ||213.27.8.6$document
@@ -2642,6 +2618,7 @@
 ||218.35.81.81$document
 ||218.48.135.50$document
 ||218.56.93.129$document
+||218.57.109.48$document
 ||218.57.53.55$document
 ||218.59.116.203$document
 ||218.72.198.15$document
@@ -2649,33 +2626,37 @@
 ||218.93.102.63$document
 ||218.93.102.75$document
 ||219.154.103.40$document
-||219.154.114.132$document
 ||219.154.114.45$document
 ||219.154.115.250$document
+||219.154.116.168$document
 ||219.154.126.205$document
+||219.154.142.35$document
+||219.154.143.132$document
 ||219.154.147.58$document
 ||219.154.148.116$document
 ||219.154.173.163$document
+||219.154.178.138$document
+||219.154.41.36$document
 ||219.155.102.14$document
+||219.155.11.252$document
 ||219.155.113.58$document
 ||219.155.14.17$document
-||219.155.170.22$document
+||219.155.209.253$document
 ||219.155.24.246$document
 ||219.155.243.184$document
 ||219.155.26.204$document
-||219.155.26.37$document
 ||219.155.29.165$document
 ||219.155.31.15$document
 ||219.155.31.67$document
-||219.155.42.216$document
+||219.155.86.156$document
 ||219.155.98.64$document
 ||219.156.131.116$document
-||219.156.167.103$document
 ||219.156.17.217$document
+||219.156.176.153$document
 ||219.156.23.29$document
 ||219.156.60.224$document
+||219.156.65.47$document
 ||219.156.88.219$document
-||219.156.9.32$document
 ||219.157.11.39$document
 ||219.157.146.200$document
 ||219.157.147.87$document
@@ -2683,8 +2664,8 @@
 ||219.157.178.201$document
 ||219.157.178.210$document
 ||219.157.183.29$document
+||219.157.214.235$document
 ||219.157.223.241$document
-||219.157.223.245$document
 ||219.157.42.228$document
 ||219.157.67.171$document
 ||219.241.6.180$document
@@ -2692,6 +2673,7 @@
 ||219.68.1.84$document
 ||219.68.163.7$document
 ||219.68.171.144$document
+||219.68.245.63$document
 ||219.68.251.32$document
 ||219.68.5.140$document
 ||219.69.71.186$document
@@ -2703,21 +2685,21 @@
 ||220.133.30.200$document
 ||220.200.22.163$document
 ||220.71.239.115$document
+||220.90.159.188$document
 ||221.1.162.82$document
 ||221.124.78.15$document
-||221.14.11.33$document
 ||221.14.122.127$document
 ||221.14.165.237$document
+||221.14.185.105$document
 ||221.14.47.162$document
-||221.14.58.5$document
+||221.14.47.189$document
+||221.14.57.175$document
 ||221.15.108.55$document
+||221.15.112.103$document
 ||221.15.125.190$document
-||221.15.127.124$document
-||221.15.147.220$document
-||221.15.21.133$document
-||221.15.212.123$document
+||221.15.155.186$document
+||221.15.190.2$document
 ||221.15.234.159$document
-||221.15.236.211$document
 ||221.15.237.107$document
 ||221.15.250.213$document
 ||221.15.253.236$document
@@ -2731,8 +2713,10 @@
 ||221.196.12.96$document
 ||221.198.167.192$document
 ||221.2.190.22$document
+||221.202.232.230$document
 ||221.214.130.147$document
 ||221.214.224.184$document
+||221.214.251.109$document
 ||221.215.116.167$document
 ||221.215.172.207$document
 ||221.215.184.31$document
@@ -2757,52 +2741,50 @@
 ||222.135.219.29$document
 ||222.135.26.161$document
 ||222.135.67.115$document
-||222.136.49.252$document
 ||222.136.53.227$document
+||222.136.77.190$document
 ||222.137.101.251$document
 ||222.137.101.33$document
 ||222.137.121.127$document
 ||222.137.137.5$document
 ||222.137.138.252$document
 ||222.137.148.192$document
-||222.137.160.202$document
+||222.137.161.88$document
 ||222.137.172.250$document
 ||222.137.198.247$document
+||222.137.220.215$document
+||222.137.237.203$document
 ||222.137.239.124$document
 ||222.137.49.36$document
-||222.137.5.150$document
-||222.137.57.234$document
+||222.137.53.193$document
 ||222.137.72.146$document
-||222.137.85.26$document
 ||222.137.96.9$document
+||222.138.118.192$document
 ||222.138.143.84$document
 ||222.138.151.100$document
 ||222.138.189.138$document
 ||222.138.201.241$document
-||222.138.23.254$document
+||222.138.213.235$document
+||222.138.226.142$document
 ||222.138.96.79$document
-||222.139.16.229$document
-||222.140.129.239$document
+||222.139.106.55$document
 ||222.140.162.140$document
 ||222.140.163.112$document
 ||222.140.17.245$document
+||222.140.179.142$document
+||222.140.208.18$document
 ||222.140.209.222$document
-||222.140.254.11$document
 ||222.140.39.66$document
+||222.141.101.39$document
 ||222.141.120.26$document
 ||222.141.13.77$document
-||222.141.44.36$document
-||222.141.73.249$document
+||222.141.40.69$document
+||222.141.46.119$document
 ||222.141.9.0$document
-||222.142.162.164$document
 ||222.142.192.66$document
 ||222.142.209.231$document
-||222.142.209.7$document
-||222.142.245.207$document
 ||222.179.215.189$document
 ||222.185.116.233$document
-||222.186.20.19$document
-||222.187.184.136$document
 ||222.187.9.178$document
 ||222.211.72.66$document
 ||222.214.54.208$document
@@ -2811,7 +2793,7 @@
 ||222.238.230.7$document
 ||222.239.83.232$document
 ||222.248.64.253$document
-||222.83.150.240$document
+||222.81.156.229$document
 ||222.92.9.126$document
 ||222.99.171.192$document
 ||223.166.117.210$document
@@ -2856,7 +2838,7 @@
 ||27.141.218.17$document
 ||27.147.29.52$document
 ||27.147.40.128$document
-||27.153.207.1$document
+||27.153.142.115$document
 ||27.184.244.14$document
 ||27.184.54.199$document
 ||27.187.248.22$document
@@ -2864,7 +2846,6 @@
 ||27.193.196.190$document
 ||27.193.217.210$document
 ||27.194.149.142$document
-||27.194.158.229$document
 ||27.194.192.66$document
 ||27.194.210.20$document
 ||27.197.17.88$document
@@ -2890,13 +2871,11 @@
 ||27.203.165.138$document
 ||27.203.175.203$document
 ||27.203.185.42$document
-||27.203.185.48$document
 ||27.203.213.79$document
 ||27.203.246.96$document
 ||27.203.255.42$document
 ||27.203.28.115$document
 ||27.203.4.188$document
-||27.203.54.217$document
 ||27.203.68.144$document
 ||27.203.87.75$document
 ||27.203.94.134$document
@@ -2920,11 +2899,10 @@
 ||27.208.164.18$document
 ||27.208.166.13$document
 ||27.208.201.212$document
-||27.208.214.139$document
 ||27.208.247.130$document
 ||27.208.25.59$document
 ||27.208.34.2$document
-||27.208.46.167$document
+||27.208.70.115$document
 ||27.208.92.64$document
 ||27.209.160.222$document
 ||27.209.231.15$document
@@ -2940,6 +2918,7 @@
 ||27.213.109.105$document
 ||27.213.109.58$document
 ||27.213.145.221$document
+||27.213.166.50$document
 ||27.213.167.175$document
 ||27.213.175.208$document
 ||27.213.220.5$document
@@ -2952,6 +2931,7 @@
 ||27.215.212.209$document
 ||27.215.212.80$document
 ||27.215.253.149$document
+||27.215.27.143$document
 ||27.215.34.242$document
 ||27.215.38.119$document
 ||27.215.38.166$document
@@ -2966,7 +2946,6 @@
 ||27.216.227.95$document
 ||27.216.234.98$document
 ||27.216.46.85$document
-||27.216.58.120$document
 ||27.216.95.56$document
 ||27.217.120.226$document
 ||27.217.133.53$document
@@ -3001,23 +2980,30 @@
 ||27.35.154.13$document
 ||27.35.212.124$document
 ||27.35.58.5$document
-||27.41.143.46$document
+||27.41.159.28$document
+||27.41.37.155$document
+||27.41.9.105$document
 ||27.41.9.44$document
+||27.41.97.36$document
+||27.43.108.78$document
+||27.43.111.161$document
+||27.43.117.66$document
+||27.46.23.10$document
 ||27.46.44.130$document
-||27.46.44.161$document
+||27.46.44.153$document
+||27.46.45.86$document
 ||27.46.46.100$document
 ||27.46.46.252$document
-||27.5.23.215$document
-||27.5.34.254$document
-||27.5.46.18$document
-||27.6.195.65$document
-||27.6.240.125$document
-||27.6.242.65$document
+||27.5.23.69$document
+||27.5.47.16$document
+||27.6.240.171$document
+||27.6.38.96$document
 ||31.0.98.131$document
 ||31.11.51.57$document
 ||31.13.23.180$document
 ||31.154.234.3$document
 ||31.163.191.11$document
+||31.168.124.130$document
 ||31.168.179.83$document
 ||31.168.184.59$document
 ||31.168.191.243$document
@@ -3038,11 +3024,13 @@
 ||31.30.119.23$document
 ||32.208.157.193$document
 ||32.218.180.9$document
+||32792.prolocksmithwinterpark.com$document
 ||35.184.169.169$document
 ||36.108.231.218$document
 ||36.250.203.246$document
 ||36.251.157.225$document
 ||36.251.18.18$document
+||36.251.18.63$document
 ||36.251.19.88$document
 ||36.251.51.244$document
 ||36.255.90.219$document
@@ -3050,10 +3038,13 @@
 ||36.33.160.167$document
 ||36.34.150.236$document
 ||36.36.243.67$document
+||36.43.11.16$document
 ||36.66.105.159$document
 ||36.66.111.203$document
 ||36.66.133.125$document
 ||36.66.139.36$document
+||36.67.152.161$document
+||36.81.23.38$document
 ||36.89.18.133$document
 ||36.96.187.93$document
 ||360.lcy2zzx.pw$document
@@ -3108,9 +3099,11 @@
 ||39.77.150.203$document
 ||39.77.197.81$document
 ||39.77.209.209$document
+||39.77.48.213$document
 ||39.77.94.189$document
 ||39.77.95.50$document
 ||39.79.146.67$document
+||39.79.163.188$document
 ||39.79.166.31$document
 ||39.79.218.46$document
 ||39.79.62.43$document
@@ -3122,6 +3115,7 @@
 ||39.80.205.255$document
 ||39.80.24.54$document
 ||39.80.36.151$document
+||39.80.37.182$document
 ||39.81.251.0$document
 ||39.81.27.15$document
 ||39.81.29.231$document
@@ -3141,17 +3135,14 @@
 ||39.86.216.144$document
 ||39.86.234.187$document
 ||39.86.248.91$document
-||39.86.60.98$document
 ||39.86.66.24$document
 ||39.86.73.100$document
-||39.86.78.228$document
 ||39.87.63.58$document
 ||39.87.90.210$document
 ||39.87.93.109$document
 ||39.88.141.172$document
 ||39.88.155.96$document
 ||39.88.233.131$document
-||39.88.41.73$document
 ||39.88.67.238$document
 ||39.88.72.9$document
 ||39.89.146.198$document
@@ -3166,66 +3157,84 @@
 ||41.219.185.171$document
 ||41.230.31.58$document
 ||41.72.203.82$document
+||41.86.18.133$document
 ||41.86.18.148$document
-||41.86.18.200$document
+||41.86.18.157$document
+||41.86.18.164$document
+||41.86.18.165$document
 ||41.86.18.71$document
-||41.86.21.23$document
-||41.86.5.233$document
-||41.86.5.236$document
+||41.86.19.206$document
+||41.86.19.80$document
+||41.86.21.38$document
+||41.86.21.44$document
+||41.86.21.62$document
+||41.86.5.142$document
+||41.86.5.198$document
+||41.86.5.206$document
 ||42.176.112.72$document
 ||42.177.164.171$document
 ||42.179.162.208$document
 ||42.179.163.177$document
 ||42.202.101.147$document
+||42.224.122.183$document
 ||42.224.122.39$document
-||42.224.169.111$document
 ||42.224.171.104$document
 ||42.224.172.125$document
-||42.224.18.165$document
+||42.224.188.223$document
+||42.224.189.79$document
 ||42.224.19.55$document
 ||42.224.220.37$document
 ||42.224.233.247$document
 ||42.224.234.23$document
 ||42.224.245.91$document
 ||42.224.249.160$document
+||42.224.249.188$document
+||42.224.3.187$document
 ||42.224.36.220$document
-||42.224.56.81$document
+||42.224.52.81$document
+||42.224.68.72$document
 ||42.224.69.11$document
 ||42.224.70.213$document
 ||42.225.120.122$document
 ||42.225.205.191$document
 ||42.225.241.5$document
-||42.226.89.25$document
 ||42.227.194.95$document
 ||42.227.196.123$document
 ||42.227.66.88$document
-||42.228.39.232$document
+||42.228.196.68$document
 ||42.228.40.56$document
 ||42.228.60.114$document
 ||42.228.67.135$document
 ||42.228.68.118$document
 ||42.228.70.126$document
 ||42.228.70.231$document
-||42.228.84.206$document
-||42.230.153.183$document
-||42.230.219.175$document
+||42.230.218.252$document
 ||42.230.25.164$document
+||42.230.46.55$document
 ||42.230.48.162$document
-||42.231.95.195$document
+||42.231.95.247$document
 ||42.232.102.163$document
-||42.232.23.76$document
+||42.232.46.169$document
+||42.233.159.21$document
 ||42.233.78.236$document
-||42.233.90.183$document
+||42.234.247.41$document
 ||42.234.85.184$document
 ||42.235.23.163$document
-||42.235.3.187$document
-||42.235.82.129$document
-||42.235.86.211$document
+||42.235.67.162$document
+||42.235.82.112$document
+||42.235.87.100$document
 ||42.235.90.32$document
 ||42.235.95.254$document
 ||42.236.148.201$document
+||42.237.142.157$document
+||42.237.24.151$document
 ||42.237.252.159$document
+||42.237.60.73$document
+||42.238.228.0$document
+||42.239.155.147$document
+||42.239.202.121$document
 ||42.239.21.27$document
+||42.239.218.137$document
 ||42.239.98.70$document
 ||42.242.200.90$document
 ||42.56.15.227$document
@@ -3234,6 +3243,7 @@
 ||42.87.29.162$document
 ||43.230.156.44$document
 ||43.241.106.183$document
+||43.252.8.94$document
 ||45.133.1.137$document
 ||45.133.1.139$document
 ||45.133.1.242$document
@@ -3248,10 +3258,13 @@
 ||45.144.225.65$document
 ||45.148.10.47$document
 ||45.148.10.94$document
+||45.165.215.19$document
 ||45.176.108.116$document
+||45.176.108.164$document
 ||45.176.108.22$document
 ||45.176.108.248$document
 ||45.176.110.99$document
+||45.176.111.119$document
 ||45.176.111.154$document
 ||45.176.111.16$document
 ||45.176.111.202$document
@@ -3267,10 +3280,10 @@
 ||45.81.235.31$document
 ||45.9.148.37$document
 ||46.151.155.218$document
+||46.161.185.15$document
 ||46.172.75.231$document
 ||46.175.184.121$document
 ||46.182.173.246$document
-||46.182.173.247$document
 ||46.20.63.218$document
 ||46.21.153.231$document
 ||46.214.27.4$document
@@ -3292,7 +3305,6 @@
 ||49.142.87.36$document
 ||49.143.32.36$document
 ||49.143.43.93$document
-||49.156.35.166$document
 ||49.158.201.200$document
 ||49.159.20.121$document
 ||49.159.21.3$document
@@ -3303,13 +3315,14 @@
 ||49.68.221.252$document
 ||49.68.249.121$document
 ||49.70.15.16$document
+||49.70.95.181$document
 ||5.146.202.18$document
 ||5.181.135.114$document
 ||5.2.70.50$document
+||5.42.37.74$document
 ||5.53.146.179$document
 ||5.8.10.62$document
 ||50.115.174.102$document
-||50.115.174.106$document
 ||50.121.91.255$document
 ||50.252.47.29$document
 ||51.171.146.13$document
@@ -3317,6 +3330,7 @@
 ||54.36.114.136$document
 ||54.36.180.122$document
 ||58.114.246.26$document
+||58.115.108.164$document
 ||58.115.162.92$document
 ||58.115.174.4$document
 ||58.125.191.4$document
@@ -3331,7 +3345,6 @@
 ||58.218.67.253$document
 ||58.22.212.107$document
 ||58.226.129.29$document
-||58.229.194.122$document
 ||58.23.245.24$document
 ||58.230.89.42$document
 ||58.238.42.192$document
@@ -3340,92 +3353,57 @@
 ||58.241.78.55$document
 ||58.243.126.133$document
 ||58.248.112.254$document
-||58.248.140.46$document
+||58.248.117.238$document
+||58.248.142.5$document
 ||58.248.143.240$document
-||58.248.144.122$document
-||58.248.144.88$document
-||58.248.147.235$document
-||58.248.151.128$document
+||58.248.144.229$document
+||58.248.147.196$document
+||58.248.151.33$document
 ||58.248.153.224$document
-||58.248.76.23$document
+||58.248.74.240$document
 ||58.248.77.38$document
-||58.248.82.34$document
 ||58.249.12.80$document
 ||58.249.14.53$document
 ||58.249.16.173$document
 ||58.249.19.127$document
-||58.249.23.58$document
-||58.249.73.182$document
-||58.249.74.197$document
+||58.249.72.88$document
+||58.249.74.243$document
 ||58.249.74.245$document
-||58.249.75.107$document
-||58.249.75.158$document
+||58.249.75.213$document
 ||58.249.77.88$document
-||58.249.79.62$document
+||58.249.80.25$document
 ||58.249.82.35$document
-||58.249.86.11$document
-||58.249.87.54$document
-||58.249.88.218$document
+||58.249.87.171$document
+||58.249.89.158$document
 ||58.252.176.71$document
-||58.253.13.50$document
+||58.255.133.161$document
+||58.255.140.150$document
 ||58.48.154.143$document
 ||58.50.221.148$document
 ||58.72.165.153$document
 ||58.72.165.39$document
 ||58.76.151.189$document
+||58.76.151.51$document
 ||58.97.206.33$document
 ||59.0.211.161$document
 ||59.102.168.189$document
+||59.127.11.50$document
 ||59.151.202.3$document
 ||59.151.214.4$document
+||59.151.246.125$document
 ||59.29.133.229$document
-||59.32.97.190$document
-||59.42.62.0$document
 ||59.45.235.176$document
 ||59.58.104.244$document
 ||59.58.117.226$document
 ||59.7.124.148$document
 ||59.8.35.22$document
-||59.92.176.186$document
-||59.92.18.43$document
-||59.92.181.100$document
-||59.92.182.21$document
-||59.92.182.84$document
-||59.92.218.209$document
-||59.92.218.254$document
-||59.93.17.66$document
-||59.93.18.37$document
-||59.93.22.45$document
-||59.94.180.222$document
-||59.94.181.124$document
-||59.94.183.163$document
-||59.95.174.230$document
-||59.95.175.37$document
-||59.96.38.154$document
-||59.96.38.182$document
-||59.97.168.127$document
-||59.97.169.111$document
-||59.97.169.173$document
-||59.97.171.61$document
-||59.97.172.0$document
-||59.97.173.49$document
-||59.97.174.151$document
-||59.97.175.163$document
-||59.99.136.22$document
-||59.99.136.63$document
-||59.99.138.83$document
-||59.99.139.190$document
-||59.99.141.237$document
-||59.99.40.173$document
-||59.99.40.27$document
-||59.99.41.192$document
-||59.99.44.136$document
-||59.99.44.201$document
-||59.99.44.5$document
-||59.99.47.220$document
-||59.99.47.96$document
-||59.99.93.136$document
-||59.99.94.181$document
+||59.92.180.232$document
+||59.92.217.35$document
+||59.94.180.230$document
+||59.96.37.181$document
+||59.96.37.192$document
+||59.96.39.222$document
+||59.97.193.255$document
 ||60.13.61.12$document
 ||60.14.48.221$document
 ||60.16.247.78$document
@@ -3443,6 +3421,7 @@
 ||60.211.19.63$document
 ||60.211.6.112$document
 ||60.212.100.83$document
+||60.212.111.39$document
 ||60.212.162.152$document
 ||60.212.202.218$document
 ||60.212.206.246$document
@@ -3453,6 +3432,8 @@
 ||60.213.162.59$document
 ||60.213.58.188$document
 ||60.213.83.55$document
+||60.214.217.96$document
+||60.214.32.17$document
 ||60.214.73.6$document
 ||60.214.93.166$document
 ||60.215.165.64$document
@@ -3466,15 +3447,15 @@
 ||60.25.115.48$document
 ||60.25.76.224$document
 ||60.253.15.104$document
-||60.253.39.88$document
+||60.253.4.72$document
 ||60.253.42.72$document
 ||60.253.51.127$document
-||60.253.8.81$document
 ||60.26.17.221$document
 ||60.7.10.121$document
 ||60.7.8.43$document
 ||60.7.99.254$document
 ||61.102.243.124$document
+||61.130.195.121$document
 ||61.162.169.210$document
 ||61.162.55.42$document
 ||61.163.142.96$document
@@ -3482,52 +3463,49 @@
 ||61.179.171.60$document
 ||61.179.91.194$document
 ||61.179.91.230$document
-||61.18.112.48$document
 ||61.192.73.253$document
 ||61.213.118.28$document
 ||61.247.224.66$document
 ||61.253.94.230$document
-||61.3.124.126$document
-||61.3.124.8$document
-||61.3.127.102$document
-||61.3.149.89$document
+||61.3.124.125$document
+||61.3.151.60$document
 ||61.47.220.169$document
 ||61.52.103.144$document
+||61.52.103.217$document
+||61.52.109.9$document
 ||61.52.11.87$document
 ||61.52.159.231$document
+||61.52.167.66$document
 ||61.52.195.226$document
+||61.52.210.53$document
+||61.52.211.61$document
 ||61.52.212.191$document
 ||61.52.214.11$document
+||61.52.234.193$document
 ||61.52.237.212$document
 ||61.52.242.56$document
+||61.52.30.172$document
+||61.52.4.214$document
+||61.52.42.174$document
 ||61.52.48.40$document
 ||61.52.76.72$document
 ||61.52.9.166$document
 ||61.52.9.62$document
+||61.52.98.22$document
 ||61.52.99.161$document
-||61.53.100.87$document
 ||61.53.102.137$document
 ||61.53.117.115$document
 ||61.53.119.161$document
 ||61.53.122.161$document
 ||61.53.123.162$document
 ||61.53.192.49$document
-||61.53.2.35$document
 ||61.53.201.162$document
-||61.53.54.255$document
-||61.53.72.250$document
-||61.53.81.18$document
-||61.53.99.179$document
 ||61.54.103.56$document
 ||61.54.168.35$document
 ||61.54.232.45$document
 ||61.54.40.202$document
-||61.54.58.190$document
 ||61.54.58.20$document
-||61.54.63.23$document
 ||61.54.64.104$document
-||61.54.76.122$document
-||61.54.77.175$document
 ||61.56.180.67$document
 ||61.56.181.7$document
 ||61.57.96.116$document
@@ -3572,17 +3550,18 @@
 ||67.3.169.223$document
 ||67.8.138.101$document
 ||67.81.98.111$document
-||67.82.242.243$document
 ||67.83.49.234$document
 ||67.84.138.165$document
 ||68.151.244.128$document
 ||68.174.182.226$document
 ||68.175.107.153$document
+||68.183.25.71$document
 ||68.188.144.143$document
 ||68.204.88.29$document
 ||68.205.106.84$document
 ||68.205.119.241$document
 ||68.78.33.33$document
+||68468438438.xyz$document
 ||69.115.37.205$document
 ||69.120.237.255$document
 ||69.123.245.151$document
@@ -3606,7 +3585,6 @@
 ||71.127.148.69$document
 ||71.146.190.91$document
 ||71.167.164.113$document
-||71.19.150.93$document
 ||71.204.63.239$document
 ||71.29.48.164$document
 ||71.34.191.213$document
@@ -3624,16 +3602,17 @@
 ||72.214.69.226$document
 ||72.229.230.118$document
 ||72.229.35.40$document
+||72.31.40.122$document
 ||73.204.216.103$document
 ||74.101.1.159$document
 ||74.108.224.112$document
+||74.116.216.141$document
 ||74.194.117.165$document
 ||74.195.115.176$document
 ||74.199.84.77$document
 ||74.64.139.223$document
 ||74.75.165.81$document
 ||75.127.141.52$document
-||75.176.213.114$document
 ||75.83.102.27$document
 ||75.99.213.61$document
 ||76.108.199.153$document
@@ -3648,6 +3627,7 @@
 ||77.71.52.220$document
 ||77.79.191.32$document
 ||77.89.203.238$document
+||77.94.89.20$document
 ||78.186.155.18$document
 ||78.187.141.144$document
 ||78.187.240.125$document
@@ -3700,7 +3680,6 @@
 ||82.80.154.214$document
 ||82.80.187.109$document
 ||82.81.100.54$document
-||82.81.106.65$document
 ||82.81.108.172$document
 ||82.81.131.158$document
 ||82.81.19.42$document
@@ -3723,9 +3702,9 @@
 ||84.210.219.208$document
 ||84.210.219.213$document
 ||84.212.219.127$document
-||84.224.162.170$document
 ||84.228.50.118$document
 ||84.228.95.204$document
+||84.238.24.35$document
 ||84.247.83.74$document
 ||84.254.39.129$document
 ||84.33.111.227$document
@@ -3745,6 +3724,7 @@
 ||85.97.195.129$document
 ||86.35.43.220$document
 ||87.61.89.40$document
+||87du.vip$document
 ||88.119.171.253$document
 ||88.2.208.71$document
 ||88.2.219.179$document
@@ -3758,7 +3738,6 @@
 ||88.250.254.90$document
 ||89.122.183.130$document
 ||89.29.213.33$document
-||89.34.26.165$document
 ||89.35.62.96$document
 ||89.40.85.166$document
 ||89.40.87.5$document
@@ -3780,7 +3759,6 @@
 ||92.114.191.82$document
 ||92.241.78.114$document
 ||92.27.246.202$document
-||92.54.237.143$document
 ||92.54.237.237$document
 ||92.83.62.139$document
 ||92.85.18.138$document
@@ -3803,6 +3781,7 @@
 ||95.153.241.63$document
 ||95.154.20.231$document
 ||95.158.19.130$document
+||95.170.113.227$document
 ||95.170.113.52$document
 ||95.170.201.34$document
 ||95.181.155.112$document
@@ -3812,7 +3791,6 @@
 ||95.9.120.40$document
 ||96.239.73.246$document
 ||96.47.147.169$document
-||97.103.64.196$document
 ||97.68.140.254$document
 ||97.96.199.75$document
 ||98.0.210.218$document
@@ -3826,7 +3804,6 @@
 ||98.30.24.54$document
 ||99.150.245.203$document
 ||99.33.195.164$document
-||99centsdigitals.com$document
 ||abcd.bg$document
 ||abclicks.in$document
 ||abissnet.net$document
@@ -3834,6 +3811,7 @@
 ||absoftechworld.com$document
 ||absupplies.co.uk$document
 ||abyssos.eu$document
+||academyshademani.com$document
 ||acbick.com$document
 ||accounts.thesmarttechhub.com$document
 ||aceeprc.com.aceeprc.com$document
@@ -3862,7 +3840,9 @@
 ||aiqtest.com$document
 ||ajpharmaholding.com$document
 ||ajstudiollc.com$document
+||akauk09.top$document
 ||akivj07.top$document
+||akpgi08.top$document
 ||al-wahd.com$document
 ||alasdemariposas.org$document
 ||alemelektronik.com$document
@@ -3898,6 +3878,7 @@
 ||api.cstdevs.com$document
 ||api.quocbao.biz$document
 ||api.sampy.io$document
+||aplicativoparasindicato.com.br$document
 ||apoolcondo.com$document
 ||app.adsensearticle.com$document
 ||app.explicitsurveys.co.uk$document
@@ -3905,7 +3886,6 @@
 ||apps.saintsoporte.com$document
 ||aqv.news$document
 ||areyoulivingwell.com$document
-||arsapetrolab.com$document
 ||artedibujoyarquitectura.com$document
 ||ask-regard.call-save.biz$document
 ||atfile.com$document
@@ -3916,14 +3896,13 @@
 ||atteuqpotentialunlimited.com$document
 ||augustair.com$document
 ||aulist.com$document
-||australiafashions.com$document
 ||automaticrefreshments.com$document
 ||avadhanagames.com$document
-||avissrilanka.com$document
 ||ayamallah.com$document
 ||azmeasurement.com$document
 ||azraktours.com$document
 ||b2b.toptanakaryakit.com.tr$document
+||b4ad7b79-534a-4e83-953e-c36da8cf27d9.s3.amazonaws.com/ww/setup.exe$document
 ||backgrounds.pk$document
 ||badeggdesign.com$document
 ||balealgodon.mx$document
@@ -3954,7 +3933,6 @@
 ||birdi.elin.co.za$document
 ||birminghamlink.org$document
 ||bitbucket.org/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe$document
-||bitbucket.org/densjons/bro/downloads/rew.exe$document
 ||bitbucket.org/dvdfv/anjj/downloads/jami.exe$document
 ||bitbucket.org/jpavelski/chpock/downloads/4.exe$document
 ||bitbucket.org/jpavelski/chpock/downloads/6.exe$document
@@ -4037,12 +4015,12 @@
 ||blog.oyinblogs.com$document
 ||blog.takbelit.com$document
 ||bmlifestyle.co.uk$document
-||bnrbook.com$document
 ||bnrnews.id$document
 ||bodenstein.co.za$document
 ||booksearch.com$document
 ||bounces.mi-fs.com$document
 ||bpo.correct.go.th$document
+||bradleyinstitute.co.za$document
 ||brandtrust.com.pk$document
 ||brendanquine.com$document
 ||brideofmessiah.com$document
@@ -4053,8 +4031,6 @@
 ||browardinsurancemiami.solucioneslink.com$document
 ||bt2.elin.co.za$document
 ||btdapi.robotake.com$document
-||bucrinsuranlceonlines.com$document
-||buenavista.co$document
 ||buigiaphat.com.vn$document
 ||bullseyemedia.in$document
 ||busandvanrentalmalaysia.com$document
@@ -4081,8 +4057,13 @@
 ||cdaonline.com.ar$document
 ||cdn.discordapp.com/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq$document
 ||cdn.discordapp.com/attachments/816070119281131570/816070273254162442/all.txt$document
+||cdn.discordapp.com/attachments/821809080812437507/824392185902006272/mmp1_1.exe$document
 ||cdn.discordapp.com/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso$document
+||cdn.discordapp.com/attachments/823810712891555890/824413943526195210/runpetest.exe$document
+||cdn.discordapp.com/attachments/824689793140129857/824690065988386816/sendhookfile.exe$document
+||cdn.discordapp.com/attachments/824689793140129857/824691026852970496/photo.exe$document
 ||cec.asso.ac-amiens.fr$document
+||cecra.cl$document
 ||cellas.sk$document
 ||cendekiabinaaksara.com$document
 ||cespol-bote.com.mx$document
@@ -4090,8 +4071,6 @@
 ||ch.rmu.ac.th$document
 ||changematterscounselling.com$document
 ||chardhamdodham.com$document
-||cheacrilnsurances.com$document
-||chealablilitycarinsurances.com$document
 ||chezalice.co.za$document
 ||childselect.com$document
 ||chinhdropfile.myvnc.com$document
@@ -4116,11 +4095,9 @@
 ||constructoralyon.com$document
 ||consulateins.solucioneslink.com$document
 ||contributeindustry.com$document
-||controladoradeplagasmm.com$document
 ||controleautomacao.com.br$document
 ||copelandscapes.com$document
 ||coulsongraphics.com$document
-||coutler.newreadermedia.net$document
 ||covid19.cyberschool.or.id$document
 ||cr-sq.com$document
 ||craftnesia.id$document
@@ -4173,14 +4150,16 @@
 ||destinymc.co.za$document
 ||detorre.es$document
 ||dev-interestingtech.pantheonsite.io$document
-||dev.sayse-tienda.com$document
 ||dev.sebpo.net$document
+||dezcom.com$document
 ||dfcf.91756.cn$document
-||dfsfcsfcdsfsdvcfsvcscv.com$document
 ||diamantenegro.mi-fs.com$document
 ||dienmayminhhung.com$document
 ||digilib.dianhusada.ac.id$document
+||digitalassets.ams3.digitaloceanspaces.com/hold/schost.exe$document
+||digitalassets.ams3.digitaloceanspaces.com/modern/five.exe$document
 ||djking.f3322.net$document
+||dl-link.link$document
 ||dl.1003b.56a.com$document
 ||dl.198424.com$document
 ||dl.installcdn-aws.com$document
@@ -4193,9 +4172,7 @@
 ||docs.google.com/uc?id=11jnyjpzkjiie_rzc4xwa2feok3x__yvc$document
 ||docs.google.com/uc?id=151uxflny3vqh_lmghrkgjhhsqxi163sh$document
 ||docs.google.com/uc?id=15iwonkjkhyvri_okkc_llq56aasvnvb9$document
-||docs.google.com/uc?id=16gqndqbduwuhy3qzxdn2nd9nufm_9ctq$document
 ||docs.google.com/uc?id=1ak46tqftzejmq-og_ky2oupgpmkgujtm$document
-||docs.google.com/uc?id=1b6stzilakqykxaw1ct2w9hzccizwotff$document
 ||docs.google.com/uc?id=1brsmnj6g0lxa44ixkypvg5tcxkvi5gjt$document
 ||docs.google.com/uc?id=1by_s4vv8gdmmz8wl-lbpjbjy5adcrjk1$document
 ||docs.google.com/uc?id=1dpsxfbptpyl-zegto9t29vvcku2rjm9u$document
@@ -4204,15 +4181,11 @@
 ||docs.google.com/uc?id=1erajjbz6gdxhsvvorlykzxyeoq-xu7wn$document
 ||docs.google.com/uc?id=1ev7gkzwjgtv2vlbbisg1ragd7nf0-xog$document
 ||docs.google.com/uc?id=1ey8zl85vszh-gdmubkoudacqs6zv2dup$document
-||docs.google.com/uc?id=1f5trx90ulgsd-m1zvdupuf_kfugoo9ye$document
 ||docs.google.com/uc?id=1gq_jf503du9oip5bwzcoi6_kgolr3kx2$document
-||docs.google.com/uc?id=1hlaoow8ug5gjejeeihwetcxyfjodcdut$document
 ||docs.google.com/uc?id=1imrv00kqbfz4ljzwq5qdau1to0zlmaqy$document
 ||docs.google.com/uc?id=1j6pvg1rznjh9pkldcyjiogo8ysiyl8_y$document
 ||docs.google.com/uc?id=1jlcqojhfhgifmirrsv0o5t-2rl-hblai$document
-||docs.google.com/uc?id=1jvvuxwek4wrjqs94bjm8_klnnngj7b5r$document
 ||docs.google.com/uc?id=1k6sh5h-nptesem_jsnuxmhzntnvdlgxz$document
-||docs.google.com/uc?id=1lc8lpsmu5ndjweyusqrxblm0g84sdcc7$document
 ||docs.google.com/uc?id=1lk6n-xrtv0dvdqljl26pzebxzp8tladk$document
 ||docs.google.com/uc?id=1lkcqgpimry4yp8grinnhsotnawquozcz$document
 ||docs.google.com/uc?id=1m34mp1cggxz-cz3a5ipjrgfog_qx8myx$document
@@ -4220,29 +4193,19 @@
 ||docs.google.com/uc?id=1m8w1y1-mxxa2pktrzkwfetwjxrlw1alo$document
 ||docs.google.com/uc?id=1m9jxzqcbnb8j8uph1qfcas8b9pngcogj$document
 ||docs.google.com/uc?id=1mdnlxs6vy5qk-u4dxz9movem4j3a3o-8$document
-||docs.google.com/uc?id=1o6omlk34dxy3cbai8rvkvrnp5g-ovsj-$document
 ||docs.google.com/uc?id=1od6gtslxvylgyeujmrbvm9yhupmq_1lv$document
 ||docs.google.com/uc?id=1ozpasp-mr-e-ui4lshy4qy4a2pl8pxsi$document
-||docs.google.com/uc?id=1pnmkgw-rlm9mjstqdxfcq0en07_x93ue$document
 ||docs.google.com/uc?id=1q0edpjr7vgo_ytns7dgjcav6317juz9y$document
 ||docs.google.com/uc?id=1q5gqeinogsri3i-ynlgvu88ajqnn9siq$document
 ||docs.google.com/uc?id=1quyiobd7-d-vcddlhxiqbqrwxyg7ongo$document
-||docs.google.com/uc?id=1qyzpbxbnmnbp5opdk5rmeplmbga9c_q9$document
 ||docs.google.com/uc?id=1rrtyvouwizor2icbcoywdid4w9rwngxi$document
 ||docs.google.com/uc?id=1sao6yxf-a0t6wdgdr36srwlju57vigx_$document
-||docs.google.com/uc?id=1sbg8kdmxp5futgje5jcfvh-ieq28holg$document
-||docs.google.com/uc?id=1seb4h5c8z5jaf2_ulvhdv7mzqzmntp0k$document
-||docs.google.com/uc?id=1skuwjvkgsmicbr1o48gnalcksfytwtdp$document
 ||docs.google.com/uc?id=1st5mtgqyofsskuhlomfihfmz_qx-i32o$document
+||docs.google.com/uc?id=1u5q84w84g_x98ti4uflzhrgvzzfyj_qi$document
 ||docs.google.com/uc?id=1umz5zjobot9__v2jxdutyborb2az90hz$document
 ||docs.google.com/uc?id=1we-h5qtxj9czhkhzvzg0qqpxufgu_v__$document
-||docs.google.com/uc?id=1wmi0gpfe9ebcgai4w6iw6pninxo6ke-m$document
 ||docs.google.com/uc?id=1wurpipyf0s__fqtn1ov619nx7v1-tcy3$document
 ||docs.google.com/uc?id=1wwkqbfluu4qusqz26ewulr48zh9vzq-w$document
-||docs.google.com/uc?id=1xbvceq1wmfjad59zyxwtykzy3xwy9iqb$document
-||docs.google.com/uc?id=1xqcnagjbut3pdajnpsx0nonhla3nqes-$document
-||docs.google.com/uc?id=1xsj8d2ysnoluawhk3g4tadaoyp8ktmab$document
-||docs.google.com/uc?id=1xtflvdimom8odrygcmip7j4aesrjtgsm$document
 ||docs.google.com/uc?id=1yyuejm8cerrq2tctsibww4uetepcmh4i$document
 ||dodsonimaging.com$document
 ||dokan.blueberrytec.com$document
@@ -4257,7 +4220,6 @@
 ||dovberger.com$document
 ||down.flash-plays.com$document
 ||down.pcclear.com$document
-||down.udashi.com$document
 ||down.webbora.com$document
 ||down1.arpun.com$document
 ||download.caihong.com$document
@@ -4305,6 +4267,7 @@
 ||dsenterprize.co.za$document
 ||dsspainting.com$document
 ||du-wizards.com$document
+||duckrambo.com$document
 ||duque.guantanameratravel.com$document
 ||dutapp.wisolve.co.za$document
 ||duvalcharter.dekitout.com$document
@@ -4316,7 +4279,6 @@
 ||ebruyatkin.com$document
 ||econews.treegle.org$document
 ||efficientegroup.com$document
-||elliot.newreadermedia.net$document
 ||en.baoend.com$document
 ||enc-tech.com$document
 ||endurotanzania.co.tz$document
@@ -4341,7 +4303,6 @@
 ||exxonabnie.ir/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//$document
 ||exxonabnie.ir/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///$document
 ||exxonabnie.ir/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////$document
-||f1sol.com$document
 ||familydentist.site$document
 ||farmaciasdrogaminas.com.br$document
 ||fate3.xyz$document
@@ -4355,6 +4316,7 @@
 ||files.martellexpress.us$document
 ||final.makkahkmcc.com$document
 ||fineartgallerym.com$document
+||fixauto.illumetechnology.com$document
 ||fkd.derpcity.ru$document
 ||flintspin.com$document
 ||flyingbuddhadesign.com$document
@@ -4364,7 +4326,6 @@
 ||footweardirect.elin.co.za$document
 ||forum.mdb.nu$document
 ||fotoobjetivo.com$document
-||foundationrepairhoustontx.net$document
 ||foxeps.com.br$document
 ||freecnetdownload.com$document
 ||freedombookshop.tickme.lk$document
@@ -4386,7 +4347,6 @@
 ||ghislain.dartois.pagesperso-orange.fr$document
 ||giadungg7.com$document
 ||giddos.ga$document
-||gilliem.com$document
 ||girotexuniformes.com$document
 ||gist.githubusercontent.com/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe$document
 ||giteletropical.com$document
@@ -4403,6 +4363,7 @@
 ||goldcupmortgage.com$document
 ||golden-memories-funerals.yourpageserver.com$document
 ||goldmen.in$document
+||gracejukes.com$document
 ||grupoinmare.com$document
 ||gruposelt.000webhostapp.com$document
 ||gs.monerorx.com$document
@@ -4413,6 +4374,7 @@
 ||harshraval.in$document
 ||hd11315.com$document
 ||hdkamera2003.hu$document
+||hdrest.fastlinktz.com$document
 ||hds.sz4h.com$document
 ||healthy20.net$document
 ||heavymaq.cl$document
@@ -4433,7 +4395,6 @@
 ||homefindersolutions.com$document
 ||hongluosi.com$document
 ||hookedupboatclub.com$document
-||hostelkielce.com$document
 ||hostzaa.com$document
 ||houstonshutters.site$document
 ||hqdecig.com/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/$document
@@ -4456,7 +4417,6 @@
 ||iesanjosemonitos.edu.co$document
 ||ikexpert.com$document
 ||ilrafrica.com$document
-||images.jermiau.com$document
 ||imbueautoworx.co.za$document
 ||incodimsa.com$document
 ||incrediblepixels.com$document
@@ -4476,8 +4436,10 @@
 ||intuitiveideas.com.my$document
 ||inversiones.arrayanfinanciero.cl$document
 ||invest.xpcorporative.com.br$document
+||investinae.com$document
 ||ipmes.ma$document
 ||iremart.es$document
+||iris101.co.uk$document
 ||isaac.mikhailmotoringschool.com$document
 ||iscamenabe.com$document
 ||ismf.com.ng$document
@@ -4488,7 +4450,6 @@
 ||it123.ru$document
 ||itc-demo.softgig.co.ke$document
 ||itconsultus.com.co$document
-||jamesjorgensen.newreadermedia.net$document
 ||jamiekaylive.com$document
 ||jamshed.pk$document
 ||jansen-heesch.nl$document
@@ -4497,7 +4458,6 @@
 ||jcedu.org/ebook/cs17.exe$document
 ||jebs.net.au$document
 ||jeffdahlke.com$document
-||jewsjuice.com$document
 ||jhayesconsulting.com$document
 ||jiaoyuzixun.cn$document
 ||jing-da.com.tw$document
@@ -4515,16 +4475,13 @@
 ||jpwoodfordco.com$document
 ||jumpmanualjacobhiller.com$document
 ||jupiter.toxsl.in$document
-||jurgensen.newreadermedia.net$document
 ||justinscott.com.au$document
 ||justlficante.mediafire.com/file/jl01o54yy09qrzg/fac215.tgz/file$document
-||kaizenjanitorial.com$document
 ||kalawatihomes.com$document
 ||kalpataru-elitus-mulund.thakkers.in$document
 ||karer.by$document
 ||karmakoincodes.weebly.com/uploads/3/2/8/8/3288864/karma_koin_codes.exe$document
 ||katanvetov.co.il$document
-||kbdom.com$document
 ||kensingtondriving.com$document
 ||kevinjewelry.com.co$document
 ||keywatch.yourpageserver.com$document
@@ -4532,7 +4489,6 @@
 ||kjcpromo.com$document
 ||kleinendeli.co.za$document
 ||korrectconceptservices.com$document
-||kotakwarna.co.id/dg/etrac/nf4emwz/$document
 ||ksh.hu/docs/adatgyujtesek/elektra/csv_to_xml.exe$document
 ||ktb.sch.id$document
 ||kuaizip.com/down/affiliate/kuaizip_setup_10029.exe$document
@@ -4566,7 +4522,6 @@
 ||lindnerelektroanlagen.de$document
 ||linkintec.cn$document
 ||linuxforensicsbook.com.s3.amazonaws.com/linuxforensicscode.zip$document
-||litroxlitro.com$document
 ||livetrack.in$document
 ||lloydsindian.co.uk$document
 ||lm.stagingarea.co.za$document
@@ -4580,11 +4535,8 @@
 ||logotypfabriken.se$document
 ||lotix.de$document
 ||lotusanddragonfly.com$document
-||lp.carrduci.com$document
 ||lp.definerisco.com$document
 ||lp.difusodesign.com$document
-||lp.juancamilogarciareyes.com$document
-||lp.tecnimasdecolombia.com.co$document
 ||ltc.typoten.com$document
 ||luckybrownie.com$document
 ||luminouspneuma.com$document
@@ -4614,6 +4566,7 @@
 ||materialescantu.com$document
 ||matruchhaya.co.in$document
 ||mattysplayground.com$document
+||maxiquim.cl$document
 ||maxtox.com.pk$document
 ||mbgrm.com$document
 ||mbsolutions.ge$document
@@ -4623,6 +4576,7 @@
 ||mediamaster.co.za$document
 ||medianews.ge$document
 ||medistaffconsulting.com$document
+||meditreat.itwebservice.in$document
 ||meeweb.com$document
 ||megamart.afnan-amc.com$document
 ||merbay.ru$document
@@ -4700,7 +4654,6 @@
 ||nikanpolimer.ir$document
 ||nilehouse.co.ug$document
 ||nilinkeji.com$document
-||nisacooks.com$document
 ||njtiledesigncenter.com$document
 ||nobius.org$document
 ||nocalnoodle.elin.co.za$document
@@ -4716,7 +4669,6 @@
 ||nyeh2o.com.au$document
 ||oakleyandfriends.co.uk$document
 ||obseques-conseils.com$document
-||ocean.tecnasulstore.com.br$document
 ||ohe.ie$document
 ||ohsewgorgeous.co.uk$document
 ||oknoplastik.sk$document
@@ -4759,6 +4711,7 @@
 ||onedrive.live.com/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4$document
 ||onedrive.live.com/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma$document
 ||onedrive.live.com/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48$document
+||onedrive.live.com/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq$document
 ||onedrive.live.com/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg$document
 ||onedrive.live.com/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw$document
 ||onedrive.live.com/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq$document
@@ -4796,6 +4749,7 @@
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4$document
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c$document
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0$document
+||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc$document
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c$document
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs$document
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0$document
@@ -4872,8 +4826,6 @@
 ||onedrive.live.com/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy$document
 ||onedrive.live.com/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw$document
 ||onedrive.live.com/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw$document
-||onedrive.live.com/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8$document
-||onedrive.live.com/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c$document
 ||onedrive.live.com/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y$document
 ||onedrive.live.com/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg$document
 ||onedrive.live.com/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns$document
@@ -4884,6 +4836,7 @@
 ||onedrive.live.com/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4$document
 ||onedrive.live.com/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm$document
 ||onedrive.live.com/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu$document
+||onedrive.live.com/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8$document
 ||onedrive.live.com/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8$document
 ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc$document
 ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y$document
@@ -4905,6 +4858,7 @@
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa$document
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu$document
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c$document
+||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy$document
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q$document
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm$document
 ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4$document
@@ -4944,7 +4898,6 @@
 ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq$document
 ||onedrive.live.com/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g$document
 ||onedrive.live.com/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum$document
-||onedrive.live.com/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa$document
 ||onedrive.live.com/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi$document
 ||onedrive.live.com/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy$document
 ||onedrive.live.com/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o$document
@@ -4967,6 +4920,7 @@
 ||onedrive.live.com/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg$document
 ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai$document
 ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc$document
+||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai$document
 ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc$document
 ||onedrive.live.com/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw$document
 ||onedrive.live.com/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8$document
@@ -5025,10 +4979,6 @@
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w$document
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta$document
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em$document
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!210&authkey=agpl0pgvft8faaa$document
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c$document
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa$document
-||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c$document
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto$document
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum$document
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto$document
@@ -5132,6 +5082,7 @@
 ||onedrive.live.com/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk$document
 ||onedrive.live.com/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw$document
 ||onedrive.live.com/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc$document
+||onedrive.live.com/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc$document
 ||onedrive.live.com/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e$document
 ||onedrive.live.com/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks$document
 ||onedrive.live.com/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks$document
@@ -5216,13 +5167,6 @@
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy$document
 ||onedrive.live.com/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774!124&authkey=afq42wqejwvcv8o$document
 ||onedrive.live.com/download?cid=d73a3a4d49e92774&resid=d73a3a4d49e92774%21124&authkey=afq42wqejwvcv8o$document
-||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na$document
-||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8$document
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o$document
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0$document
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o$document
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0$document
-||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw$document
 ||onedrive.live.com/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe$document
 ||onedrive.live.com/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq$document
 ||onedrive.live.com/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4$document
@@ -5349,7 +5293,6 @@
 ||payments.atifsiddiqui.me$document
 ||pcsoori.com$document
 ||pd.oceaniarp.net$document
-||perpus.onlineman7-jombang.sch.id$document
 ||perpustekim.untirta.ac.id$document
 ||petercollie.com$document
 ||ph4s.ru$document
@@ -5372,6 +5315,7 @@
 ||poulman.panagiotopoulos-tours.gr$document
 ||ppdb.smk-ciptaskill.sch.id$document
 ||pptvideotemplates.com$document
+||prestasicash.com.ar$document
 ||prestigehomeautomation.net$document
 ||prishaartcreations.com$document
 ||procrossover.ru/wp-content/uploads/2020/10/skoda22.jpg$document
@@ -5387,7 +5331,6 @@
 ||prosyarmakassar.com$document
 ||provence.elin.co.za$document
 ||prueba.danielluza.com$document
-||ptpmeccatronica.eu$document
 ||pujashoppe.in$document
 ||punchdialogues.com$document
 ||punjabdevelopersassociation.com.pk$document
@@ -5455,7 +5398,6 @@
 ||rsgym.net$document
 ||rubazar.pro$document
 ||rubycityvietnam.com$document
-||ruch.newreadermedia.net$document
 ||ruisgood.ru$document
 ||ruwadalkuwait.com$document
 ||rydchile.cl$document
@@ -5490,6 +5432,7 @@
 ||serendibsourcing.com$document
 ||servicemhkd.myvnc.com$document
 ||servicemhkd80.myvnc.com$document
+||serviciovirtual.com.ar$document
 ||seyranikenger.com.tr$document
 ||sgessy.com.br$document
 ||shaheentbfoundation.com$document
@@ -5504,7 +5447,6 @@
 ||shopsofe.com$document
 ||shrushtiinfotech.com$document
 ||sibernetix.fr$document
-||siddharthpanditpautra.com$document
 ||sige.brisainformatica.com.br$document
 ||signatureads.co.in$document
 ||siili.net$document
@@ -5556,7 +5498,8 @@
 ||statsres.com$document
 ||statssound.com$document
 ||statsspot.com$document
-||stattilion.bar$document
+||statsvilla.com$document
+||stemschool.net$document
 ||stiepancasetia.ac.id$document
 ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt$document
 ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt$document
@@ -5578,13 +5521,13 @@
 ||supermercadostia.com$document
 ||support-4-free.com$document
 ||support.clz.kr$document
+||supportit.online$document
 ||sw.yourpageserver.com$document
 ||sweaty.dk$document
 ||sweet-diet.com$document
 ||swentsai.com$document
 ||swiftlogisticseg.com$document
 ||swwbia.com$document
-||syedpro.dezinetimes.com$document
 ||syracusecoffee.com$document
 ||sys.pbmadu.co.id$document
 ||sytraders.co$document
@@ -5598,6 +5541,7 @@
 ||tapalkoedacoffee.com$document
 ||tarravalleyfoods.com.au$document
 ||taurus.ug$document
+||tavo.cl$document
 ||taxicabsrilanka.com$document
 ||taxpos.com$document
 ||tc.snpsresidential.com$document
@@ -5619,6 +5563,7 @@
 ||test.letraele.es$document
 ||test.typoten.com$document
 ||test.wanepghana.org$document
+||test1.asistencia247.com$document
 ||test1.milenial.id$document
 ||test1.tenplusone.my$document
 ||test2.basis-web.com$document
@@ -5687,7 +5632,7 @@
 ||unisoftcc.com$document
 ||unyazitelecom.com$document
 ||upcbpta.com$document
-||urbane.dezinetimes.com$document
+||urbantrapfest.cl$document
 ||useformoney.000webhostapp.com$document
 ||users.skynet.be/crisanar/defis/jek_crackme1.7.zip$document
 ||usmadetshirts.com$document
@@ -5697,7 +5642,6 @@
 ||vcah.co.uk$document
 ||vegadelcasero.cl$document
 ||vendas.lidiacarmeli.com.br$document
-||verify.aicosoft.com$document
 ||vfocus.net$document
 ||vidmattic.com$document
 ||vienen.gblix.srv.br$document
@@ -5717,6 +5661,7 @@
 ||vokasi.ub.ac.id$document
 ||vologroup.com.br$document
 ||voteyouramerica.dekitout.com$document
+||vpinversiones.cl$document
 ||vstsample.com$document
 ||vtube.fadlymotivator.com$document
 ||vvsskmodinationalschool.com$document
@@ -5779,6 +5724,5 @@
 ||yskadvisors.com$document
 ||yummyyogaudaipur.com$document
 ||yzkzixun.com$document
-||zakra.tecnasulstore.com.br$document
 ||zytrox.tk$document
 ||zz.690tx.com$document
diff --git a/urlhaus-filter-vivaldi.txt b/urlhaus-filter-vivaldi.txt
index f8e8c1c6..b6e4f116 100644
--- a/urlhaus-filter-vivaldi.txt
+++ b/urlhaus-filter-vivaldi.txt
@@ -1,5 +1,5 @@
 ! Title: Malicious URL Blocklist (Vivaldi)
-! Updated: Sat, 27 Mar 2021 12:12:22 UTC
+! Updated: Sun, 28 Mar 2021 00:12:34 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1867,6 +1867,7 @@
 ||101.108.142.60$document
 ||101.108.142.75$document
 ||101.108.142.82$document
+||101.108.142.9$document
 ||101.108.143.105$document
 ||101.108.143.110$document
 ||101.108.143.137$document
@@ -2393,6 +2394,7 @@
 ||101.66.80.23$document
 ||101.66.80.72$document
 ||101.66.81.166$document
+||101.66.81.70$document
 ||101.67.176.237$document
 ||101.67.180.154$document
 ||101.67.198.121$document
@@ -2972,6 +2974,7 @@
 ||103.126.100.31$document
 ||103.126.100.9$document
 ||103.126.217.58$document
+||103.126.35.40$document
 ||103.127.104.16$document
 ||103.127.104.165$document
 ||103.127.104.184$document
@@ -4275,6 +4278,7 @@
 ||103.245.48.197$document
 ||103.245.49.135$document
 ||103.245.49.147$document
+||103.245.49.180$document
 ||103.245.49.183$document
 ||103.245.49.204$document
 ||103.245.49.24$document
@@ -8722,6 +8726,7 @@
 ||107.173.160.139$document
 ||107.173.160.14$document
 ||107.173.171.123$document
+||107.173.171.143$document
 ||107.173.171.168$document
 ||107.173.175.135$document
 ||107.173.176.100$document
@@ -12359,6 +12364,7 @@
 ||112.122.63.240$document
 ||112.122.63.54$document
 ||112.122.63.6$document
+||112.122.63.70$document
 ||112.122.63.9$document
 ||112.122.90.208$document
 ||112.122.99.186$document
@@ -14454,6 +14460,7 @@
 ||112.235.188.86$document
 ||112.235.194.43$document
 ||112.235.210.15$document
+||112.235.210.251$document
 ||112.235.217.106$document
 ||112.235.217.213$document
 ||112.235.219.224$document
@@ -16833,6 +16840,7 @@
 ||112.242.96.25$document
 ||112.242.96.4$document
 ||112.242.96.56$document
+||112.242.97.131$document
 ||112.242.97.165$document
 ||112.242.97.195$document
 ||112.242.98.194$document
@@ -16887,6 +16895,7 @@
 ||112.245.177.136$document
 ||112.245.177.145$document
 ||112.245.177.215$document
+||112.245.178.153$document
 ||112.245.179.96$document
 ||112.245.182.56$document
 ||112.245.182.9$document
@@ -17215,6 +17224,7 @@
 ||112.247.156.74$document
 ||112.247.158.19$document
 ||112.247.16.190$document
+||112.247.16.222$document
 ||112.247.161.45$document
 ||112.247.161.83$document
 ||112.247.163.177$document
@@ -17282,6 +17292,7 @@
 ||112.247.248.76$document
 ||112.247.249.198$document
 ||112.247.249.82$document
+||112.247.25.42$document
 ||112.247.250.193$document
 ||112.247.250.96$document
 ||112.247.251.11$document
@@ -18714,6 +18725,7 @@
 ||112.254.125.2$document
 ||112.254.127.63$document
 ||112.254.128.119$document
+||112.254.128.160$document
 ||112.254.128.224$document
 ||112.254.129.79$document
 ||112.254.129.95$document
@@ -18817,6 +18829,7 @@
 ||112.254.188.12$document
 ||112.254.188.137$document
 ||112.254.188.19$document
+||112.254.188.228$document
 ||112.254.188.35$document
 ||112.254.189.137$document
 ||112.254.189.16$document
@@ -21507,6 +21520,7 @@
 ||113.116.177.248$document
 ||113.116.177.29$document
 ||113.116.177.81$document
+||113.116.177.90$document
 ||113.116.178.100$document
 ||113.116.178.133$document
 ||113.116.178.138$document
@@ -22346,6 +22360,7 @@
 ||113.116.89.25$document
 ||113.116.89.29$document
 ||113.116.89.40$document
+||113.116.89.41$document
 ||113.116.89.45$document
 ||113.116.89.55$document
 ||113.116.89.82$document
@@ -22700,6 +22715,7 @@
 ||113.118.159.142$document
 ||113.118.159.144$document
 ||113.118.159.153$document
+||113.118.159.178$document
 ||113.118.159.215$document
 ||113.118.159.22$document
 ||113.118.159.232$document
@@ -23153,6 +23169,7 @@
 ||113.118.87.84$document
 ||113.118.87.88$document
 ||113.119.36.91$document
+||113.119.37.141$document
 ||113.119.85.16$document
 ||113.122.238.68$document
 ||113.122.32.245$document
@@ -26887,6 +26904,7 @@
 ||113.88.39.104$document
 ||113.88.39.194$document
 ||113.88.39.2$document
+||113.88.39.21$document
 ||113.88.39.35$document
 ||113.88.39.37$document
 ||113.88.39.55$document
@@ -27595,6 +27613,7 @@
 ||113.90.26.54$document
 ||113.90.26.6$document
 ||113.90.27.178$document
+||113.90.27.218$document
 ||113.90.92.191$document
 ||113.90.93.98$document
 ||113.90.94.120$document
@@ -27722,6 +27741,7 @@
 ||113.92.196.102$document
 ||113.92.196.116$document
 ||113.92.196.145$document
+||113.92.196.173$document
 ||113.92.196.192$document
 ||113.92.196.227$document
 ||113.92.196.235$document
@@ -30188,6 +30208,7 @@
 ||115.205.14.76$document
 ||115.205.15.79$document
 ||115.205.171.34$document
+||115.205.197.221$document
 ||115.205.235.30$document
 ||115.205.66.30$document
 ||115.205.70.49$document
@@ -32677,6 +32698,7 @@
 ||115.48.201.222$document
 ||115.48.201.244$document
 ||115.48.201.255$document
+||115.48.201.26$document
 ||115.48.201.31$document
 ||115.48.201.37$document
 ||115.48.201.40$document
@@ -33514,6 +33536,7 @@
 ||115.48.40.227$document
 ||115.48.40.3$document
 ||115.48.40.63$document
+||115.48.41.101$document
 ||115.48.41.141$document
 ||115.48.41.156$document
 ||115.48.41.184$document
@@ -34454,6 +34477,7 @@
 ||115.49.24.52$document
 ||115.49.24.58$document
 ||115.49.24.60$document
+||115.49.24.63$document
 ||115.49.240.125$document
 ||115.49.240.14$document
 ||115.49.240.147$document
@@ -36544,6 +36568,7 @@
 ||115.50.168.145$document
 ||115.50.168.153$document
 ||115.50.168.159$document
+||115.50.168.160$document
 ||115.50.168.168$document
 ||115.50.168.183$document
 ||115.50.168.19$document
@@ -36686,6 +36711,7 @@
 ||115.50.171.172$document
 ||115.50.171.184$document
 ||115.50.171.188$document
+||115.50.171.192$document
 ||115.50.171.196$document
 ||115.50.171.248$document
 ||115.50.171.250$document
@@ -37471,6 +37497,7 @@
 ||115.50.211.56$document
 ||115.50.211.62$document
 ||115.50.211.65$document
+||115.50.211.74$document
 ||115.50.211.8$document
 ||115.50.211.80$document
 ||115.50.212.1$document
@@ -38654,6 +38681,7 @@
 ||115.50.242.244$document
 ||115.50.242.246$document
 ||115.50.242.43$document
+||115.50.242.7$document
 ||115.50.242.81$document
 ||115.50.242.89$document
 ||115.50.243.10$document
@@ -38771,6 +38799,7 @@
 ||115.50.247.245$document
 ||115.50.247.33$document
 ||115.50.247.40$document
+||115.50.247.46$document
 ||115.50.247.47$document
 ||115.50.247.56$document
 ||115.50.247.80$document
@@ -40644,6 +40673,7 @@
 ||115.50.79.50$document
 ||115.50.79.7$document
 ||115.50.79.73$document
+||115.50.79.78$document
 ||115.50.79.95$document
 ||115.50.8.131$document
 ||115.50.8.159$document
@@ -41824,6 +41854,7 @@
 ||115.51.58.162$document
 ||115.51.61.137$document
 ||115.51.7.177$document
+||115.51.7.254$document
 ||115.51.78.11$document
 ||115.51.88.101$document
 ||115.51.88.11$document
@@ -42459,6 +42490,7 @@
 ||115.52.172.58$document
 ||115.52.172.63$document
 ||115.52.172.64$document
+||115.52.172.72$document
 ||115.52.172.74$document
 ||115.52.172.91$document
 ||115.52.172.93$document
@@ -43810,6 +43842,7 @@
 ||115.53.56.72$document
 ||115.53.57.189$document
 ||115.53.58.162$document
+||115.53.58.228$document
 ||115.53.58.24$document
 ||115.53.59.170$document
 ||115.53.59.68$document
@@ -43925,6 +43958,7 @@
 ||115.54.112.31$document
 ||115.54.113.101$document
 ||115.54.113.128$document
+||115.54.113.49$document
 ||115.54.114.20$document
 ||115.54.114.211$document
 ||115.54.115.1$document
@@ -44113,6 +44147,7 @@
 ||115.54.158.17$document
 ||115.54.158.176$document
 ||115.54.158.210$document
+||115.54.158.251$document
 ||115.54.158.255$document
 ||115.54.158.67$document
 ||115.54.159.101$document
@@ -45802,6 +45837,7 @@
 ||115.55.126.58$document
 ||115.55.126.59$document
 ||115.55.126.88$document
+||115.55.127.0$document
 ||115.55.127.101$document
 ||115.55.127.126$document
 ||115.55.127.146$document
@@ -48042,6 +48078,7 @@
 ||115.55.197.78$document
 ||115.55.197.99$document
 ||115.55.198.103$document
+||115.55.198.105$document
 ||115.55.198.117$document
 ||115.55.198.127$document
 ||115.55.198.143$document
@@ -48844,6 +48881,7 @@
 ||115.55.52.113$document
 ||115.55.52.125$document
 ||115.55.52.136$document
+||115.55.52.17$document
 ||115.55.52.200$document
 ||115.55.52.206$document
 ||115.55.52.208$document
@@ -49749,6 +49787,7 @@
 ||115.56.131.136$document
 ||115.56.131.144$document
 ||115.56.131.148$document
+||115.56.131.150$document
 ||115.56.131.166$document
 ||115.56.131.170$document
 ||115.56.131.186$document
@@ -49998,6 +50037,7 @@
 ||115.56.135.237$document
 ||115.56.135.247$document
 ||115.56.135.250$document
+||115.56.135.255$document
 ||115.56.135.28$document
 ||115.56.135.33$document
 ||115.56.135.36$document
@@ -50418,6 +50458,7 @@
 ||115.56.142.39$document
 ||115.56.142.4$document
 ||115.56.142.44$document
+||115.56.142.45$document
 ||115.56.142.49$document
 ||115.56.142.5$document
 ||115.56.142.66$document
@@ -50745,6 +50786,7 @@
 ||115.56.150.130$document
 ||115.56.150.139$document
 ||115.56.150.14$document
+||115.56.150.149$document
 ||115.56.150.150$document
 ||115.56.150.152$document
 ||115.56.150.156$document
@@ -50994,6 +51036,7 @@
 ||115.56.155.38$document
 ||115.56.155.42$document
 ||115.56.155.43$document
+||115.56.155.50$document
 ||115.56.155.51$document
 ||115.56.155.54$document
 ||115.56.155.64$document
@@ -52595,6 +52638,7 @@
 ||115.56.27.88$document
 ||115.56.3.209$document
 ||115.56.31.10$document
+||115.56.31.11$document
 ||115.56.31.156$document
 ||115.56.31.170$document
 ||115.56.31.176$document
@@ -54743,6 +54787,7 @@
 ||115.58.91.225$document
 ||115.58.91.240$document
 ||115.58.91.52$document
+||115.58.91.65$document
 ||115.58.91.74$document
 ||115.58.91.86$document
 ||115.58.91.9$document
@@ -57993,6 +58038,7 @@
 ||115.61.112.13$document
 ||115.61.112.14$document
 ||115.61.112.140$document
+||115.61.112.159$document
 ||115.61.112.161$document
 ||115.61.112.168$document
 ||115.61.112.185$document
@@ -58630,6 +58676,7 @@
 ||115.61.158.55$document
 ||115.61.158.90$document
 ||115.61.158.93$document
+||115.61.158.98$document
 ||115.61.159.102$document
 ||115.61.159.115$document
 ||115.61.159.118$document
@@ -60154,6 +60201,7 @@
 ||115.62.170.41$document
 ||115.62.170.82$document
 ||115.62.170.91$document
+||115.62.171.143$document
 ||115.62.171.177$document
 ||115.62.171.71$document
 ||115.62.171.81$document
@@ -60548,6 +60596,7 @@
 ||115.63.131.168$document
 ||115.63.131.169$document
 ||115.63.131.170$document
+||115.63.131.173$document
 ||115.63.131.176$document
 ||115.63.131.229$document
 ||115.63.131.230$document
@@ -60779,6 +60828,7 @@
 ||115.63.139.178$document
 ||115.63.139.183$document
 ||115.63.139.186$document
+||115.63.139.187$document
 ||115.63.139.229$document
 ||115.63.139.246$document
 ||115.63.139.25$document
@@ -68429,6 +68479,7 @@
 ||115.97.139.254$document
 ||115.97.139.28$document
 ||115.97.139.3$document
+||115.97.139.32$document
 ||115.97.139.35$document
 ||115.97.139.4$document
 ||115.97.139.43$document
@@ -92781,6 +92832,7 @@
 ||116.68.98.160$document
 ||116.68.98.163$document
 ||116.68.98.17$document
+||116.68.98.173$document
 ||116.68.98.178$document
 ||116.68.98.182$document
 ||116.68.98.184$document
@@ -94891,6 +94943,7 @@
 ||116.72.28.187$document
 ||116.72.28.204$document
 ||116.72.28.226$document
+||116.72.28.239$document
 ||116.72.28.48$document
 ||116.72.28.49$document
 ||116.72.28.76$document
@@ -96508,6 +96561,7 @@
 ||116.73.52.121$document
 ||116.73.52.122$document
 ||116.73.52.124$document
+||116.73.52.125$document
 ||116.73.52.127$document
 ||116.73.52.13$document
 ||116.73.52.132$document
@@ -98339,6 +98393,7 @@
 ||116.73.99.95$document
 ||116.73.99.97$document
 ||116.74.101.118$document
+||116.74.101.150$document
 ||116.74.101.161$document
 ||116.74.101.177$document
 ||116.74.101.210$document
@@ -100255,6 +100310,7 @@
 ||116.74.23.37$document
 ||116.74.23.44$document
 ||116.74.23.45$document
+||116.74.23.46$document
 ||116.74.23.48$document
 ||116.74.23.51$document
 ||116.74.23.52$document
@@ -100346,6 +100402,7 @@
 ||116.74.24.75$document
 ||116.74.24.76$document
 ||116.74.24.79$document
+||116.74.24.8$document
 ||116.74.24.82$document
 ||116.74.24.84$document
 ||116.74.24.85$document
@@ -111716,6 +111773,7 @@
 ||116.88.65.131$document
 ||116.9.145.199$document
 ||116.9.43.106$document
+||116.9.43.220$document
 ||116.9.43.235$document
 ||116.90.238.142$document
 ||116.91.202.79$document
@@ -112817,6 +112875,7 @@
 ||117.194.148.188$document
 ||117.194.148.189$document
 ||117.194.148.190$document
+||117.194.148.198$document
 ||117.194.148.202$document
 ||117.194.148.205$document
 ||117.194.148.207$document
@@ -113099,6 +113158,7 @@
 ||117.194.151.176$document
 ||117.194.151.178$document
 ||117.194.151.180$document
+||117.194.151.184$document
 ||117.194.151.192$document
 ||117.194.151.196$document
 ||117.194.151.198$document
@@ -114050,6 +114110,7 @@
 ||117.194.164.97$document
 ||117.194.164.99$document
 ||117.194.165.0$document
+||117.194.165.1$document
 ||117.194.165.100$document
 ||117.194.165.101$document
 ||117.194.165.102$document
@@ -114741,6 +114802,7 @@
 ||117.196.48.178$document
 ||117.196.48.179$document
 ||117.196.48.180$document
+||117.196.48.181$document
 ||117.196.48.183$document
 ||117.196.48.184$document
 ||117.196.48.185$document
@@ -115031,6 +115093,7 @@
 ||117.196.50.147$document
 ||117.196.50.15$document
 ||117.196.50.150$document
+||117.196.50.154$document
 ||117.196.50.158$document
 ||117.196.50.161$document
 ||117.196.50.164$document
@@ -115074,6 +115137,7 @@
 ||117.196.50.23$document
 ||117.196.50.230$document
 ||117.196.50.236$document
+||117.196.50.239$document
 ||117.196.50.24$document
 ||117.196.50.240$document
 ||117.196.50.241$document
@@ -115118,6 +115182,7 @@
 ||117.196.50.7$document
 ||117.196.50.71$document
 ||117.196.50.72$document
+||117.196.50.76$document
 ||117.196.50.77$document
 ||117.196.50.78$document
 ||117.196.50.79$document
@@ -115996,6 +116061,7 @@
 ||117.202.66.40$document
 ||117.202.66.41$document
 ||117.202.66.42$document
+||117.202.66.44$document
 ||117.202.66.45$document
 ||117.202.66.46$document
 ||117.202.66.47$document
@@ -117612,6 +117678,7 @@
 ||117.207.47.96$document
 ||117.207.5.156$document
 ||117.207.50.5$document
+||117.208.132.10$document
 ||117.208.132.101$document
 ||117.208.132.102$document
 ||117.208.132.103$document
@@ -117885,6 +117952,7 @@
 ||117.208.133.86$document
 ||117.208.133.87$document
 ||117.208.133.9$document
+||117.208.133.91$document
 ||117.208.133.92$document
 ||117.208.133.97$document
 ||117.208.134.0$document
@@ -119326,6 +119394,7 @@
 ||117.213.41.74$document
 ||117.213.41.75$document
 ||117.213.41.78$document
+||117.213.41.8$document
 ||117.213.41.80$document
 ||117.213.41.82$document
 ||117.213.41.83$document
@@ -120269,6 +120338,7 @@
 ||117.213.47.134$document
 ||117.213.47.136$document
 ||117.213.47.138$document
+||117.213.47.139$document
 ||117.213.47.14$document
 ||117.213.47.140$document
 ||117.213.47.142$document
@@ -120528,6 +120598,7 @@
 ||117.215.210.230$document
 ||117.215.210.243$document
 ||117.215.210.245$document
+||117.215.210.249$document
 ||117.215.210.25$document
 ||117.215.210.250$document
 ||117.215.210.251$document
@@ -120589,6 +120660,7 @@
 ||117.215.212.153$document
 ||117.215.212.166$document
 ||117.215.212.168$document
+||117.215.212.174$document
 ||117.215.212.176$document
 ||117.215.212.180$document
 ||117.215.212.182$document
@@ -120730,6 +120802,7 @@
 ||117.215.248.158$document
 ||117.215.248.17$document
 ||117.215.248.181$document
+||117.215.248.198$document
 ||117.215.248.20$document
 ||117.215.248.201$document
 ||117.215.248.205$document
@@ -121573,6 +121646,7 @@
 ||117.222.162.70$document
 ||117.222.162.71$document
 ||117.222.162.72$document
+||117.222.162.73$document
 ||117.222.162.74$document
 ||117.222.162.75$document
 ||117.222.162.76$document
@@ -122346,6 +122420,7 @@
 ||117.222.166.28$document
 ||117.222.166.3$document
 ||117.222.166.30$document
+||117.222.166.36$document
 ||117.222.166.38$document
 ||117.222.166.39$document
 ||117.222.166.4$document
@@ -122822,6 +122897,7 @@
 ||117.222.170.217$document
 ||117.222.170.223$document
 ||117.222.170.224$document
+||117.222.170.234$document
 ||117.222.170.237$document
 ||117.222.170.238$document
 ||117.222.170.239$document
@@ -124470,6 +124546,7 @@
 ||117.242.210.238$document
 ||117.242.210.239$document
 ||117.242.210.24$document
+||117.242.210.240$document
 ||117.242.210.241$document
 ||117.242.210.244$document
 ||117.242.210.246$document
@@ -124750,6 +124827,7 @@
 ||117.242.48.212$document
 ||117.242.48.232$document
 ||117.242.48.57$document
+||117.242.49.157$document
 ||117.242.49.166$document
 ||117.242.49.185$document
 ||117.242.49.21$document
@@ -126495,6 +126573,7 @@
 ||117.248.63.61$document
 ||117.248.63.62$document
 ||117.248.63.67$document
+||117.248.63.70$document
 ||117.248.63.73$document
 ||117.248.63.74$document
 ||117.248.63.75$document
@@ -127587,6 +127666,7 @@
 ||117.251.63.206$document
 ||117.251.63.207$document
 ||117.251.63.209$document
+||117.251.63.21$document
 ||117.251.63.211$document
 ||117.251.63.212$document
 ||117.251.63.214$document
@@ -128462,6 +128542,7 @@
 ||118.113.244.200$document
 ||118.113.245.110$document
 ||118.114.216.131$document
+||118.114.84.237$document
 ||118.116.192.103$document
 ||118.116.192.53$document
 ||118.117.167.48$document
@@ -128781,6 +128862,7 @@
 ||118.172.224.136$document
 ||118.172.224.179$document
 ||118.172.224.205$document
+||118.172.224.37$document
 ||118.172.231.79$document
 ||118.172.232.164$document
 ||118.172.234.157$document
@@ -130317,6 +130399,7 @@
 ||118.79.91.203$document
 ||118.79.92.29$document
 ||118.79.93.194$document
+||118.79.96.11$document
 ||118.79.96.249$document
 ||118.79.96.9$document
 ||118.79.97.100$document
@@ -130634,6 +130717,7 @@
 ||119.118.128.127$document
 ||119.118.139.228$document
 ||119.118.143.250$document
+||119.118.150.84$document
 ||119.118.161.115$document
 ||119.118.167.179$document
 ||119.118.172.168$document
@@ -131014,6 +131098,7 @@
 ||119.123.173.46$document
 ||119.123.173.73$document
 ||119.123.173.91$document
+||119.123.173.95$document
 ||119.123.173.96$document
 ||119.123.174.102$document
 ||119.123.174.11$document
@@ -131058,6 +131143,7 @@
 ||119.123.175.174$document
 ||119.123.175.175$document
 ||119.123.175.185$document
+||119.123.175.210$document
 ||119.123.175.215$document
 ||119.123.175.222$document
 ||119.123.175.228$document
@@ -131276,6 +131362,7 @@
 ||119.123.219.194$document
 ||119.123.219.204$document
 ||119.123.219.230$document
+||119.123.219.232$document
 ||119.123.219.234$document
 ||119.123.219.240$document
 ||119.123.219.247$document
@@ -131319,6 +131406,7 @@
 ||119.123.221.5$document
 ||119.123.221.6$document
 ||119.123.221.74$document
+||119.123.221.94$document
 ||119.123.222.0$document
 ||119.123.222.112$document
 ||119.123.222.128$document
@@ -131459,6 +131547,7 @@
 ||119.123.239.109$document
 ||119.123.239.117$document
 ||119.123.239.122$document
+||119.123.239.131$document
 ||119.123.239.142$document
 ||119.123.239.153$document
 ||119.123.239.180$document
@@ -137600,6 +137689,7 @@
 ||120.57.214.195$document
 ||120.57.214.200$document
 ||120.57.214.223$document
+||120.57.214.228$document
 ||120.57.214.251$document
 ||120.57.214.38$document
 ||120.57.214.44$document
@@ -139452,6 +139542,7 @@
 ||120.6.233.250$document
 ||120.6.239.231$document
 ||120.6.240.130$document
+||120.6.241.130$document
 ||120.6.242.41$document
 ||120.6.248.88$document
 ||120.6.4.156$document
@@ -140464,6 +140555,7 @@
 ||120.85.196.179$document
 ||120.85.196.196$document
 ||120.85.196.205$document
+||120.85.196.211$document
 ||120.85.196.217$document
 ||120.85.196.220$document
 ||120.85.196.23$document
@@ -140563,6 +140655,7 @@
 ||120.85.199.91$document
 ||120.85.199.97$document
 ||120.85.208.103$document
+||120.85.208.107$document
 ||120.85.208.111$document
 ||120.85.208.114$document
 ||120.85.208.121$document
@@ -140741,6 +140834,7 @@
 ||120.85.238.0$document
 ||120.85.238.10$document
 ||120.85.238.107$document
+||120.85.238.129$document
 ||120.85.238.13$document
 ||120.85.238.137$document
 ||120.85.238.139$document
@@ -140757,6 +140851,7 @@
 ||120.85.238.218$document
 ||120.85.238.219$document
 ||120.85.238.233$document
+||120.85.238.238$document
 ||120.85.238.240$document
 ||120.85.238.244$document
 ||120.85.238.25$document
@@ -145415,6 +145510,7 @@
 ||123.11.125.93$document
 ||123.11.126.117$document
 ||123.11.126.2$document
+||123.11.126.225$document
 ||123.11.126.241$document
 ||123.11.126.62$document
 ||123.11.126.76$document
@@ -146832,6 +146928,7 @@
 ||123.11.62.73$document
 ||123.11.62.76$document
 ||123.11.63.112$document
+||123.11.63.113$document
 ||123.11.63.133$document
 ||123.11.63.170$document
 ||123.11.63.180$document
@@ -147456,6 +147553,7 @@
 ||123.12.185.95$document
 ||123.12.186.64$document
 ||123.12.187.224$document
+||123.12.189.247$document
 ||123.12.189.252$document
 ||123.12.189.93$document
 ||123.12.19.142$document
@@ -147567,6 +147665,7 @@
 ||123.12.225.250$document
 ||123.12.225.254$document
 ||123.12.225.62$document
+||123.12.225.70$document
 ||123.12.225.90$document
 ||123.12.225.94$document
 ||123.12.226.11$document
@@ -147907,6 +148006,7 @@
 ||123.12.243.76$document
 ||123.12.243.82$document
 ||123.12.243.83$document
+||123.12.243.85$document
 ||123.12.243.89$document
 ||123.12.243.95$document
 ||123.12.243.99$document
@@ -149465,6 +149565,7 @@
 ||123.130.254.2$document
 ||123.130.26.116$document
 ||123.130.27.172$document
+||123.130.27.19$document
 ||123.130.28.103$document
 ||123.130.28.105$document
 ||123.130.28.213$document
@@ -150430,6 +150531,7 @@
 ||123.14.127.174$document
 ||123.14.127.209$document
 ||123.14.127.219$document
+||123.14.127.238$document
 ||123.14.127.243$document
 ||123.14.127.250$document
 ||123.14.127.33$document
@@ -150772,6 +150874,7 @@
 ||123.14.173.130$document
 ||123.14.173.154$document
 ||123.14.173.159$document
+||123.14.173.199$document
 ||123.14.173.202$document
 ||123.14.173.218$document
 ||123.14.174.128$document
@@ -151260,6 +151363,7 @@
 ||123.14.249.250$document
 ||123.14.249.253$document
 ||123.14.249.30$document
+||123.14.249.33$document
 ||123.14.249.34$document
 ||123.14.249.38$document
 ||123.14.249.46$document
@@ -151512,6 +151616,7 @@
 ||123.14.34.184$document
 ||123.14.34.200$document
 ||123.14.34.222$document
+||123.14.34.240$document
 ||123.14.34.246$document
 ||123.14.34.36$document
 ||123.14.34.42$document
@@ -151567,6 +151672,7 @@
 ||123.14.37.215$document
 ||123.14.37.228$document
 ||123.14.37.231$document
+||123.14.37.32$document
 ||123.14.37.81$document
 ||123.14.38.0$document
 ||123.14.38.11$document
@@ -151714,6 +151820,7 @@
 ||123.14.50.184$document
 ||123.14.50.185$document
 ||123.14.50.207$document
+||123.14.50.214$document
 ||123.14.50.221$document
 ||123.14.50.251$document
 ||123.14.50.3$document
@@ -152494,6 +152601,7 @@
 ||123.153.59.88$document
 ||123.153.80.178$document
 ||123.153.88.252$document
+||123.154.116.116$document
 ||123.154.116.130$document
 ||123.154.116.155$document
 ||123.154.116.19$document
@@ -154354,6 +154462,7 @@
 ||123.4.194.144$document
 ||123.4.194.147$document
 ||123.4.194.15$document
+||123.4.194.152$document
 ||123.4.194.167$document
 ||123.4.194.173$document
 ||123.4.194.18$document
@@ -154566,6 +154675,7 @@
 ||123.4.213.128$document
 ||123.4.213.152$document
 ||123.4.213.169$document
+||123.4.213.239$document
 ||123.4.213.74$document
 ||123.4.213.83$document
 ||123.4.214.10$document
@@ -155118,6 +155228,7 @@
 ||123.4.45.112$document
 ||123.4.45.192$document
 ||123.4.45.221$document
+||123.4.45.31$document
 ||123.4.45.4$document
 ||123.4.45.7$document
 ||123.4.46.136$document
@@ -159756,6 +159867,7 @@
 ||123.8.71.235$document
 ||123.8.71.243$document
 ||123.8.71.246$document
+||123.8.71.27$document
 ||123.8.71.32$document
 ||123.8.71.7$document
 ||123.8.71.82$document
@@ -161028,6 +161140,7 @@
 ||123.9.239.80$document
 ||123.9.240.102$document
 ||123.9.240.103$document
+||123.9.240.115$document
 ||123.9.240.138$document
 ||123.9.240.146$document
 ||123.9.240.16$document
@@ -162387,6 +162500,7 @@
 ||124.131.136.92$document
 ||124.131.137.113$document
 ||124.131.137.137$document
+||124.131.137.147$document
 ||124.131.137.183$document
 ||124.131.137.190$document
 ||124.131.137.192$document
@@ -162747,6 +162861,7 @@
 ||124.131.23.131$document
 ||124.131.23.177$document
 ||124.131.239.254$document
+||124.131.24.185$document
 ||124.131.24.187$document
 ||124.131.24.219$document
 ||124.131.24.229$document
@@ -164137,6 +164252,7 @@
 ||124.92.133.100$document
 ||124.92.135.150$document
 ||124.92.135.30$document
+||124.92.135.37$document
 ||124.92.137.146$document
 ||124.92.137.71$document
 ||124.92.139.198$document
@@ -164380,6 +164496,7 @@
 ||125.106.44.171$document
 ||125.106.45.123$document
 ||125.106.45.200$document
+||125.106.46.225$document
 ||125.106.47.217$document
 ||125.106.48.237$document
 ||125.106.48.250$document
@@ -167521,6 +167638,7 @@
 ||125.41.164.56$document
 ||125.41.164.59$document
 ||125.41.164.6$document
+||125.41.164.60$document
 ||125.41.164.69$document
 ||125.41.164.92$document
 ||125.41.164.93$document
@@ -167716,6 +167834,7 @@
 ||125.41.184.230$document
 ||125.41.184.251$document
 ||125.41.185.110$document
+||125.41.185.186$document
 ||125.41.185.237$document
 ||125.41.185.252$document
 ||125.41.185.65$document
@@ -167874,6 +167993,7 @@
 ||125.41.191.8$document
 ||125.41.191.88$document
 ||125.41.196.104$document
+||125.41.196.114$document
 ||125.41.196.119$document
 ||125.41.196.128$document
 ||125.41.196.132$document
@@ -169762,6 +169882,7 @@
 ||125.41.97.224$document
 ||125.41.97.226$document
 ||125.41.97.228$document
+||125.41.97.231$document
 ||125.41.97.234$document
 ||125.41.97.237$document
 ||125.41.97.238$document
@@ -173148,6 +173269,7 @@
 ||125.43.6.111$document
 ||125.43.6.114$document
 ||125.43.6.138$document
+||125.43.6.186$document
 ||125.43.6.191$document
 ||125.43.6.204$document
 ||125.43.6.216$document
@@ -173242,6 +173364,7 @@
 ||125.43.63.252$document
 ||125.43.63.39$document
 ||125.43.63.46$document
+||125.43.63.47$document
 ||125.43.63.49$document
 ||125.43.63.50$document
 ||125.43.63.55$document
@@ -174995,6 +175118,7 @@
 ||125.44.207.72$document
 ||125.44.207.91$document
 ||125.44.207.97$document
+||125.44.208.152$document
 ||125.44.208.153$document
 ||125.44.208.164$document
 ||125.44.208.165$document
@@ -175473,6 +175597,7 @@
 ||125.44.227.242$document
 ||125.44.227.248$document
 ||125.44.227.4$document
+||125.44.227.51$document
 ||125.44.227.65$document
 ||125.44.227.69$document
 ||125.44.228.124$document
@@ -176416,6 +176541,7 @@
 ||125.44.70.28$document
 ||125.44.70.31$document
 ||125.44.70.5$document
+||125.44.70.64$document
 ||125.44.70.68$document
 ||125.44.70.87$document
 ||125.44.71.10$document
@@ -177128,6 +177254,7 @@
 ||125.45.43.19$document
 ||125.45.43.190$document
 ||125.45.43.209$document
+||125.45.43.63$document
 ||125.45.43.78$document
 ||125.45.48.101$document
 ||125.45.48.154$document
@@ -178195,6 +178322,7 @@
 ||125.46.165.83$document
 ||125.46.166.10$document
 ||125.46.166.101$document
+||125.46.166.112$document
 ||125.46.166.121$document
 ||125.46.166.123$document
 ||125.46.166.125$document
@@ -179427,6 +179555,7 @@
 ||125.47.124.60$document
 ||125.47.124.62$document
 ||125.47.125.129$document
+||125.47.125.16$document
 ||125.47.126.230$document
 ||125.47.126.53$document
 ||125.47.126.63$document
@@ -180396,6 +180525,7 @@
 ||125.47.248.117$document
 ||125.47.248.119$document
 ||125.47.248.124$document
+||125.47.248.131$document
 ||125.47.248.135$document
 ||125.47.248.141$document
 ||125.47.248.142$document
@@ -180902,9 +181032,11 @@
 ||125.47.37.56$document
 ||125.47.37.68$document
 ||125.47.38.10$document
+||125.47.38.114$document
 ||125.47.38.119$document
 ||125.47.38.124$document
 ||125.47.38.132$document
+||125.47.38.142$document
 ||125.47.38.152$document
 ||125.47.38.168$document
 ||125.47.38.17$document
@@ -181005,6 +181137,7 @@
 ||125.47.47.198$document
 ||125.47.47.209$document
 ||125.47.47.21$document
+||125.47.47.212$document
 ||125.47.47.217$document
 ||125.47.47.220$document
 ||125.47.47.233$document
@@ -183001,6 +183134,7 @@
 ||125.99.220.202$document
 ||125.99.220.216$document
 ||125.99.222.152$document
+||125.99.222.2$document
 ||125.99.222.245$document
 ||125.99.222.76$document
 ||125.99.223.227$document
@@ -185551,6 +185685,7 @@
 ||139.213.7.128$document
 ||139.213.7.230$document
 ||139.213.96.26$document
+||139.213.97.191$document
 ||139.213.97.23$document
 ||139.214.62.66$document
 ||139.214.62.96$document
@@ -185779,6 +185914,7 @@
 ||14.109.109.129$document
 ||14.109.111.219$document
 ||14.109.112.100$document
+||14.109.126.96$document
 ||14.113.12.153$document
 ||14.113.13.184$document
 ||14.113.14.145$document
@@ -186798,6 +186934,7 @@
 ||140.237.28.148$document
 ||140.237.29.28$document
 ||140.237.30.113$document
+||140.237.30.172$document
 ||140.237.30.179$document
 ||140.237.30.188$document
 ||140.237.31.197$document
@@ -187601,6 +187738,7 @@
 ||149.255.15.112$document
 ||149.255.15.121$document
 ||149.255.15.134$document
+||149.255.15.172$document
 ||149.255.15.180$document
 ||149.255.15.182$document
 ||149.255.15.184$document
@@ -190286,6 +190424,7 @@
 ||163.125.2.36$document
 ||163.125.2.67$document
 ||163.125.200.107$document
+||163.125.200.118$document
 ||163.125.200.126$document
 ||163.125.200.129$document
 ||163.125.200.13$document
@@ -190307,6 +190446,7 @@
 ||163.125.200.230$document
 ||163.125.200.233$document
 ||163.125.200.238$document
+||163.125.200.242$document
 ||163.125.200.247$document
 ||163.125.200.37$document
 ||163.125.200.40$document
@@ -190395,6 +190535,7 @@
 ||163.125.202.235$document
 ||163.125.202.245$document
 ||163.125.202.246$document
+||163.125.202.255$document
 ||163.125.202.27$document
 ||163.125.202.4$document
 ||163.125.202.57$document
@@ -190402,6 +190543,7 @@
 ||163.125.202.74$document
 ||163.125.202.8$document
 ||163.125.202.83$document
+||163.125.202.87$document
 ||163.125.202.9$document
 ||163.125.203.10$document
 ||163.125.203.118$document
@@ -190419,6 +190561,7 @@
 ||163.125.203.213$document
 ||163.125.203.214$document
 ||163.125.203.23$document
+||163.125.203.236$document
 ||163.125.203.32$document
 ||163.125.203.33$document
 ||163.125.203.4$document
@@ -190477,6 +190620,7 @@
 ||163.125.206.133$document
 ||163.125.206.145$document
 ||163.125.206.151$document
+||163.125.206.16$document
 ||163.125.206.162$document
 ||163.125.206.164$document
 ||163.125.206.187$document
@@ -190804,6 +190948,7 @@
 ||163.204.21.75$document
 ||163.204.210.243$document
 ||163.204.210.34$document
+||163.204.211.136$document
 ||163.204.211.205$document
 ||163.204.211.228$document
 ||163.204.211.47$document
@@ -191891,6 +192036,7 @@
 ||168.187.202.184$document
 ||168.187.234.86$document
 ||168.194.110.39$document
+||168.194.146.145$document
 ||168.194.176.180$document
 ||168.194.214.107$document
 ||168.194.214.113$document
@@ -192890,6 +193036,7 @@
 ||171.125.122.33$document
 ||171.125.122.54$document
 ||171.125.122.90$document
+||171.125.122.91$document
 ||171.125.123.88$document
 ||171.125.124.133$document
 ||171.125.124.58$document
@@ -193153,6 +193300,7 @@
 ||171.125.65.193$document
 ||171.125.65.202$document
 ||171.125.65.22$document
+||171.125.65.89$document
 ||171.125.66.6$document
 ||171.125.68.45$document
 ||171.125.7.181$document
@@ -198105,6 +198253,7 @@
 ||175.164.59.67$document
 ||175.164.6.45$document
 ||175.164.61.169$document
+||175.164.61.215$document
 ||175.164.63.75$document
 ||175.164.63.94$document
 ||175.164.66.17$document
@@ -198247,6 +198396,7 @@
 ||175.169.118.51$document
 ||175.169.127.142$document
 ||175.169.127.205$document
+||175.169.13.182$document
 ||175.169.15.220$document
 ||175.169.160.119$document
 ||175.169.163.231$document
@@ -201150,6 +201300,7 @@
 ||178.141.41.122$document
 ||178.141.41.125$document
 ||178.141.41.239$document
+||178.141.44.152$document
 ||178.141.44.159$document
 ||178.141.44.184$document
 ||178.141.44.21$document
@@ -201413,6 +201564,7 @@
 ||178.175.1.155$document
 ||178.175.1.157$document
 ||178.175.1.159$document
+||178.175.1.16$document
 ||178.175.1.161$document
 ||178.175.1.162$document
 ||178.175.1.164$document
@@ -201420,6 +201572,7 @@
 ||178.175.1.172$document
 ||178.175.1.174$document
 ||178.175.1.175$document
+||178.175.1.176$document
 ||178.175.1.178$document
 ||178.175.1.179$document
 ||178.175.1.182$document
@@ -201455,6 +201608,7 @@
 ||178.175.1.33$document
 ||178.175.1.34$document
 ||178.175.1.43$document
+||178.175.1.44$document
 ||178.175.1.46$document
 ||178.175.1.48$document
 ||178.175.1.5$document
@@ -201484,6 +201638,7 @@
 ||178.175.10.108$document
 ||178.175.10.113$document
 ||178.175.10.12$document
+||178.175.10.121$document
 ||178.175.10.124$document
 ||178.175.10.125$document
 ||178.175.10.133$document
@@ -201503,6 +201658,7 @@
 ||178.175.10.173$document
 ||178.175.10.175$document
 ||178.175.10.177$document
+||178.175.10.178$document
 ||178.175.10.182$document
 ||178.175.10.184$document
 ||178.175.10.186$document
@@ -201581,6 +201737,7 @@
 ||178.175.100.185$document
 ||178.175.100.187$document
 ||178.175.100.190$document
+||178.175.100.191$document
 ||178.175.100.193$document
 ||178.175.100.2$document
 ||178.175.100.201$document
@@ -201619,6 +201776,7 @@
 ||178.175.100.48$document
 ||178.175.100.49$document
 ||178.175.100.5$document
+||178.175.100.52$document
 ||178.175.100.54$document
 ||178.175.100.58$document
 ||178.175.100.61$document
@@ -201668,11 +201826,13 @@
 ||178.175.101.168$document
 ||178.175.101.170$document
 ||178.175.101.171$document
+||178.175.101.173$document
 ||178.175.101.174$document
 ||178.175.101.177$document
 ||178.175.101.186$document
 ||178.175.101.187$document
 ||178.175.101.189$document
+||178.175.101.191$document
 ||178.175.101.194$document
 ||178.175.101.196$document
 ||178.175.101.199$document
@@ -201884,8 +202044,10 @@
 ||178.175.103.233$document
 ||178.175.103.234$document
 ||178.175.103.239$document
+||178.175.103.24$document
 ||178.175.103.242$document
 ||178.175.103.245$document
+||178.175.103.246$document
 ||178.175.103.253$document
 ||178.175.103.26$document
 ||178.175.103.27$document
@@ -201951,6 +202113,7 @@
 ||178.175.104.145$document
 ||178.175.104.148$document
 ||178.175.104.15$document
+||178.175.104.151$document
 ||178.175.104.152$document
 ||178.175.104.153$document
 ||178.175.104.154$document
@@ -201959,6 +202122,7 @@
 ||178.175.104.16$document
 ||178.175.104.161$document
 ||178.175.104.163$document
+||178.175.104.166$document
 ||178.175.104.167$document
 ||178.175.104.169$document
 ||178.175.104.17$document
@@ -201978,6 +202142,7 @@
 ||178.175.104.195$document
 ||178.175.104.196$document
 ||178.175.104.198$document
+||178.175.104.199$document
 ||178.175.104.200$document
 ||178.175.104.202$document
 ||178.175.104.206$document
@@ -201991,6 +202156,7 @@
 ||178.175.104.230$document
 ||178.175.104.234$document
 ||178.175.104.235$document
+||178.175.104.239$document
 ||178.175.104.241$document
 ||178.175.104.243$document
 ||178.175.104.244$document
@@ -201999,6 +202165,7 @@
 ||178.175.104.252$document
 ||178.175.104.253$document
 ||178.175.104.255$document
+||178.175.104.26$document
 ||178.175.104.27$document
 ||178.175.104.29$document
 ||178.175.104.34$document
@@ -202076,6 +202243,7 @@
 ||178.175.105.208$document
 ||178.175.105.21$document
 ||178.175.105.213$document
+||178.175.105.214$document
 ||178.175.105.215$document
 ||178.175.105.217$document
 ||178.175.105.220$document
@@ -202084,6 +202252,7 @@
 ||178.175.105.235$document
 ||178.175.105.237$document
 ||178.175.105.238$document
+||178.175.105.240$document
 ||178.175.105.245$document
 ||178.175.105.247$document
 ||178.175.105.248$document
@@ -202125,6 +202294,7 @@
 ||178.175.105.93$document
 ||178.175.105.94$document
 ||178.175.105.96$document
+||178.175.105.99$document
 ||178.175.106.100$document
 ||178.175.106.102$document
 ||178.175.106.103$document
@@ -202144,6 +202314,7 @@
 ||178.175.106.136$document
 ||178.175.106.144$document
 ||178.175.106.146$document
+||178.175.106.149$document
 ||178.175.106.15$document
 ||178.175.106.154$document
 ||178.175.106.156$document
@@ -202205,6 +202376,7 @@
 ||178.175.106.28$document
 ||178.175.106.31$document
 ||178.175.106.32$document
+||178.175.106.36$document
 ||178.175.106.37$document
 ||178.175.106.42$document
 ||178.175.106.44$document
@@ -202224,6 +202396,7 @@
 ||178.175.106.78$document
 ||178.175.106.79$document
 ||178.175.106.8$document
+||178.175.106.83$document
 ||178.175.106.84$document
 ||178.175.106.87$document
 ||178.175.106.9$document
@@ -202575,6 +202748,7 @@
 ||178.175.11.149$document
 ||178.175.11.150$document
 ||178.175.11.154$document
+||178.175.11.155$document
 ||178.175.11.156$document
 ||178.175.11.157$document
 ||178.175.11.158$document
@@ -202608,6 +202782,7 @@
 ||178.175.11.23$document
 ||178.175.11.230$document
 ||178.175.11.235$document
+||178.175.11.241$document
 ||178.175.11.243$document
 ||178.175.11.244$document
 ||178.175.11.246$document
@@ -202692,6 +202867,7 @@
 ||178.175.110.190$document
 ||178.175.110.191$document
 ||178.175.110.192$document
+||178.175.110.194$document
 ||178.175.110.195$document
 ||178.175.110.197$document
 ||178.175.110.198$document
@@ -202842,6 +203018,7 @@
 ||178.175.112.103$document
 ||178.175.112.106$document
 ||178.175.112.109$document
+||178.175.112.110$document
 ||178.175.112.113$document
 ||178.175.112.114$document
 ||178.175.112.117$document
@@ -203071,6 +203248,7 @@
 ||178.175.114.123$document
 ||178.175.114.124$document
 ||178.175.114.125$document
+||178.175.114.127$document
 ||178.175.114.129$document
 ||178.175.114.13$document
 ||178.175.114.135$document
@@ -203281,6 +203459,7 @@
 ||178.175.116.1$document
 ||178.175.116.10$document
 ||178.175.116.100$document
+||178.175.116.101$document
 ||178.175.116.103$document
 ||178.175.116.104$document
 ||178.175.116.106$document
@@ -203307,6 +203486,7 @@
 ||178.175.116.159$document
 ||178.175.116.165$document
 ||178.175.116.169$document
+||178.175.116.170$document
 ||178.175.116.171$document
 ||178.175.116.174$document
 ||178.175.116.175$document
@@ -203787,6 +203967,7 @@
 ||178.175.12.78$document
 ||178.175.12.79$document
 ||178.175.12.91$document
+||178.175.12.93$document
 ||178.175.12.97$document
 ||178.175.120.100$document
 ||178.175.120.101$document
@@ -203868,6 +204049,7 @@
 ||178.175.120.44$document
 ||178.175.120.47$document
 ||178.175.120.49$document
+||178.175.120.5$document
 ||178.175.120.52$document
 ||178.175.120.57$document
 ||178.175.120.58$document
@@ -203920,6 +204102,8 @@
 ||178.175.121.180$document
 ||178.175.121.19$document
 ||178.175.121.190$document
+||178.175.121.192$document
+||178.175.121.193$document
 ||178.175.121.2$document
 ||178.175.121.202$document
 ||178.175.121.204$document
@@ -204161,6 +204345,7 @@
 ||178.175.123.247$document
 ||178.175.123.249$document
 ||178.175.123.255$document
+||178.175.123.26$document
 ||178.175.123.27$document
 ||178.175.123.29$document
 ||178.175.123.3$document
@@ -204581,6 +204766,7 @@
 ||178.175.127.214$document
 ||178.175.127.216$document
 ||178.175.127.217$document
+||178.175.127.219$document
 ||178.175.127.225$document
 ||178.175.127.228$document
 ||178.175.127.23$document
@@ -204603,6 +204789,7 @@
 ||178.175.127.35$document
 ||178.175.127.36$document
 ||178.175.127.38$document
+||178.175.127.43$document
 ||178.175.127.45$document
 ||178.175.127.46$document
 ||178.175.127.53$document
@@ -204626,6 +204813,7 @@
 ||178.175.127.91$document
 ||178.175.127.92$document
 ||178.175.127.95$document
+||178.175.127.97$document
 ||178.175.13.0$document
 ||178.175.13.1$document
 ||178.175.13.101$document
@@ -204720,6 +204908,7 @@
 ||178.175.14.126$document
 ||178.175.14.13$document
 ||178.175.14.130$document
+||178.175.14.131$document
 ||178.175.14.141$document
 ||178.175.14.144$document
 ||178.175.14.152$document
@@ -205047,6 +205236,7 @@
 ||178.175.17.62$document
 ||178.175.17.63$document
 ||178.175.17.64$document
+||178.175.17.66$document
 ||178.175.17.70$document
 ||178.175.17.74$document
 ||178.175.17.77$document
@@ -205259,6 +205449,7 @@
 ||178.175.2.18$document
 ||178.175.2.181$document
 ||178.175.2.184$document
+||178.175.2.186$document
 ||178.175.2.187$document
 ||178.175.2.188$document
 ||178.175.2.189$document
@@ -205413,6 +205604,7 @@
 ||178.175.20.87$document
 ||178.175.20.93$document
 ||178.175.20.96$document
+||178.175.20.97$document
 ||178.175.21.1$document
 ||178.175.21.110$document
 ||178.175.21.115$document
@@ -205610,6 +205802,7 @@
 ||178.175.23.184$document
 ||178.175.23.185$document
 ||178.175.23.187$document
+||178.175.23.19$document
 ||178.175.23.198$document
 ||178.175.23.199$document
 ||178.175.23.201$document
@@ -205702,6 +205895,7 @@
 ||178.175.24.189$document
 ||178.175.24.190$document
 ||178.175.24.191$document
+||178.175.24.198$document
 ||178.175.24.199$document
 ||178.175.24.200$document
 ||178.175.24.204$document
@@ -205975,6 +206169,7 @@
 ||178.175.27.122$document
 ||178.175.27.124$document
 ||178.175.27.125$document
+||178.175.27.137$document
 ||178.175.27.138$document
 ||178.175.27.14$document
 ||178.175.27.143$document
@@ -206027,6 +206222,7 @@
 ||178.175.27.239$document
 ||178.175.27.24$document
 ||178.175.27.241$document
+||178.175.27.244$document
 ||178.175.27.245$document
 ||178.175.27.246$document
 ||178.175.27.247$document
@@ -206115,6 +206311,7 @@
 ||178.175.28.198$document
 ||178.175.28.199$document
 ||178.175.28.20$document
+||178.175.28.200$document
 ||178.175.28.202$document
 ||178.175.28.205$document
 ||178.175.28.206$document
@@ -206140,6 +206337,7 @@
 ||178.175.28.4$document
 ||178.175.28.5$document
 ||178.175.28.50$document
+||178.175.28.51$document
 ||178.175.28.55$document
 ||178.175.28.59$document
 ||178.175.28.6$document
@@ -206147,6 +206345,7 @@
 ||178.175.28.64$document
 ||178.175.28.65$document
 ||178.175.28.66$document
+||178.175.28.69$document
 ||178.175.28.7$document
 ||178.175.28.72$document
 ||178.175.28.74$document
@@ -206196,6 +206395,7 @@
 ||178.175.29.204$document
 ||178.175.29.205$document
 ||178.175.29.207$document
+||178.175.29.208$document
 ||178.175.29.209$document
 ||178.175.29.219$document
 ||178.175.29.220$document
@@ -206232,6 +206432,7 @@
 ||178.175.29.55$document
 ||178.175.29.59$document
 ||178.175.29.6$document
+||178.175.29.7$document
 ||178.175.29.72$document
 ||178.175.29.73$document
 ||178.175.29.77$document
@@ -206308,6 +206509,7 @@
 ||178.175.3.28$document
 ||178.175.3.3$document
 ||178.175.3.31$document
+||178.175.3.32$document
 ||178.175.3.33$document
 ||178.175.3.34$document
 ||178.175.3.4$document
@@ -206320,6 +206522,7 @@
 ||178.175.3.58$document
 ||178.175.3.6$document
 ||178.175.3.62$document
+||178.175.3.66$document
 ||178.175.3.68$document
 ||178.175.3.69$document
 ||178.175.3.72$document
@@ -206329,6 +206532,7 @@
 ||178.175.3.80$document
 ||178.175.3.81$document
 ||178.175.3.85$document
+||178.175.3.87$document
 ||178.175.3.94$document
 ||178.175.3.98$document
 ||178.175.30.0$document
@@ -206487,6 +206691,7 @@
 ||178.175.31.247$document
 ||178.175.31.249$document
 ||178.175.31.251$document
+||178.175.31.252$document
 ||178.175.31.253$document
 ||178.175.31.29$document
 ||178.175.31.3$document
@@ -206518,6 +206723,7 @@
 ||178.175.31.94$document
 ||178.175.31.97$document
 ||178.175.31.98$document
+||178.175.31.99$document
 ||178.175.32.0$document
 ||178.175.32.1$document
 ||178.175.32.100$document
@@ -206537,6 +206743,7 @@
 ||178.175.32.133$document
 ||178.175.32.135$document
 ||178.175.32.138$document
+||178.175.32.14$document
 ||178.175.32.140$document
 ||178.175.32.141$document
 ||178.175.32.142$document
@@ -206586,6 +206793,7 @@
 ||178.175.32.24$document
 ||178.175.32.241$document
 ||178.175.32.243$document
+||178.175.32.244$document
 ||178.175.32.246$document
 ||178.175.32.248$document
 ||178.175.32.249$document
@@ -206657,6 +206865,7 @@
 ||178.175.33.186$document
 ||178.175.33.192$document
 ||178.175.33.193$document
+||178.175.33.196$document
 ||178.175.33.198$document
 ||178.175.33.2$document
 ||178.175.33.202$document
@@ -206682,6 +206891,7 @@
 ||178.175.33.241$document
 ||178.175.33.242$document
 ||178.175.33.244$document
+||178.175.33.245$document
 ||178.175.33.246$document
 ||178.175.33.255$document
 ||178.175.33.26$document
@@ -206900,6 +207110,7 @@
 ||178.175.35.85$document
 ||178.175.35.86$document
 ||178.175.35.89$document
+||178.175.35.91$document
 ||178.175.35.92$document
 ||178.175.35.93$document
 ||178.175.35.96$document
@@ -206982,6 +207193,7 @@
 ||178.175.36.37$document
 ||178.175.36.46$document
 ||178.175.36.47$document
+||178.175.36.5$document
 ||178.175.36.51$document
 ||178.175.36.52$document
 ||178.175.36.56$document
@@ -207100,6 +207312,7 @@
 ||178.175.37.67$document
 ||178.175.37.68$document
 ||178.175.37.70$document
+||178.175.37.71$document
 ||178.175.37.74$document
 ||178.175.37.75$document
 ||178.175.37.76$document
@@ -207219,6 +207432,7 @@
 ||178.175.39.106$document
 ||178.175.39.107$document
 ||178.175.39.11$document
+||178.175.39.110$document
 ||178.175.39.112$document
 ||178.175.39.113$document
 ||178.175.39.121$document
@@ -207289,6 +207503,7 @@
 ||178.175.39.57$document
 ||178.175.39.58$document
 ||178.175.39.61$document
+||178.175.39.63$document
 ||178.175.39.71$document
 ||178.175.39.74$document
 ||178.175.39.76$document
@@ -207536,6 +207751,7 @@
 ||178.175.41.217$document
 ||178.175.41.221$document
 ||178.175.41.223$document
+||178.175.41.224$document
 ||178.175.41.225$document
 ||178.175.41.229$document
 ||178.175.41.23$document
@@ -207624,9 +207840,11 @@
 ||178.175.42.228$document
 ||178.175.42.234$document
 ||178.175.42.235$document
+||178.175.42.240$document
 ||178.175.42.243$document
 ||178.175.42.245$document
 ||178.175.42.247$document
+||178.175.42.25$document
 ||178.175.42.253$document
 ||178.175.42.254$document
 ||178.175.42.255$document
@@ -207804,6 +208022,7 @@
 ||178.175.44.178$document
 ||178.175.44.179$document
 ||178.175.44.186$document
+||178.175.44.188$document
 ||178.175.44.19$document
 ||178.175.44.191$document
 ||178.175.44.194$document
@@ -207932,6 +208151,7 @@
 ||178.175.45.241$document
 ||178.175.45.244$document
 ||178.175.45.246$document
+||178.175.45.25$document
 ||178.175.45.250$document
 ||178.175.45.252$document
 ||178.175.45.253$document
@@ -208290,6 +208510,7 @@
 ||178.175.49.163$document
 ||178.175.49.166$document
 ||178.175.49.169$document
+||178.175.49.177$document
 ||178.175.49.18$document
 ||178.175.49.180$document
 ||178.175.49.185$document
@@ -208303,6 +208524,7 @@
 ||178.175.49.208$document
 ||178.175.49.21$document
 ||178.175.49.213$document
+||178.175.49.214$document
 ||178.175.49.215$document
 ||178.175.49.219$document
 ||178.175.49.221$document
@@ -208320,6 +208542,7 @@
 ||178.175.49.247$document
 ||178.175.49.248$document
 ||178.175.49.251$document
+||178.175.49.252$document
 ||178.175.49.253$document
 ||178.175.49.3$document
 ||178.175.49.31$document
@@ -208429,6 +208652,7 @@
 ||178.175.5.68$document
 ||178.175.5.70$document
 ||178.175.5.71$document
+||178.175.5.79$document
 ||178.175.5.84$document
 ||178.175.5.85$document
 ||178.175.5.88$document
@@ -208460,6 +208684,7 @@
 ||178.175.50.151$document
 ||178.175.50.152$document
 ||178.175.50.165$document
+||178.175.50.168$document
 ||178.175.50.169$document
 ||178.175.50.173$document
 ||178.175.50.174$document
@@ -208497,6 +208722,7 @@
 ||178.175.50.27$document
 ||178.175.50.28$document
 ||178.175.50.3$document
+||178.175.50.32$document
 ||178.175.50.33$document
 ||178.175.50.38$document
 ||178.175.50.40$document
@@ -208641,6 +208867,7 @@
 ||178.175.52.140$document
 ||178.175.52.141$document
 ||178.175.52.142$document
+||178.175.52.146$document
 ||178.175.52.149$document
 ||178.175.52.15$document
 ||178.175.52.153$document
@@ -208662,6 +208889,7 @@
 ||178.175.52.200$document
 ||178.175.52.205$document
 ||178.175.52.206$document
+||178.175.52.21$document
 ||178.175.52.211$document
 ||178.175.52.212$document
 ||178.175.52.216$document
@@ -208831,6 +209059,7 @@
 ||178.175.54.141$document
 ||178.175.54.142$document
 ||178.175.54.147$document
+||178.175.54.15$document
 ||178.175.54.150$document
 ||178.175.54.151$document
 ||178.175.54.154$document
@@ -208838,6 +209067,7 @@
 ||178.175.54.162$document
 ||178.175.54.163$document
 ||178.175.54.165$document
+||178.175.54.167$document
 ||178.175.54.172$document
 ||178.175.54.173$document
 ||178.175.54.178$document
@@ -209069,6 +209299,7 @@
 ||178.175.56.44$document
 ||178.175.56.48$document
 ||178.175.56.50$document
+||178.175.56.52$document
 ||178.175.56.54$document
 ||178.175.56.55$document
 ||178.175.56.57$document
@@ -209104,6 +209335,7 @@
 ||178.175.57.119$document
 ||178.175.57.12$document
 ||178.175.57.121$document
+||178.175.57.124$document
 ||178.175.57.126$document
 ||178.175.57.127$document
 ||178.175.57.129$document
@@ -209188,6 +209420,7 @@
 ||178.175.57.94$document
 ||178.175.57.95$document
 ||178.175.57.96$document
+||178.175.57.99$document
 ||178.175.58.100$document
 ||178.175.58.101$document
 ||178.175.58.105$document
@@ -209329,6 +209562,7 @@
 ||178.175.59.237$document
 ||178.175.59.238$document
 ||178.175.59.239$document
+||178.175.59.241$document
 ||178.175.59.243$document
 ||178.175.59.244$document
 ||178.175.59.245$document
@@ -209537,6 +209771,7 @@
 ||178.175.60.7$document
 ||178.175.60.70$document
 ||178.175.60.75$document
+||178.175.60.76$document
 ||178.175.60.79$document
 ||178.175.60.8$document
 ||178.175.60.80$document
@@ -209627,6 +209862,7 @@
 ||178.175.61.9$document
 ||178.175.61.90$document
 ||178.175.61.91$document
+||178.175.61.95$document
 ||178.175.61.96$document
 ||178.175.61.97$document
 ||178.175.62.1$document
@@ -209642,6 +209878,7 @@
 ||178.175.62.122$document
 ||178.175.62.123$document
 ||178.175.62.128$document
+||178.175.62.141$document
 ||178.175.62.143$document
 ||178.175.62.150$document
 ||178.175.62.151$document
@@ -209780,6 +210017,7 @@
 ||178.175.63.227$document
 ||178.175.63.228$document
 ||178.175.63.229$document
+||178.175.63.230$document
 ||178.175.63.231$document
 ||178.175.63.235$document
 ||178.175.63.239$document
@@ -209805,6 +210043,7 @@
 ||178.175.63.75$document
 ||178.175.63.76$document
 ||178.175.63.77$document
+||178.175.63.78$document
 ||178.175.63.80$document
 ||178.175.63.87$document
 ||178.175.63.88$document
@@ -209838,6 +210077,7 @@
 ||178.175.64.149$document
 ||178.175.64.151$document
 ||178.175.64.154$document
+||178.175.64.155$document
 ||178.175.64.156$document
 ||178.175.64.158$document
 ||178.175.64.163$document
@@ -209958,6 +210198,7 @@
 ||178.175.65.181$document
 ||178.175.65.184$document
 ||178.175.65.186$document
+||178.175.65.19$document
 ||178.175.65.192$document
 ||178.175.65.193$document
 ||178.175.65.194$document
@@ -210202,6 +210443,7 @@
 ||178.175.67.48$document
 ||178.175.67.51$document
 ||178.175.67.54$document
+||178.175.67.55$document
 ||178.175.67.59$document
 ||178.175.67.6$document
 ||178.175.67.60$document
@@ -210238,6 +210480,7 @@
 ||178.175.68.113$document
 ||178.175.68.114$document
 ||178.175.68.115$document
+||178.175.68.116$document
 ||178.175.68.121$document
 ||178.175.68.124$document
 ||178.175.68.125$document
@@ -210912,6 +211155,7 @@
 ||178.175.73.72$document
 ||178.175.73.76$document
 ||178.175.73.77$document
+||178.175.73.78$document
 ||178.175.73.86$document
 ||178.175.73.88$document
 ||178.175.73.89$document
@@ -210971,6 +211215,7 @@
 ||178.175.74.201$document
 ||178.175.74.203$document
 ||178.175.74.204$document
+||178.175.74.205$document
 ||178.175.74.206$document
 ||178.175.74.207$document
 ||178.175.74.21$document
@@ -210988,6 +211233,7 @@
 ||178.175.74.237$document
 ||178.175.74.238$document
 ||178.175.74.241$document
+||178.175.74.247$document
 ||178.175.74.251$document
 ||178.175.74.253$document
 ||178.175.74.30$document
@@ -211181,6 +211427,7 @@
 ||178.175.76.240$document
 ||178.175.76.241$document
 ||178.175.76.244$document
+||178.175.76.246$document
 ||178.175.76.248$document
 ||178.175.76.27$document
 ||178.175.76.29$document
@@ -211260,6 +211507,7 @@
 ||178.175.77.242$document
 ||178.175.77.244$document
 ||178.175.77.246$document
+||178.175.77.248$document
 ||178.175.77.250$document
 ||178.175.77.251$document
 ||178.175.77.252$document
@@ -211267,6 +211515,7 @@
 ||178.175.77.31$document
 ||178.175.77.32$document
 ||178.175.77.33$document
+||178.175.77.34$document
 ||178.175.77.37$document
 ||178.175.77.38$document
 ||178.175.77.40$document
@@ -211367,6 +211616,7 @@
 ||178.175.78.48$document
 ||178.175.78.50$document
 ||178.175.78.51$document
+||178.175.78.57$document
 ||178.175.78.58$document
 ||178.175.78.60$document
 ||178.175.78.64$document
@@ -211519,6 +211769,7 @@
 ||178.175.8.217$document
 ||178.175.8.223$document
 ||178.175.8.225$document
+||178.175.8.227$document
 ||178.175.8.233$document
 ||178.175.8.238$document
 ||178.175.8.24$document
@@ -211535,6 +211786,7 @@
 ||178.175.8.60$document
 ||178.175.8.61$document
 ||178.175.8.63$document
+||178.175.8.64$document
 ||178.175.8.67$document
 ||178.175.8.69$document
 ||178.175.8.72$document
@@ -211650,6 +211902,7 @@
 ||178.175.80.82$document
 ||178.175.80.86$document
 ||178.175.80.87$document
+||178.175.80.89$document
 ||178.175.80.90$document
 ||178.175.80.91$document
 ||178.175.80.92$document
@@ -211701,6 +211954,7 @@
 ||178.175.81.185$document
 ||178.175.81.186$document
 ||178.175.81.189$document
+||178.175.81.19$document
 ||178.175.81.192$document
 ||178.175.81.194$document
 ||178.175.81.197$document
@@ -211815,6 +212069,7 @@
 ||178.175.82.224$document
 ||178.175.82.226$document
 ||178.175.82.228$document
+||178.175.82.23$document
 ||178.175.82.230$document
 ||178.175.82.233$document
 ||178.175.82.235$document
@@ -211876,11 +212131,13 @@
 ||178.175.83.125$document
 ||178.175.83.130$document
 ||178.175.83.133$document
+||178.175.83.136$document
 ||178.175.83.137$document
 ||178.175.83.138$document
 ||178.175.83.139$document
 ||178.175.83.141$document
 ||178.175.83.143$document
+||178.175.83.144$document
 ||178.175.83.145$document
 ||178.175.83.147$document
 ||178.175.83.15$document
@@ -211997,6 +212254,7 @@
 ||178.175.84.158$document
 ||178.175.84.159$document
 ||178.175.84.16$document
+||178.175.84.17$document
 ||178.175.84.170$document
 ||178.175.84.178$document
 ||178.175.84.180$document
@@ -212450,10 +212708,12 @@
 ||178.175.88.230$document
 ||178.175.88.236$document
 ||178.175.88.237$document
+||178.175.88.24$document
 ||178.175.88.241$document
 ||178.175.88.242$document
 ||178.175.88.243$document
 ||178.175.88.246$document
+||178.175.88.248$document
 ||178.175.88.251$document
 ||178.175.88.253$document
 ||178.175.88.254$document
@@ -212554,6 +212814,7 @@
 ||178.175.89.25$document
 ||178.175.89.253$document
 ||178.175.89.28$document
+||178.175.89.30$document
 ||178.175.89.31$document
 ||178.175.89.33$document
 ||178.175.89.37$document
@@ -212691,6 +212952,7 @@
 ||178.175.90.177$document
 ||178.175.90.178$document
 ||178.175.90.179$document
+||178.175.90.185$document
 ||178.175.90.186$document
 ||178.175.90.187$document
 ||178.175.90.188$document
@@ -212745,6 +213007,7 @@
 ||178.175.90.79$document
 ||178.175.90.8$document
 ||178.175.90.80$document
+||178.175.90.81$document
 ||178.175.90.85$document
 ||178.175.90.89$document
 ||178.175.90.90$document
@@ -212937,6 +213200,7 @@
 ||178.175.92.42$document
 ||178.175.92.43$document
 ||178.175.92.45$document
+||178.175.92.48$document
 ||178.175.92.51$document
 ||178.175.92.54$document
 ||178.175.92.61$document
@@ -212997,6 +213261,7 @@
 ||178.175.93.196$document
 ||178.175.93.197$document
 ||178.175.93.198$document
+||178.175.93.199$document
 ||178.175.93.200$document
 ||178.175.93.202$document
 ||178.175.93.203$document
@@ -213188,6 +213453,7 @@
 ||178.175.95.154$document
 ||178.175.95.156$document
 ||178.175.95.158$document
+||178.175.95.163$document
 ||178.175.95.164$document
 ||178.175.95.165$document
 ||178.175.95.166$document
@@ -213289,6 +213555,7 @@
 ||178.175.96.169$document
 ||178.175.96.180$document
 ||178.175.96.181$document
+||178.175.96.187$document
 ||178.175.96.189$document
 ||178.175.96.192$document
 ||178.175.96.195$document
@@ -213340,6 +213607,7 @@
 ||178.175.96.70$document
 ||178.175.96.75$document
 ||178.175.96.8$document
+||178.175.96.81$document
 ||178.175.96.82$document
 ||178.175.96.88$document
 ||178.175.96.95$document
@@ -213408,6 +213676,7 @@
 ||178.175.97.219$document
 ||178.175.97.220$document
 ||178.175.97.224$document
+||178.175.97.225$document
 ||178.175.97.23$document
 ||178.175.97.230$document
 ||178.175.97.231$document
@@ -213472,6 +213741,7 @@
 ||178.175.98.205$document
 ||178.175.98.206$document
 ||178.175.98.207$document
+||178.175.98.216$document
 ||178.175.98.217$document
 ||178.175.98.221$document
 ||178.175.98.224$document
@@ -214142,6 +214412,7 @@
 ||178.95.195.240$document
 ||178.95.197.16$document
 ||178.95.197.55$document
+||178.95.197.91$document
 ||178.95.198.146$document
 ||178.95.199.144$document
 ||178.95.199.175$document
@@ -214463,6 +214734,7 @@
 ||179.42.107.127$document
 ||179.42.107.128$document
 ||179.42.107.137$document
+||179.42.107.139$document
 ||179.42.107.141$document
 ||179.42.107.144$document
 ||179.42.107.149$document
@@ -215828,6 +216100,7 @@
 ||180.188.224.104$document
 ||180.188.236.174$document
 ||180.188.236.247$document
+||180.188.236.32$document
 ||180.188.236.9$document
 ||180.188.241.111$document
 ||180.188.241.115$document
@@ -216012,6 +216285,7 @@
 ||180.253.17.128$document
 ||180.253.191.125$document
 ||180.253.27.248$document
+||180.253.99.109$document
 ||180.254.167.231$document
 ||180.254.241.245$document
 ||180.254.53.113$document
@@ -217190,6 +217464,7 @@
 ||182.112.28.104$document
 ||182.112.28.108$document
 ||182.112.28.116$document
+||182.112.28.118$document
 ||182.112.28.122$document
 ||182.112.28.123$document
 ||182.112.28.13$document
@@ -217424,6 +217699,7 @@
 ||182.112.34.187$document
 ||182.112.34.20$document
 ||182.112.34.202$document
+||182.112.34.220$document
 ||182.112.34.233$document
 ||182.112.34.25$document
 ||182.112.34.34$document
@@ -219677,6 +219953,7 @@
 ||182.113.238.135$document
 ||182.113.238.136$document
 ||182.113.238.165$document
+||182.113.238.197$document
 ||182.113.238.199$document
 ||182.113.238.20$document
 ||182.113.238.28$document
@@ -219871,6 +220148,7 @@
 ||182.113.29.230$document
 ||182.113.29.241$document
 ||182.113.29.245$document
+||182.113.29.28$document
 ||182.113.29.44$document
 ||182.113.29.46$document
 ||182.113.29.54$document
@@ -221882,6 +222160,7 @@
 ||182.114.76.254$document
 ||182.114.76.39$document
 ||182.114.76.41$document
+||182.114.76.42$document
 ||182.114.76.50$document
 ||182.114.76.67$document
 ||182.114.76.81$document
@@ -223932,6 +224211,7 @@
 ||182.116.116.61$document
 ||182.116.116.64$document
 ||182.116.116.68$document
+||182.116.116.70$document
 ||182.116.116.73$document
 ||182.116.116.75$document
 ||182.116.116.76$document
@@ -224108,6 +224388,7 @@
 ||182.116.119.53$document
 ||182.116.119.56$document
 ||182.116.119.59$document
+||182.116.119.66$document
 ||182.116.119.68$document
 ||182.116.119.7$document
 ||182.116.119.74$document
@@ -224294,6 +224575,7 @@
 ||182.116.36.149$document
 ||182.116.36.15$document
 ||182.116.36.174$document
+||182.116.36.175$document
 ||182.116.36.180$document
 ||182.116.36.195$document
 ||182.116.36.199$document
@@ -226604,6 +226886,7 @@
 ||182.117.13.21$document
 ||182.117.13.32$document
 ||182.117.13.4$document
+||182.117.13.57$document
 ||182.117.13.71$document
 ||182.117.13.73$document
 ||182.117.13.75$document
@@ -229972,6 +230255,7 @@
 ||182.118.164.227$document
 ||182.118.164.248$document
 ||182.118.165.190$document
+||182.118.166.128$document
 ||182.118.166.153$document
 ||182.118.166.36$document
 ||182.118.166.82$document
@@ -230715,6 +230999,7 @@
 ||182.119.15.63$document
 ||182.119.15.68$document
 ||182.119.15.70$document
+||182.119.15.78$document
 ||182.119.15.81$document
 ||182.119.15.86$document
 ||182.119.15.91$document
@@ -230975,6 +231260,7 @@
 ||182.119.166.4$document
 ||182.119.166.64$document
 ||182.119.166.72$document
+||182.119.166.76$document
 ||182.119.166.84$document
 ||182.119.166.9$document
 ||182.119.166.94$document
@@ -231140,6 +231426,7 @@
 ||182.119.179.130$document
 ||182.119.179.169$document
 ||182.119.179.17$document
+||182.119.179.193$document
 ||182.119.179.199$document
 ||182.119.179.202$document
 ||182.119.179.230$document
@@ -231518,6 +231805,7 @@
 ||182.119.196.160$document
 ||182.119.196.182$document
 ||182.119.196.190$document
+||182.119.197.123$document
 ||182.119.199.158$document
 ||182.119.199.85$document
 ||182.119.2.110$document
@@ -231618,6 +231906,7 @@
 ||182.119.202.159$document
 ||182.119.202.170$document
 ||182.119.202.179$document
+||182.119.202.180$document
 ||182.119.202.189$document
 ||182.119.202.20$document
 ||182.119.202.201$document
@@ -231818,6 +232107,7 @@
 ||182.119.21.39$document
 ||182.119.21.46$document
 ||182.119.21.54$document
+||182.119.21.68$document
 ||182.119.21.76$document
 ||182.119.21.79$document
 ||182.119.21.81$document
@@ -233461,6 +233751,7 @@
 ||182.119.88.4$document
 ||182.119.88.54$document
 ||182.119.88.88$document
+||182.119.89.107$document
 ||182.119.89.11$document
 ||182.119.89.123$document
 ||182.119.89.126$document
@@ -236311,6 +236602,7 @@
 ||182.121.15.199$document
 ||182.121.15.203$document
 ||182.121.15.219$document
+||182.121.15.223$document
 ||182.121.15.227$document
 ||182.121.15.237$document
 ||182.121.15.252$document
@@ -238191,6 +238483,7 @@
 ||182.121.254.117$document
 ||182.121.254.127$document
 ||182.121.254.132$document
+||182.121.254.147$document
 ||182.121.254.15$document
 ||182.121.254.152$document
 ||182.121.254.198$document
@@ -239237,6 +239530,7 @@
 ||182.121.54.8$document
 ||182.121.54.81$document
 ||182.121.54.95$document
+||182.121.55.106$document
 ||182.121.55.109$document
 ||182.121.55.112$document
 ||182.121.55.122$document
@@ -241957,6 +242251,7 @@
 ||182.123.241.130$document
 ||182.123.241.172$document
 ||182.123.241.173$document
+||182.123.241.195$document
 ||182.123.241.200$document
 ||182.123.241.214$document
 ||182.123.241.23$document
@@ -242767,6 +243062,7 @@
 ||182.124.200.94$document
 ||182.124.201.176$document
 ||182.124.201.186$document
+||182.124.201.207$document
 ||182.124.201.222$document
 ||182.124.202.211$document
 ||182.124.202.241$document
@@ -244288,6 +244584,7 @@
 ||182.126.123.185$document
 ||182.126.123.188$document
 ||182.126.123.189$document
+||182.126.123.19$document
 ||182.126.123.191$document
 ||182.126.123.193$document
 ||182.126.123.199$document
@@ -246549,6 +246846,7 @@
 ||182.127.106.176$document
 ||182.127.106.216$document
 ||182.127.106.217$document
+||182.127.106.43$document
 ||182.127.106.5$document
 ||182.127.106.53$document
 ||182.127.106.57$document
@@ -249995,6 +250293,7 @@
 ||182.127.93.229$document
 ||182.127.93.230$document
 ||182.127.93.35$document
+||182.127.93.38$document
 ||182.127.93.39$document
 ||182.127.93.4$document
 ||182.127.93.42$document
@@ -250442,6 +250741,7 @@
 ||182.245.26.132$document
 ||182.245.26.171$document
 ||182.245.27.165$document
+||182.245.28.162$document
 ||182.245.28.80$document
 ||182.245.34.249$document
 ||182.245.34.32$document
@@ -251107,6 +251407,7 @@
 ||182.56.192.77$document
 ||182.56.193.147$document
 ||182.56.193.161$document
+||182.56.193.251$document
 ||182.56.193.26$document
 ||182.56.193.39$document
 ||182.56.193.46$document
@@ -255725,6 +256026,7 @@
 ||182.59.222.42$document
 ||182.59.222.60$document
 ||182.59.222.96$document
+||182.59.223.113$document
 ||182.59.223.124$document
 ||182.59.223.127$document
 ||182.59.223.131$document
@@ -255916,6 +256218,7 @@
 ||182.59.235.100$document
 ||182.59.235.107$document
 ||182.59.235.121$document
+||182.59.235.150$document
 ||182.59.235.151$document
 ||182.59.235.157$document
 ||182.59.235.164$document
@@ -258274,6 +258577,7 @@
 ||183.185.113.113$document
 ||183.185.115.92$document
 ||183.185.125.227$document
+||183.185.162.225$document
 ||183.185.168.107$document
 ||183.185.168.165$document
 ||183.185.169.102$document
@@ -258668,6 +258972,7 @@
 ||183.188.90.55$document
 ||183.188.91.12$document
 ||183.188.92.208$document
+||183.188.93.116$document
 ||183.188.93.21$document
 ||183.188.94.13$document
 ||183.188.94.195$document
@@ -262177,6 +262482,7 @@
 ||186.33.112.208$document
 ||186.33.112.209$document
 ||186.33.112.210$document
+||186.33.112.211$document
 ||186.33.112.214$document
 ||186.33.112.216$document
 ||186.33.112.218$document
@@ -262264,6 +262570,7 @@
 ||186.33.112.95$document
 ||186.33.112.96$document
 ||186.33.112.97$document
+||186.33.113.137$document
 ||186.33.113.2$document
 ||186.33.113.241$document
 ||186.33.113.5$document
@@ -263546,6 +263853,7 @@
 ||188.116.36.88$document
 ||188.119.112.125$document
 ||188.119.120.135$document
+||188.119.45.194$document
 ||188.119.45.205$document
 ||188.119.49.1$document
 ||188.119.58.176$document
@@ -265890,6 +266198,7 @@
 ||190.72.32.132$document
 ||190.72.62.232$document
 ||190.73.101.231$document
+||190.73.12.149$document
 ||190.73.71.174$document
 ||190.74.22.100$document
 ||190.75.113.109$document
@@ -267086,6 +267395,7 @@
 ||193.38.55.126$document
 ||193.38.55.59$document
 ||193.38.55.73$document
+||193.38.55.9$document
 ||193.39.185.202$document
 ||193.39.185.207$document
 ||193.39.185.214$document
@@ -269616,6 +269926,7 @@
 ||2.68.190.234$document
 ||2.68.192.214$document
 ||2.68.234.169$document
+||2.68.59.23$document
 ||2.68.78.147$document
 ||2.82.200.218$document
 ||2.82.28.27$document
@@ -270901,6 +271212,7 @@
 ||202.164.139.120$document
 ||202.164.139.121$document
 ||202.164.139.123$document
+||202.164.139.124$document
 ||202.164.139.125$document
 ||202.164.139.127$document
 ||202.164.139.128$document
@@ -270995,6 +271307,7 @@
 ||202.164.139.243$document
 ||202.164.139.246$document
 ||202.164.139.247$document
+||202.164.139.248$document
 ||202.164.139.249$document
 ||202.164.139.25$document
 ||202.164.139.252$document
@@ -275338,6 +275651,7 @@
 ||209.133.223.130$document
 ||209.14.30.109$document
 ||209.14.30.121$document
+||209.14.30.132$document
 ||209.14.30.135$document
 ||209.14.30.136$document
 ||209.14.30.156$document
@@ -275349,6 +275663,7 @@
 ||209.14.30.205$document
 ||209.14.30.30$document
 ||209.14.30.54$document
+||209.14.31.111$document
 ||209.14.31.125$document
 ||209.14.31.162$document
 ||209.14.31.163$document
@@ -278065,6 +278380,7 @@
 ||218.32.118.1$document
 ||218.32.118.185$document
 ||218.32.124.170$document
+||218.32.96.158$document
 ||218.32.98.172$document
 ||218.35.198.109$document
 ||218.35.205.235$document
@@ -278163,6 +278479,7 @@
 ||218.57.107.48$document
 ||218.57.109.101$document
 ||218.57.109.155$document
+||218.57.109.48$document
 ||218.57.109.58$document
 ||218.57.115.102$document
 ||218.57.115.124$document
@@ -279709,6 +280026,7 @@
 ||219.154.116.154$document
 ||219.154.116.156$document
 ||219.154.116.166$document
+||219.154.116.168$document
 ||219.154.116.17$document
 ||219.154.116.171$document
 ||219.154.116.185$document
@@ -280362,6 +280680,7 @@
 ||219.154.142.196$document
 ||219.154.142.210$document
 ||219.154.142.239$document
+||219.154.142.35$document
 ||219.154.142.4$document
 ||219.154.142.41$document
 ||219.154.142.43$document
@@ -280497,6 +280816,7 @@
 ||219.154.176.189$document
 ||219.154.176.24$document
 ||219.154.177.205$document
+||219.154.178.138$document
 ||219.154.178.175$document
 ||219.154.178.69$document
 ||219.154.178.72$document
@@ -280705,6 +281025,7 @@
 ||219.154.41.137$document
 ||219.154.41.183$document
 ||219.154.41.31$document
+||219.154.41.36$document
 ||219.154.41.51$document
 ||219.154.42.109$document
 ||219.154.42.121$document
@@ -281014,6 +281335,7 @@
 ||219.155.11.212$document
 ||219.155.11.220$document
 ||219.155.11.240$document
+||219.155.11.252$document
 ||219.155.11.28$document
 ||219.155.11.36$document
 ||219.155.11.41$document
@@ -281652,6 +281974,7 @@
 ||219.155.209.230$document
 ||219.155.209.232$document
 ||219.155.209.25$document
+||219.155.209.253$document
 ||219.155.209.35$document
 ||219.155.209.54$document
 ||219.155.209.74$document
@@ -283024,6 +283347,7 @@
 ||219.155.86.128$document
 ||219.155.86.136$document
 ||219.155.86.145$document
+||219.155.86.156$document
 ||219.155.86.17$document
 ||219.155.86.182$document
 ||219.155.86.191$document
@@ -283854,6 +284178,7 @@
 ||219.156.175.190$document
 ||219.156.175.225$document
 ||219.156.176.129$document
+||219.156.176.153$document
 ||219.156.176.184$document
 ||219.156.176.20$document
 ||219.156.176.64$document
@@ -283864,6 +284189,7 @@
 ||219.156.177.212$document
 ||219.156.177.232$document
 ||219.156.177.71$document
+||219.156.178.130$document
 ||219.156.178.133$document
 ||219.156.178.137$document
 ||219.156.178.179$document
@@ -284514,6 +284840,7 @@
 ||219.156.65.250$document
 ||219.156.65.251$document
 ||219.156.65.27$document
+||219.156.65.47$document
 ||219.156.65.48$document
 ||219.156.65.70$document
 ||219.156.65.71$document
@@ -286178,6 +286505,7 @@
 ||219.157.214.216$document
 ||219.157.214.22$document
 ||219.157.214.221$document
+||219.157.214.235$document
 ||219.157.214.236$document
 ||219.157.214.24$document
 ||219.157.214.31$document
@@ -289990,6 +290318,7 @@
 ||221.13.191.75$document
 ||221.13.191.91$document
 ||221.13.208.118$document
+||221.13.208.159$document
 ||221.13.208.8$document
 ||221.13.210.251$document
 ||221.13.211.121$document
@@ -290739,6 +291068,7 @@
 ||221.14.184.24$document
 ||221.14.184.32$document
 ||221.14.184.76$document
+||221.14.185.105$document
 ||221.14.185.112$document
 ||221.14.185.157$document
 ||221.14.185.4$document
@@ -290860,6 +291190,7 @@
 ||221.14.46.48$document
 ||221.14.47.162$document
 ||221.14.47.182$document
+||221.14.47.189$document
 ||221.14.47.46$document
 ||221.14.47.77$document
 ||221.14.47.82$document
@@ -290868,6 +291199,7 @@
 ||221.14.56.169$document
 ||221.14.56.252$document
 ||221.14.56.67$document
+||221.14.57.175$document
 ||221.14.57.62$document
 ||221.14.58.27$document
 ||221.14.58.5$document
@@ -291019,6 +291351,7 @@
 ||221.15.111.49$document
 ||221.15.111.82$document
 ||221.15.111.96$document
+||221.15.112.103$document
 ||221.15.112.186$document
 ||221.15.112.203$document
 ||221.15.112.220$document
@@ -291660,6 +291993,7 @@
 ||221.15.155.179$document
 ||221.15.155.180$document
 ||221.15.155.184$document
+||221.15.155.186$document
 ||221.15.155.194$document
 ||221.15.155.197$document
 ||221.15.155.199$document
@@ -292395,6 +292729,7 @@
 ||221.15.190.179$document
 ||221.15.190.18$document
 ||221.15.190.188$document
+||221.15.190.2$document
 ||221.15.190.232$document
 ||221.15.190.234$document
 ||221.15.190.247$document
@@ -294674,6 +295009,7 @@
 ||221.201.54.42$document
 ||221.201.54.97$document
 ||221.202.232.175$document
+||221.202.232.230$document
 ||221.202.232.5$document
 ||221.202.234.170$document
 ||221.202.235.198$document
@@ -294968,6 +295304,7 @@
 ||221.214.249.112$document
 ||221.214.249.181$document
 ||221.214.249.199$document
+||221.214.251.109$document
 ||221.214.251.162$document
 ||221.214.251.91$document
 ||221.214.254.15$document
@@ -296727,6 +297064,7 @@
 ||222.136.76.154$document
 ||222.136.76.84$document
 ||222.136.77.141$document
+||222.136.77.190$document
 ||222.136.77.3$document
 ||222.136.77.91$document
 ||222.136.78.29$document
@@ -298114,6 +298452,7 @@
 ||222.137.161.73$document
 ||222.137.161.8$document
 ||222.137.161.85$document
+||222.137.161.88$document
 ||222.137.161.91$document
 ||222.137.161.95$document
 ||222.137.161.96$document
@@ -299290,6 +299629,7 @@
 ||222.137.220.204$document
 ||222.137.220.207$document
 ||222.137.220.212$document
+||222.137.220.215$document
 ||222.137.220.219$document
 ||222.137.220.226$document
 ||222.137.220.244$document
@@ -299499,6 +299839,7 @@
 ||222.137.237.181$document
 ||222.137.237.187$document
 ||222.137.237.190$document
+||222.137.237.203$document
 ||222.137.237.208$document
 ||222.137.237.212$document
 ||222.137.237.217$document
@@ -299981,6 +300322,7 @@
 ||222.137.53.125$document
 ||222.137.53.191$document
 ||222.137.53.192$document
+||222.137.53.193$document
 ||222.137.53.229$document
 ||222.137.53.242$document
 ||222.137.53.255$document
@@ -300893,6 +301235,7 @@
 ||222.138.118.186$document
 ||222.138.118.190$document
 ||222.138.118.191$document
+||222.138.118.192$document
 ||222.138.118.195$document
 ||222.138.118.196$document
 ||222.138.118.2$document
@@ -301755,6 +302098,7 @@
 ||222.138.183.111$document
 ||222.138.183.116$document
 ||222.138.183.117$document
+||222.138.183.120$document
 ||222.138.183.123$document
 ||222.138.183.126$document
 ||222.138.183.129$document
@@ -302147,6 +302491,7 @@
 ||222.138.213.192$document
 ||222.138.213.202$document
 ||222.138.213.219$document
+||222.138.213.235$document
 ||222.138.213.239$document
 ||222.138.213.245$document
 ||222.138.213.31$document
@@ -302776,6 +303121,7 @@
 ||222.138.50.32$document
 ||222.138.50.50$document
 ||222.138.50.75$document
+||222.138.51.203$document
 ||222.138.51.69$document
 ||222.138.52.108$document
 ||222.138.52.200$document
@@ -303026,6 +303372,7 @@
 ||222.139.106.121$document
 ||222.139.106.154$document
 ||222.139.106.230$document
+||222.139.106.55$document
 ||222.139.107.10$document
 ||222.139.107.113$document
 ||222.139.107.137$document
@@ -304552,6 +304899,7 @@
 ||222.140.179.11$document
 ||222.140.179.120$document
 ||222.140.179.14$document
+||222.140.179.142$document
 ||222.140.179.16$document
 ||222.140.179.168$document
 ||222.140.179.178$document
@@ -304791,6 +305139,7 @@
 ||222.140.207.76$document
 ||222.140.207.85$document
 ||222.140.208.132$document
+||222.140.208.18$document
 ||222.140.208.205$document
 ||222.140.208.219$document
 ||222.140.208.45$document
@@ -305111,6 +305460,7 @@
 ||222.141.101.240$document
 ||222.141.101.251$document
 ||222.141.101.254$document
+||222.141.101.39$document
 ||222.141.101.55$document
 ||222.141.101.87$document
 ||222.141.101.92$document
@@ -306134,6 +306484,7 @@
 ||222.141.40.47$document
 ||222.141.40.58$document
 ||222.141.40.65$document
+||222.141.40.69$document
 ||222.141.40.7$document
 ||222.141.40.73$document
 ||222.141.40.75$document
@@ -308422,6 +308773,7 @@
 ||222.81.155.83$document
 ||222.81.155.88$document
 ||222.81.156.100$document
+||222.81.156.229$document
 ||222.81.157.146$document
 ||222.81.157.148$document
 ||222.81.157.177$document
@@ -309914,6 +310266,7 @@
 ||27.153.140.109$document
 ||27.153.141.43$document
 ||27.153.141.80$document
+||27.153.142.115$document
 ||27.153.142.228$document
 ||27.153.142.44$document
 ||27.153.143.113$document
@@ -313911,6 +314264,7 @@
 ||27.208.200.128$document
 ||27.208.200.67$document
 ||27.208.201.212$document
+||27.208.202.165$document
 ||27.208.202.25$document
 ||27.208.203.172$document
 ||27.208.205.119$document
@@ -313961,6 +314315,7 @@
 ||27.208.55.230$document
 ||27.208.55.65$document
 ||27.208.63.93$document
+||27.208.70.115$document
 ||27.208.70.207$document
 ||27.208.72.67$document
 ||27.208.76.142$document
@@ -315016,6 +315371,7 @@
 ||27.213.165.198$document
 ||27.213.166.136$document
 ||27.213.166.174$document
+||27.213.166.50$document
 ||27.213.167.154$document
 ||27.213.167.175$document
 ||27.213.167.180$document
@@ -315740,6 +316096,7 @@
 ||27.215.253.149$document
 ||27.215.254.134$document
 ||27.215.255.209$document
+||27.215.27.143$document
 ||27.215.28.105$document
 ||27.215.28.45$document
 ||27.215.3.1$document
@@ -320118,6 +320475,7 @@
 ||27.41.159.205$document
 ||27.41.159.216$document
 ||27.41.159.26$document
+||27.41.159.28$document
 ||27.41.159.33$document
 ||27.41.159.58$document
 ||27.41.159.76$document
@@ -320867,6 +321225,7 @@
 ||27.41.37.128$document
 ||27.41.37.131$document
 ||27.41.37.133$document
+||27.41.37.155$document
 ||27.41.37.171$document
 ||27.41.37.180$document
 ||27.41.37.187$document
@@ -321015,6 +321374,7 @@
 ||27.41.89.195$document
 ||27.41.89.50$document
 ||27.41.89.89$document
+||27.41.9.105$document
 ||27.41.9.113$document
 ||27.41.9.130$document
 ||27.41.9.135$document
@@ -321067,6 +321427,7 @@
 ||27.41.97.172$document
 ||27.41.97.191$document
 ||27.41.97.2$document
+||27.41.97.36$document
 ||27.41.97.40$document
 ||27.41.97.6$document
 ||27.41.97.94$document
@@ -321101,10 +321462,12 @@
 ||27.43.105.64$document
 ||27.43.106.242$document
 ||27.43.107.181$document
+||27.43.108.78$document
 ||27.43.109.21$document
 ||27.43.110.101$document
 ||27.43.110.185$document
 ||27.43.110.198$document
+||27.43.111.161$document
 ||27.43.111.217$document
 ||27.43.111.46$document
 ||27.43.115.108$document
@@ -321116,6 +321479,7 @@
 ||27.43.116.9$document
 ||27.43.116.96$document
 ||27.43.117.15$document
+||27.43.117.66$document
 ||27.43.117.89$document
 ||27.43.118.111$document
 ||27.43.118.150$document
@@ -321247,6 +321611,7 @@
 ||27.46.22.67$document
 ||27.46.22.83$document
 ||27.46.22.9$document
+||27.46.23.10$document
 ||27.46.23.123$document
 ||27.46.23.181$document
 ||27.46.23.188$document
@@ -321292,6 +321657,7 @@
 ||27.46.44.233$document
 ||27.46.44.235$document
 ||27.46.44.237$document
+||27.46.44.239$document
 ||27.46.44.246$document
 ||27.46.44.254$document
 ||27.46.44.31$document
@@ -321351,6 +321717,7 @@
 ||27.46.45.7$document
 ||27.46.45.82$document
 ||27.46.45.85$document
+||27.46.45.86$document
 ||27.46.45.88$document
 ||27.46.45.89$document
 ||27.46.45.90$document
@@ -322771,6 +323138,7 @@
 ||27.5.30.70$document
 ||27.5.30.71$document
 ||27.5.30.72$document
+||27.5.30.79$document
 ||27.5.30.81$document
 ||27.5.30.82$document
 ||27.5.30.87$document
@@ -323230,6 +323598,7 @@
 ||27.5.36.221$document
 ||27.5.36.222$document
 ||27.5.36.230$document
+||27.5.36.232$document
 ||27.5.36.233$document
 ||27.5.36.234$document
 ||27.5.36.238$document
@@ -323745,6 +324114,7 @@
 ||27.5.41.143$document
 ||27.5.41.144$document
 ||27.5.41.145$document
+||27.5.41.146$document
 ||27.5.41.148$document
 ||27.5.41.149$document
 ||27.5.41.155$document
@@ -326260,6 +326630,7 @@
 ||27.6.122.19$document
 ||27.6.122.192$document
 ||27.6.122.193$document
+||27.6.122.194$document
 ||27.6.122.197$document
 ||27.6.122.2$document
 ||27.6.122.202$document
@@ -331762,6 +332133,7 @@
 ||27.6.240.156$document
 ||27.6.240.161$document
 ||27.6.240.169$document
+||27.6.240.171$document
 ||27.6.240.175$document
 ||27.6.240.181$document
 ||27.6.240.183$document
@@ -331983,6 +332355,7 @@
 ||27.6.243.113$document
 ||27.6.243.117$document
 ||27.6.243.12$document
+||27.6.243.122$document
 ||27.6.243.126$document
 ||27.6.243.127$document
 ||27.6.243.128$document
@@ -332672,6 +333045,7 @@
 ||27.6.34.217$document
 ||27.6.34.60$document
 ||27.6.38.222$document
+||27.6.38.96$document
 ||27.6.4.101$document
 ||27.6.4.102$document
 ||27.6.4.106$document
@@ -345138,6 +345512,7 @@
 ||36.251.18.2$document
 ||36.251.18.40$document
 ||36.251.18.44$document
+||36.251.18.63$document
 ||36.251.19.213$document
 ||36.251.19.231$document
 ||36.251.19.249$document
@@ -345742,6 +346117,7 @@
 ||36.42.107.77$document
 ||36.42.107.99$document
 ||36.43.10.121$document
+||36.43.11.16$document
 ||36.43.11.211$document
 ||36.43.12.163$document
 ||36.43.64.10$document
@@ -345879,6 +346255,7 @@
 ||36.81.158.24$document
 ||36.81.187.39$document
 ||36.81.209.186$document
+||36.81.23.38$document
 ||36.81.230.140$document
 ||36.81.31.124$document
 ||36.82.179.161$document
@@ -349350,6 +349727,7 @@
 ||39.77.44.29$document
 ||39.77.44.32$document
 ||39.77.46.7$document
+||39.77.48.213$document
 ||39.77.49.13$document
 ||39.77.5.113$document
 ||39.77.5.214$document
@@ -349779,6 +350157,7 @@
 ||39.79.162.176$document
 ||39.79.163.104$document
 ||39.79.163.173$document
+||39.79.163.188$document
 ||39.79.163.252$document
 ||39.79.163.96$document
 ||39.79.164.165$document
@@ -350243,6 +350622,7 @@
 ||39.80.35.201$document
 ||39.80.36.151$document
 ||39.80.36.64$document
+||39.80.37.182$document
 ||39.80.38.117$document
 ||39.80.38.27$document
 ||39.80.39.207$document
@@ -353929,6 +354309,7 @@
 ||42.224.122.174$document
 ||42.224.122.176$document
 ||42.224.122.182$document
+||42.224.122.183$document
 ||42.224.122.186$document
 ||42.224.122.19$document
 ||42.224.122.191$document
@@ -355551,6 +355932,7 @@
 ||42.224.188.115$document
 ||42.224.188.137$document
 ||42.224.188.176$document
+||42.224.188.223$document
 ||42.224.188.241$document
 ||42.224.188.250$document
 ||42.224.188.85$document
@@ -355558,6 +355940,7 @@
 ||42.224.189.121$document
 ||42.224.189.153$document
 ||42.224.189.208$document
+||42.224.189.79$document
 ||42.224.189.88$document
 ||42.224.189.89$document
 ||42.224.189.90$document
@@ -356601,6 +356984,7 @@
 ||42.224.249.178$document
 ||42.224.249.18$document
 ||42.224.249.182$document
+||42.224.249.188$document
 ||42.224.249.190$document
 ||42.224.249.195$document
 ||42.224.249.208$document
@@ -357047,6 +357431,7 @@
 ||42.224.3.171$document
 ||42.224.3.179$document
 ||42.224.3.180$document
+||42.224.3.187$document
 ||42.224.3.192$document
 ||42.224.3.205$document
 ||42.224.3.206$document
@@ -357763,6 +358148,7 @@
 ||42.224.52.56$document
 ||42.224.52.58$document
 ||42.224.52.8$document
+||42.224.52.81$document
 ||42.224.52.97$document
 ||42.224.53.120$document
 ||42.224.53.130$document
@@ -357904,6 +358290,7 @@
 ||42.224.59.245$document
 ||42.224.59.247$document
 ||42.224.59.249$document
+||42.224.59.251$document
 ||42.224.59.68$document
 ||42.224.59.73$document
 ||42.224.59.74$document
@@ -358283,6 +358670,7 @@
 ||42.224.68.67$document
 ||42.224.68.69$document
 ||42.224.68.70$document
+||42.224.68.72$document
 ||42.224.68.74$document
 ||42.224.68.78$document
 ||42.224.68.79$document
@@ -362145,6 +362533,7 @@
 ||42.228.196.177$document
 ||42.228.196.193$document
 ||42.228.196.218$document
+||42.228.196.68$document
 ||42.228.196.89$document
 ||42.228.197.136$document
 ||42.228.197.142$document
@@ -366989,6 +367378,7 @@
 ||42.230.46.198$document
 ||42.230.46.231$document
 ||42.230.46.246$document
+||42.230.46.55$document
 ||42.230.46.70$document
 ||42.230.46.9$document
 ||42.230.46.93$document
@@ -369414,6 +369804,7 @@
 ||42.231.95.195$document
 ||42.231.95.210$document
 ||42.231.95.230$document
+||42.231.95.247$document
 ||42.231.95.99$document
 ||42.231.96.105$document
 ||42.231.96.176$document
@@ -370350,6 +370741,7 @@
 ||42.232.45.85$document
 ||42.232.46.1$document
 ||42.232.46.129$document
+||42.232.46.169$document
 ||42.232.46.73$document
 ||42.232.46.86$document
 ||42.232.47.212$document
@@ -371046,6 +371438,7 @@
 ||42.233.159.141$document
 ||42.233.159.168$document
 ||42.233.159.19$document
+||42.233.159.21$document
 ||42.233.159.223$document
 ||42.233.159.228$document
 ||42.233.159.230$document
@@ -372569,6 +372962,7 @@
 ||42.234.246.77$document
 ||42.234.247.171$document
 ||42.234.247.4$document
+||42.234.247.41$document
 ||42.234.247.44$document
 ||42.234.247.55$document
 ||42.234.247.57$document
@@ -375857,6 +376251,7 @@
 ||42.235.81.88$document
 ||42.235.82.0$document
 ||42.235.82.108$document
+||42.235.82.112$document
 ||42.235.82.118$document
 ||42.235.82.129$document
 ||42.235.82.141$document
@@ -375887,6 +376282,7 @@
 ||42.235.82.44$document
 ||42.235.82.45$document
 ||42.235.82.46$document
+||42.235.82.52$document
 ||42.235.82.53$document
 ||42.235.82.54$document
 ||42.235.82.60$document
@@ -376077,6 +376473,7 @@
 ||42.235.86.87$document
 ||42.235.86.95$document
 ||42.235.87.1$document
+||42.235.87.100$document
 ||42.235.87.102$document
 ||42.235.87.103$document
 ||42.235.87.121$document
@@ -377262,6 +377659,7 @@
 ||42.237.14.202$document
 ||42.237.14.74$document
 ||42.237.14.8$document
+||42.237.142.157$document
 ||42.237.15.110$document
 ||42.237.15.142$document
 ||42.237.15.153$document
@@ -377371,6 +377769,7 @@
 ||42.237.24.108$document
 ||42.237.24.129$document
 ||42.237.24.14$document
+||42.237.24.151$document
 ||42.237.24.166$document
 ||42.237.24.220$document
 ||42.237.24.23$document
@@ -377623,6 +378022,7 @@
 ||42.237.60.219$document
 ||42.237.60.254$document
 ||42.237.60.42$document
+||42.237.60.73$document
 ||42.237.61.107$document
 ||42.237.61.152$document
 ||42.237.61.246$document
@@ -378252,6 +378652,7 @@
 ||42.238.227.72$document
 ||42.238.227.86$document
 ||42.238.227.95$document
+||42.238.228.0$document
 ||42.238.228.122$document
 ||42.238.228.132$document
 ||42.238.228.220$document
@@ -378440,6 +378841,7 @@
 ||42.238.250.202$document
 ||42.238.250.246$document
 ||42.238.250.248$document
+||42.238.250.56$document
 ||42.238.251.226$document
 ||42.238.251.47$document
 ||42.238.251.61$document
@@ -378956,6 +379358,7 @@
 ||42.239.154.85$document
 ||42.239.155.124$document
 ||42.239.155.143$document
+||42.239.155.147$document
 ||42.239.155.158$document
 ||42.239.155.159$document
 ||42.239.155.165$document
@@ -379224,6 +379627,7 @@
 ||42.239.201.20$document
 ||42.239.201.86$document
 ||42.239.202.100$document
+||42.239.202.121$document
 ||42.239.202.145$document
 ||42.239.202.227$document
 ||42.239.202.229$document
@@ -379318,6 +379722,7 @@
 ||42.239.217.21$document
 ||42.239.217.228$document
 ||42.239.217.56$document
+||42.239.218.137$document
 ||42.239.218.141$document
 ||42.239.218.157$document
 ||42.239.218.63$document
@@ -381577,6 +381982,7 @@
 ||45.176.108.154$document
 ||45.176.108.157$document
 ||45.176.108.161$document
+||45.176.108.164$document
 ||45.176.108.168$document
 ||45.176.108.170$document
 ||45.176.108.18$document
@@ -386717,6 +387123,7 @@
 ||5.39.218.162$document
 ||5.39.219.130$document
 ||5.39.223.68$document
+||5.42.37.74$document
 ||5.42.48.223$document
 ||5.42.82.17$document
 ||5.42.92.195$document
@@ -387478,6 +387885,7 @@
 ||58.11.78.109$document
 ||58.114.245.23$document
 ||58.114.246.26$document
+||58.115.108.164$document
 ||58.115.160.50$document
 ||58.115.162.92$document
 ||58.115.166.148$document
@@ -388147,6 +388555,7 @@
 ||58.248.116.190$document
 ||58.248.116.199$document
 ||58.248.116.2$document
+||58.248.116.21$document
 ||58.248.116.210$document
 ||58.248.116.216$document
 ||58.248.116.222$document
@@ -388177,6 +388586,7 @@
 ||58.248.117.218$document
 ||58.248.117.226$document
 ||58.248.117.233$document
+||58.248.117.238$document
 ||58.248.117.244$document
 ||58.248.117.253$document
 ||58.248.117.4$document
@@ -388333,6 +388743,7 @@
 ||58.248.142.11$document
 ||58.248.142.111$document
 ||58.248.142.116$document
+||58.248.142.132$document
 ||58.248.142.137$document
 ||58.248.142.138$document
 ||58.248.142.148$document
@@ -388358,6 +388769,7 @@
 ||58.248.142.239$document
 ||58.248.142.24$document
 ||58.248.142.4$document
+||58.248.142.5$document
 ||58.248.142.53$document
 ||58.248.142.64$document
 ||58.248.142.67$document
@@ -388490,6 +388902,7 @@
 ||58.248.147.159$document
 ||58.248.147.179$document
 ||58.248.147.182$document
+||58.248.147.196$document
 ||58.248.147.208$document
 ||58.248.147.224$document
 ||58.248.147.226$document
@@ -388592,6 +389005,7 @@
 ||58.248.151.247$document
 ||58.248.151.248$document
 ||58.248.151.25$document
+||58.248.151.33$document
 ||58.248.151.4$document
 ||58.248.151.48$document
 ||58.248.151.6$document
@@ -388685,6 +389099,7 @@
 ||58.248.74.230$document
 ||58.248.74.236$document
 ||58.248.74.24$document
+||58.248.74.240$document
 ||58.248.74.241$document
 ||58.248.74.246$document
 ||58.248.74.41$document
@@ -389364,6 +389779,7 @@
 ||58.249.72.49$document
 ||58.249.72.67$document
 ||58.249.72.69$document
+||58.249.72.88$document
 ||58.249.72.95$document
 ||58.249.72.98$document
 ||58.249.73.1$document
@@ -389420,6 +389836,7 @@
 ||58.249.74.222$document
 ||58.249.74.227$document
 ||58.249.74.235$document
+||58.249.74.243$document
 ||58.249.74.245$document
 ||58.249.74.248$document
 ||58.249.74.35$document
@@ -389445,6 +389862,7 @@
 ||58.249.75.194$document
 ||58.249.75.20$document
 ||58.249.75.209$document
+||58.249.75.213$document
 ||58.249.75.214$document
 ||58.249.75.218$document
 ||58.249.75.233$document
@@ -389617,6 +390035,7 @@
 ||58.249.80.242$document
 ||58.249.80.245$document
 ||58.249.80.246$document
+||58.249.80.25$document
 ||58.249.80.37$document
 ||58.249.80.38$document
 ||58.249.80.46$document
@@ -389902,6 +390321,7 @@
 ||58.249.89.143$document
 ||58.249.89.15$document
 ||58.249.89.157$document
+||58.249.89.158$document
 ||58.249.89.160$document
 ||58.249.89.162$document
 ||58.249.89.167$document
@@ -390310,6 +390730,7 @@
 ||58.255.140.125$document
 ||58.255.140.146$document
 ||58.255.140.149$document
+||58.255.140.150$document
 ||58.255.140.156$document
 ||58.255.140.190$document
 ||58.255.140.21$document
@@ -390885,6 +391306,7 @@
 ||59.127.10.103$document
 ||59.127.108.38$document
 ||59.127.109.11$document
+||59.127.11.50$document
 ||59.127.124.161$document
 ||59.127.125.164$document
 ||59.127.130.170$document
@@ -395722,6 +396144,7 @@
 ||59.92.176.201$document
 ||59.92.176.202$document
 ||59.92.176.209$document
+||59.92.176.21$document
 ||59.92.176.218$document
 ||59.92.176.221$document
 ||59.92.176.222$document
@@ -395731,6 +396154,7 @@
 ||59.92.176.233$document
 ||59.92.176.235$document
 ||59.92.176.236$document
+||59.92.176.24$document
 ||59.92.176.243$document
 ||59.92.176.244$document
 ||59.92.176.245$document
@@ -395745,6 +396169,7 @@
 ||59.92.176.40$document
 ||59.92.176.41$document
 ||59.92.176.44$document
+||59.92.176.45$document
 ||59.92.176.47$document
 ||59.92.176.55$document
 ||59.92.176.56$document
@@ -395952,7 +396377,9 @@
 ||59.92.179.114$document
 ||59.92.179.115$document
 ||59.92.179.119$document
+||59.92.179.12$document
 ||59.92.179.123$document
+||59.92.179.124$document
 ||59.92.179.125$document
 ||59.92.179.13$document
 ||59.92.179.14$document
@@ -396025,6 +396452,7 @@
 ||59.92.18.145$document
 ||59.92.18.152$document
 ||59.92.18.155$document
+||59.92.18.156$document
 ||59.92.18.159$document
 ||59.92.18.161$document
 ||59.92.18.170$document
@@ -396348,6 +396776,7 @@
 ||59.92.181.221$document
 ||59.92.181.222$document
 ||59.92.181.223$document
+||59.92.181.224$document
 ||59.92.181.225$document
 ||59.92.181.226$document
 ||59.92.181.227$document
@@ -396471,6 +396900,7 @@
 ||59.92.182.138$document
 ||59.92.182.14$document
 ||59.92.182.140$document
+||59.92.182.141$document
 ||59.92.182.144$document
 ||59.92.182.145$document
 ||59.92.182.147$document
@@ -396833,6 +397263,7 @@
 ||59.92.19.211$document
 ||59.92.19.212$document
 ||59.92.19.229$document
+||59.92.19.230$document
 ||59.92.19.235$document
 ||59.92.19.24$document
 ||59.92.19.244$document
@@ -398162,6 +398593,7 @@
 ||59.93.19.99$document
 ||59.93.20.0$document
 ||59.93.20.1$document
+||59.93.20.104$document
 ||59.93.20.106$document
 ||59.93.20.107$document
 ||59.93.20.110$document
@@ -398237,6 +398669,7 @@
 ||59.93.21.111$document
 ||59.93.21.115$document
 ||59.93.21.117$document
+||59.93.21.119$document
 ||59.93.21.121$document
 ||59.93.21.126$document
 ||59.93.21.127$document
@@ -401204,6 +401637,7 @@
 ||59.96.37.177$document
 ||59.96.37.179$document
 ||59.96.37.180$document
+||59.96.37.181$document
 ||59.96.37.182$document
 ||59.96.37.183$document
 ||59.96.37.185$document
@@ -401280,6 +401714,7 @@
 ||59.96.37.34$document
 ||59.96.37.35$document
 ||59.96.37.37$document
+||59.96.37.38$document
 ||59.96.37.39$document
 ||59.96.37.4$document
 ||59.96.37.40$document
@@ -401666,6 +402101,7 @@
 ||59.96.39.241$document
 ||59.96.39.242$document
 ||59.96.39.243$document
+||59.96.39.244$document
 ||59.96.39.246$document
 ||59.96.39.247$document
 ||59.96.39.248$document
@@ -404091,6 +404527,7 @@
 ||59.99.139.184$document
 ||59.99.139.186$document
 ||59.99.139.189$document
+||59.99.139.19$document
 ||59.99.139.190$document
 ||59.99.139.191$document
 ||59.99.139.192$document
@@ -404145,6 +404582,7 @@
 ||59.99.139.64$document
 ||59.99.139.66$document
 ||59.99.139.68$document
+||59.99.139.71$document
 ||59.99.139.73$document
 ||59.99.139.76$document
 ||59.99.139.78$document
@@ -404438,6 +404876,7 @@
 ||59.99.142.157$document
 ||59.99.142.158$document
 ||59.99.142.159$document
+||59.99.142.163$document
 ||59.99.142.164$document
 ||59.99.142.165$document
 ||59.99.142.167$document
@@ -404540,6 +404979,7 @@
 ||59.99.143.112$document
 ||59.99.143.113$document
 ||59.99.143.114$document
+||59.99.143.115$document
 ||59.99.143.117$document
 ||59.99.143.119$document
 ||59.99.143.120$document
@@ -404837,6 +405277,7 @@
 ||59.99.190.18$document
 ||59.99.190.182$document
 ||59.99.190.187$document
+||59.99.190.189$document
 ||59.99.190.190$document
 ||59.99.190.191$document
 ||59.99.190.192$document
@@ -405669,6 +406110,7 @@
 ||59.99.44.123$document
 ||59.99.44.124$document
 ||59.99.44.125$document
+||59.99.44.126$document
 ||59.99.44.129$document
 ||59.99.44.131$document
 ||59.99.44.132$document
@@ -405863,6 +406305,7 @@
 ||59.99.45.153$document
 ||59.99.45.154$document
 ||59.99.45.155$document
+||59.99.45.156$document
 ||59.99.45.158$document
 ||59.99.45.16$document
 ||59.99.45.160$document
@@ -406039,6 +406482,7 @@
 ||59.99.46.166$document
 ||59.99.46.167$document
 ||59.99.46.168$document
+||59.99.46.170$document
 ||59.99.46.171$document
 ||59.99.46.172$document
 ||59.99.46.174$document
@@ -406046,6 +406490,7 @@
 ||59.99.46.176$document
 ||59.99.46.177$document
 ||59.99.46.18$document
+||59.99.46.180$document
 ||59.99.46.181$document
 ||59.99.46.182$document
 ||59.99.46.183$document
@@ -406998,6 +407443,7 @@
 ||59.99.95.161$document
 ||59.99.95.162$document
 ||59.99.95.164$document
+||59.99.95.166$document
 ||59.99.95.167$document
 ||59.99.95.168$document
 ||59.99.95.169$document
@@ -408322,6 +408768,7 @@
 ||60.212.11.156$document
 ||60.212.110.19$document
 ||60.212.110.3$document
+||60.212.111.39$document
 ||60.212.117.125$document
 ||60.212.117.206$document
 ||60.212.117.51$document
@@ -408688,6 +409135,7 @@
 ||60.214.217.79$document
 ||60.214.217.82$document
 ||60.214.217.85$document
+||60.214.217.96$document
 ||60.214.218.136$document
 ||60.214.218.192$document
 ||60.214.218.196$document
@@ -408780,6 +409228,7 @@
 ||60.214.32.138$document
 ||60.214.32.150$document
 ||60.214.32.151$document
+||60.214.32.17$document
 ||60.214.32.236$document
 ||60.214.32.243$document
 ||60.214.32.244$document
@@ -418963,6 +419412,7 @@
 ||61.128.83.148$document
 ||61.128.88.38$document
 ||61.129.101.57$document
+||61.130.195.121$document
 ||61.130.195.172$document
 ||61.130.198.170$document
 ||61.130.224.119$document
@@ -421473,6 +421923,7 @@
 ||61.3.151.37$document
 ||61.3.151.38$document
 ||61.3.151.56$document
+||61.3.151.60$document
 ||61.3.151.66$document
 ||61.3.151.70$document
 ||61.3.151.84$document
@@ -421750,6 +422201,7 @@
 ||61.52.103.2$document
 ||61.52.103.20$document
 ||61.52.103.21$document
+||61.52.103.217$document
 ||61.52.103.220$document
 ||61.52.103.228$document
 ||61.52.103.229$document
@@ -421788,6 +422240,7 @@
 ||61.52.103.91$document
 ||61.52.103.93$document
 ||61.52.103.99$document
+||61.52.109.9$document
 ||61.52.11.12$document
 ||61.52.11.15$document
 ||61.52.11.2$document
@@ -422139,6 +422592,7 @@
 ||61.52.166.218$document
 ||61.52.167.246$document
 ||61.52.167.249$document
+||61.52.167.66$document
 ||61.52.167.89$document
 ||61.52.168.106$document
 ||61.52.168.121$document
@@ -422978,6 +423432,7 @@
 ||61.52.211.31$document
 ||61.52.211.38$document
 ||61.52.211.59$document
+||61.52.211.61$document
 ||61.52.211.75$document
 ||61.52.211.76$document
 ||61.52.211.77$document
@@ -423628,6 +424083,7 @@
 ||61.52.30.159$document
 ||61.52.30.160$document
 ||61.52.30.161$document
+||61.52.30.172$document
 ||61.52.30.174$document
 ||61.52.30.176$document
 ||61.52.30.178$document
@@ -423874,6 +424330,7 @@
 ||61.52.4.127$document
 ||61.52.4.138$document
 ||61.52.4.151$document
+||61.52.4.214$document
 ||61.52.4.220$document
 ||61.52.4.59$document
 ||61.52.4.81$document
@@ -423927,6 +424384,7 @@
 ||61.52.42.112$document
 ||61.52.42.134$document
 ||61.52.42.138$document
+||61.52.42.174$document
 ||61.52.42.192$document
 ||61.52.42.196$document
 ||61.52.42.20$document
@@ -425401,6 +425859,7 @@
 ||61.52.98.210$document
 ||61.52.98.214$document
 ||61.52.98.215$document
+||61.52.98.22$document
 ||61.52.98.220$document
 ||61.52.98.231$document
 ||61.52.98.244$document
@@ -429968,6 +430427,7 @@
 ||62.76.5.154$document
 ||62.77.210.124$document
 ||62.78.131.240$document
+||62.78.82.93$document
 ||62.80.167.71$document
 ||62.80.231.196$document
 ||62.80.235.224$document
@@ -430802,6 +431262,7 @@
 ||68.183.24.160$document
 ||68.183.24.34$document
 ||68.183.25.231$document
+||68.183.25.71$document
 ||68.183.26.100$document
 ||68.183.26.166$document
 ||68.183.26.74$document
@@ -430933,6 +431394,7 @@
 ||68.99.179.195$document
 ||68.99.179.89$document
 ||68.99.180.30$document
+||68468438438.xyz$document
 ||68h7.com$document
 ||68yuanzhijia.xyz/wp-admin/y2kbcwlezlkontymoscer2ggetzbjqxb0oybicpckgboagxr7t/$document
 ||69.10.193.239$document
@@ -431991,6 +432453,7 @@
 ||77.43.248.83$document
 ||77.43.250.181$document
 ||77.43.250.205$document
+||77.43.250.246$document
 ||77.43.251.170$document
 ||77.43.251.196$document
 ||77.43.251.77$document
@@ -432092,6 +432555,7 @@
 ||77.49.200.235$document
 ||77.51.189.86$document
 ||77.52.180.138$document
+||77.53.144.46$document
 ||77.53.145.33$document
 ||77.53.2.182$document
 ||77.53.246.179$document
@@ -438421,6 +438885,7 @@
 ||999.buzz$document
 ||999.co.id$document
 ||999.rajaojek.com$document
+||999080321newfolder1002002131-service1002.space$document
 ||999102com.cn$document
 ||99bkx.com$document
 ||99centsdigitals.com$document
@@ -440034,7 +440499,7 @@
 ||adventureexplorer.in$document
 ||adventurehr.com$document
 ||adventureitdate.com$document
-||adventureits.com/wp-content/6399952952/q54d7zyhe/$document
+||adventureits.com$document
 ||adventuremania.com$document
 ||adventureracen.nl/cgi-bin/parts_service/$document
 ||adventurersafaris.com$document
@@ -441092,6 +441557,7 @@
 ||akatanomastos.net$document
 ||akatlot.com$document
 ||akatsolution.net$document
+||akauk09.top$document
 ||akaunting.redocom.com$document
 ||akawork.io$document
 ||akbaara.com$document
@@ -441175,6 +441641,7 @@
 ||akowa.projet-test.com$document
 ||akowalska.ecrm.pl$document
 ||akpeugono.com$document
+||akpgi08.top$document
 ||akpp-service.top$document
 ||akppservis30.ru$document
 ||akprokonaija.com$document
@@ -447024,6 +447491,7 @@
 ||b2streeteats.com$document
 ||b3shop.net$document
 ||b4512652-a-62cb3a1a-s-sites.googlegroups.com$document
+||b4ad7b79-534a-4e83-953e-c36da8cf27d9.s3.amazonaws.com/ww/setup.exe$document
 ||b4ckdoorarchive.com$document
 ||b4events.it$document
 ||b5.doshimotai.ru$document
@@ -454042,7 +454510,7 @@
 ||camelmorocco.com$document
 ||camelotbrasil.com$document
 ||camelotorganics.com$document
-||cameltrektours.com/wordpress_fille/overview/$document
+||cameltrektours.com$document
 ||camenisch-software.ch$document
 ||camera.risami.net$document
 ||camera88.vn$document
@@ -456017,9 +456485,14 @@
 ||cdn.discordapp.com/attachments/821484577327022114/821484844893732874/2tgyjedsrgftyuikjsedrfgtgh.txt$document
 ||cdn.discordapp.com/attachments/821484577327022114/821484978260672592/ytguj3tgyhjedrgtgyfhjrft.txt$document
 ||cdn.discordapp.com/attachments/821511904769998921/821511945881911306/panam.exe$document
+||cdn.discordapp.com/attachments/821809080812437507/824392185902006272/mmp1_1.exe$document
 ||cdn.discordapp.com/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso$document
 ||cdn.discordapp.com/attachments/823624203529486349/823684377765871646/we.jpg$document
 ||cdn.discordapp.com/attachments/823801311480250391/824870560605274122/bilfx1x.exe$document
+||cdn.discordapp.com/attachments/823810712891555890/824413943526195210/runpetest.exe$document
+||cdn.discordapp.com/attachments/824689793140129857/824690055498170398/token_stealer.bat$document
+||cdn.discordapp.com/attachments/824689793140129857/824690065988386816/sendhookfile.exe$document
+||cdn.discordapp.com/attachments/824689793140129857/824691026852970496/photo.exe$document
 ||cdn.discordapp.com/attachments/824721527890641000/824721774205206618/2_5388614236127628287.exe$document
 ||cdn.discordapp.com/attachments/824721527890641000/824722602072997949/222.exe$document
 ||cdn.discordapp.com:443/attachments/790590543397781576/820879760904683561/system.exe$document
@@ -464674,6 +465147,8 @@
 ||digitalangels.eu$document
 ||digitalankur.com$document
 ||digitalassets.ams3.digitaloceanspaces.com/hahaza/visual19.exe$document
+||digitalassets.ams3.digitaloceanspaces.com/hold/schost.exe$document
+||digitalassets.ams3.digitaloceanspaces.com/modern/five.exe$document
 ||digitalassets.ams3.digitaloceanspaces.com/randf/multitimerrt.exe$document
 ||digitalaxom.in$document
 ||digitalbazar.com$document
@@ -465315,6 +465790,7 @@
 ||dl-97674424.md-downloads.com$document
 ||dl-gameplayer.dmm.com/product/apkggame/giga_baldrbringerextendcode/giga_baldrbringerextendcode/win/src/content/data/data/uninstall.exe$document
 ||dl-gameplayer.dmm.com/product/apkggame/nel_narikiri/nel_narikiri/win/src/content/data/%e3%81%aa%e3%82%8a%e3%81%8d%e3%82%8a%e3%83%90%e3%82%ab%e3%83%83%e3%83%97%e3%83%ab%ef%bc%81.exe$document
+||dl-link.link$document
 ||dl-link.live$document
 ||dl-link.network$document
 ||dl-rw.com$document
@@ -483280,6 +483756,7 @@
 ||duckhouse.org$document
 ||duckiesplumbing.com.au$document
 ||duckpvp.xyz$document
+||duckrambo.com$document
 ||ducks.org.tw$document
 ||ducontcl.esy.es$document
 ||ducro.nl$document
@@ -490784,7 +491261,7 @@
 ||freedomsec.com.br$document
 ||freedomsolutionsuk.co.uk$document
 ||freedomtoshine.co$document
-||freedomwellnesstherapy.com/wp-includes/1a0fhsde7zdx9/$document
+||freedomwellnesstherapy.com$document
 ||freedownloadbravebrowser.com$document
 ||freeeeweb-com.umbler.net$document
 ||freeezguru.com$document
@@ -493212,6 +493689,7 @@
 ||gislegal.ir$document
 ||gisselltejeda.com$document
 ||gist.githubusercontent.com/jamme1020031/b0d4eadf162334049858b225bbac3017/raw/309944c554ba111c4b563fbf34ce416062516465/ilike.txt$document
+||gist.githubusercontent.com/jamme1020031/ef880bfeed7c6314b365c84b5999a27c/raw/4b3456ebe9e1a9717598dd416450e0eafe856311/fuuuuu.txt$document
 ||gist.githubusercontent.com/raigabrielmaia/4384962bcff6896cc89eb7b68924f62d/raw/1788cb8fc869dd68f507a462dee4dd6453e0ed24/avast.mp3$document
 ||gist.githubusercontent.com/raigabrielmaia/4384962bcff6896cc89eb7b68924f62d/raw/1788cb8fc869dd68f507a462dee4dd6453e0ed24/avastt.mp3$document
 ||gist.githubusercontent.com/raigabrielmaia/4384962bcff6896cc89eb7b68924f62d/raw/1788cb8fc869dd68f507a462dee4dd6453e0ed24/nod.mp3$document
@@ -499266,7 +499744,7 @@
 ||iappco.ir$document
 ||iar.webprojemiz.com$document
 ||iarpp.ro$document
-||iasdcentralbucaramanga.com/wp-includes/bt9vl1jt8gwkyrcfxcxtur1avcka98qreu1pvdx24wxdbzbfzsyfvs9g7ldu6h/$document
+||iasdcentralbucaramanga.com$document
 ||iasgoogle.com$document
 ||iashelpdesk.in$document
 ||iasira.dm.files.1drv.com$document
@@ -501658,6 +502136,7 @@
 ||investigadoresforenses-abcjuris.com$document
 ||investigatorsnorthwest.co.uk$document
 ||investime.info$document
+||investinae.com$document
 ||investingbazar.com$document
 ||investingpivot.co.uk$document
 ||investinscs.com$document
@@ -503962,7 +504441,7 @@
 ||joeundrosky.com$document
 ||joezer-online.com$document
 ||jofox.nl$document
-||jofre.eu/wp-content/themes/basic/css/msg.jpg$document
+||jofre.eu$document
 ||jogaae.jfoaigh.com$document
 ||joghataisalam.ir$document
 ||joghatay.ir$document
@@ -508544,7 +509023,8 @@
 ||laparoscopysales.com$document
 ||lapartenza-khl.com$document
 ||lapc.com.pk$document
-||lapcare.com$document
+||lapcare.com/wp-content/9fotgty/$document
+||lapcare.com/wp-content/o2bwo/$document
 ||lapcentervn.xyz$document
 ||lapchallenge.co.uk$document
 ||lapelimmortelle.com.au$document
@@ -509714,7 +510194,10 @@
 ||lglab.co.uk$document
 ||lgmi.org.uk$document
 ||lgonlinecenter.com$document
-||lgpass.com$document
+||lgpass.com/images/closed_resource/security_portal/575383_fczjbnodcixu/$document
+||lgpass.com/images/common_resource/interior_cloud/637368803912_d35jil4kauy8qn/$document
+||lgpass.com/images/d1q66rszmw123555/$document
+||lgpass.com/images/wk128/$document
 ||lgrp35.vatelstudents.fr$document
 ||lgs.ec$document
 ||lgservis.net$document
@@ -517449,7 +517932,7 @@
 ||mojang.com.br$document
 ||mojehaftom.com$document
 ||mojewnetrza.pl$document
-||mojno--vse.ru$document
+||mojno--vse.ru/content/6tqjfutopvigfknidf0sfae6guwnsxjjicomwynq0qmfksrit2be2/$document
 ||mojo-studios.co.uk$document
 ||mojorockstar.com$document
 ||mojstudent.net$document
@@ -517986,7 +518469,14 @@
 ||motzadministraties.nl$document
 ||mouas.xyz$document
 ||mouaysha.com$document
-||moufed.com$document
+||moufed.com/uu/bin_xcmcfzvl198.bin$document
+||moufed.com/wi/bin_ofekr30.bin$document
+||moufed.com/wi/bin_ygdafxi87.bin$document
+||moufed.com/wii/bin_ucpwetyk79.bin$document
+||moufed.com/wu/azor_gzufukw49.bin$document
+||moufed.com/wu/bin_ksbky53.bin$document
+||moufed.com/wu/bin_lzszqq48.bin$document
+||moufed.com/wu/bin_xiaudeklm176.bin$document
 ||moulin-de-la-hunelle.be$document
 ||mouni11.xyz$document
 ||mounicmadiraju.com$document
@@ -519358,7 +519848,7 @@
 ||mytemplate.ro$document
 ||mytempucheck.com$document
 ||mytest.alessioatzeni.com$document
-||mytestingserver.ml/wp-admin/41m/$document
+||mytestingserver.ml$document
 ||mytestwp.cf$document
 ||mytex.pe$document
 ||mythelxis.gr$document
@@ -521640,7 +522130,7 @@
 ||no1angelsescort.com$document
 ||no1spinningfields.90degrees.digital$document
 ||no1websitedesigner.com$document
-||no2politics.com/files/us_us/doc/invoice-069345/$document
+||no2politics.com$document
 ||no70.fun$document
 ||noabuseshere.top$document
 ||noach.nl$document
@@ -523153,6 +523643,7 @@
 ||ol.cognitiononline.in$document
 ||olacabattachment.com$document
 ||oladi.sulinet.hu$document
+||olafyoutrue.xyz$document
 ||olahnyomda.hu$document
 ||olairdryport.com$document
 ||olalekan419.000webhostapp.com$document
@@ -526741,7 +527232,7 @@
 ||ostappnp.myjino.ru$document
 ||ostaz.ml$document
 ||osteklenie-balkonov.tomsk.ru$document
-||ostemeda.lt/wp-content/s/$document
+||ostemeda.lt$document
 ||osteoliv.com$document
 ||osteopatasitgesblog.es$document
 ||osteopathin-husum.de$document
@@ -535247,9 +535738,7 @@
 ||physicianmedical-legalconsulting.com$document
 ||physicscafe.com.sg$document
 ||physio-bo.de$document
-||physio-svdh.ch/sitepage/wzfnncemhvoqidqzhnzkj82qdhk3jyqj39x1djl9pwrakgmuel0xtr/$document
-||physio-svdh.ch/wp-admin/kk/$document
-||physio-svdh.ch/wp-admin/reporting/kv8wbwskaa0txl3jxs/$document
+||physio-svdh.ch$document
 ||physio-veda.de$document
 ||physiodelacomba.ch/userfiles/xing.txt$document
 ||physionize.com$document
@@ -539465,7 +539954,7 @@
 ||radiolajee.com$document
 ||radioland.eu$document
 ||radiolavariada.net$document
-||radiolevi.ro/wp-content/vdbb/$document
+||radiolevi.ro$document
 ||radiomaismg.com.br$document
 ||radiomaxima.cl$document
 ||radiomega-hit.com$document
@@ -540008,6 +540497,7 @@
 ||raw.githubusercontent.com/i87924hgasdhg/hgytiryty/master/busybox$document
 ||raw.githubusercontent.com/idumkyf/za5u0i/gh-pages/h4qpxjhvr.jpeg$document
 ||raw.githubusercontent.com/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe$document
+||raw.githubusercontent.com/itroublve/token-browser-password-stealer-creator/master/avoid%20me/tokenstealer.vbs$document
 ||raw.githubusercontent.com/itroublve/token-browser-password-stealer-creator/master/avoid%20me/tokenstealer2.vbs$document
 ||raw.githubusercontent.com/jocofid282/tewsa/master/blow.exe$document
 ||raw.githubusercontent.com/jocofid282/tewsa/master/dera$document
@@ -542933,6 +543423,7 @@
 ||s-vrach.com.ua$document
 ||s-zone.uz$document
 ||s.51shijuan.com$document
+||s.lletlee.com$document
 ||s.oooooooooo.ga$document
 ||s.put.re$document
 ||s.thechinesemuslim.com$document
@@ -545364,7 +545855,7 @@
 ||seioodsoi.club$document
 ||seis.me$document
 ||seismophonic.com$document
-||seitaiken.net/wp-admin/qz9b/$document
+||seitaiken.net$document
 ||seitenstreifen.ch$document
 ||seivenco.com$document
 ||seiz-ib.de$document
@@ -562684,7 +563175,7 @@
 ||url.emailprotection.link/?bcp_lqdelwbkhxktoiznr8rouhtt9w4qlfovfoxc0z5zmn6k8ji5zi9v7qbcrvrgeprp065w1sneu27jfm6lqozrkxpwdzwxoqhcuebeujx-pj0fn_jidanzngihd_cy1/$document
 ||url.emailprotection.link/?bgmvicpuho15c9_q9hiofgnmkaco0q_lujjcaeowkfik_hdtt1uqmbkpovhxykckgjoqoytv_u0g2umkhd4mbi9ms8vo3vliq2clouuaa6no2a7ij5ljfsouoeememvmi/$document
 ||url.emailprotection.link/?bizyxbw1fdagsfcc1n6ep1awpdx9dr0brnjjqwgyaofpw98limviipvrszjnzzluclpeqqdywfxwnwudvwrljcufuhl2_nha0bs8wz9jmbahcciikbseljewayzbe_cnd/$document
-||url.sg$document
+||url.sg/rwtho$document
 ||url2.mailanyone.net/v1/?m=1hibcm-0003zv-63&i=57e1b682&c=sb1blj46bk32u6f729r5t_slvkx-heewxh20_zdn9-3ktcc0-kn35fykilpydgeyvrbwqwb5h__fk383wtdakqftjlelxz06jbaglri5jmujnydjkasqxwdtg2hn-_be1dzrnthvvhigyhm_tvbew342habp8dtit9jjlieuc2x-ipgdgipe7y_c9jhe69532gmnxozb5wifjfbstzicagmtpg6yxmreaf0sq2dgo-ksy54hetfhn6gwm4kiw2vvcqx17a9bm6ykn8bwpwdjwg/$document
 ||url3.mailanyone.net$document
 ||url5459.41southbar.com$document
diff --git a/urlhaus-filter.tpl b/urlhaus-filter.tpl
index 5a7dcfb0..53c9099d 100644
--- a/urlhaus-filter.tpl
+++ b/urlhaus-filter.tpl
@@ -1,6 +1,6 @@
 msFilterList
 # Title: Malicious Hosts Blocklist (IE)
-# Updated: Sat, 27 Mar 2021 12:12:22 UTC
+# Updated: Sun, 28 Mar 2021 00:12:34 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1456,6 +1456,7 @@ msFilterList
 -d 67373.vip
 -d 67lget9865181258.freebackup.fun
 -d 67ms.top
+-d 68468438438.xyz
 -d 68h7.com
 -d 695c0lock1.com
 -d 69market2.com
@@ -1778,6 +1779,7 @@ msFilterList
 -d 999.buzz
 -d 999.co.id
 -d 999.rajaojek.com
+-d 999080321newfolder1002002131-service1002.space
 -d 999102com.cn
 -d 99bkx.com
 -d 99centsdigitals.com
@@ -3275,6 +3277,7 @@ msFilterList
 -d adventureexplorer.in
 -d adventurehr.com
 -d adventureitdate.com
+-d adventureits.com
 -d adventuremania.com
 -d adventurersafaris.com
 -d adventuresofarchibald.com
@@ -4303,6 +4306,7 @@ msFilterList
 -d akatanomastos.net
 -d akatlot.com
 -d akatsolution.net
+-d akauk09.top
 -d akaunting.redocom.com
 -d akawork.io
 -d akbaara.com
@@ -4386,6 +4390,7 @@ msFilterList
 -d akowa.projet-test.com
 -d akowalska.ecrm.pl
 -d akpeugono.com
+-d akpgi08.top
 -d akpp-service.top
 -d akppservis30.ru
 -d akprokonaija.com
@@ -16338,6 +16343,7 @@ msFilterList
 -d camelmorocco.com
 -d camelotbrasil.com
 -d camelotorganics.com
+-d cameltrektours.com
 -d camenisch-software.ch
 -d camera.risami.net
 -d camera88.vn
@@ -26359,6 +26365,7 @@ msFilterList
 -d dl-675423.store-downloads.com
 -d dl-80076342.md-downloads.com
 -d dl-97674424.md-downloads.com
+-d dl-link.link
 -d dl-link.live
 -d dl-link.network
 -d dl-rw.com
@@ -28030,6 +28037,7 @@ msFilterList
 -d duckhouse.org
 -d duckiesplumbing.com.au
 -d duckpvp.xyz
+-d duckrambo.com
 -d ducks.org.tw
 -d ducontcl.esy.es
 -d ducro.nl
@@ -35224,6 +35232,7 @@ msFilterList
 -d freedomsec.com.br
 -d freedomsolutionsuk.co.uk
 -d freedomtoshine.co
+-d freedomwellnesstherapy.com
 -d freedownloadbravebrowser.com
 -d freeeeweb-com.umbler.net
 -d freeezguru.com
@@ -43179,6 +43188,7 @@ msFilterList
 -d iappco.ir
 -d iar.webprojemiz.com
 -d iarpp.ro
+-d iasdcentralbucaramanga.com
 -d iasgoogle.com
 -d iashelpdesk.in
 -d iasira.dm.files.1drv.com
@@ -45483,6 +45493,7 @@ msFilterList
 -d investigadoresforenses-abcjuris.com
 -d investigatorsnorthwest.co.uk
 -d investime.info
+-d investinae.com
 -d investingbazar.com
 -d investingpivot.co.uk
 -d investinscs.com
@@ -47706,6 +47717,7 @@ msFilterList
 -d joeundrosky.com
 -d joezer-online.com
 -d jofox.nl
+-d jofre.eu
 -d jogaae.jfoaigh.com
 -d joghataisalam.ir
 -d joghatay.ir
@@ -52150,7 +52162,6 @@ msFilterList
 -d laparoscopysales.com
 -d lapartenza-khl.com
 -d lapc.com.pk
--d lapcare.com
 -d lapcentervn.xyz
 -d lapchallenge.co.uk
 -d lapelimmortelle.com.au
@@ -53216,7 +53227,6 @@ msFilterList
 -d lglab.co.uk
 -d lgmi.org.uk
 -d lgonlinecenter.com
--d lgpass.com
 -d lgrp35.vatelstudents.fr
 -d lgs.ec
 -d lgservis.net
@@ -60574,7 +60584,6 @@ msFilterList
 -d mojang.com.br
 -d mojehaftom.com
 -d mojewnetrza.pl
--d mojno--vse.ru
 -d mojo-studios.co.uk
 -d mojorockstar.com
 -d mojstudent.net
@@ -61101,7 +61110,6 @@ msFilterList
 -d motzadministraties.nl
 -d mouas.xyz
 -d mouaysha.com
--d moufed.com
 -d moulin-de-la-hunelle.be
 -d mouni11.xyz
 -d mounicmadiraju.com
@@ -62409,6 +62417,7 @@ msFilterList
 -d mytemplate.ro
 -d mytempucheck.com
 -d mytest.alessioatzeni.com
+-d mytestingserver.ml
 -d mytestwp.cf
 -d mytex.pe
 -d mythelxis.gr
@@ -64601,6 +64610,7 @@ msFilterList
 -d no1angelsescort.com
 -d no1spinningfields.90degrees.digital
 -d no1websitedesigner.com
+-d no2politics.com
 -d no70.fun
 -d noabuseshere.top
 -d noach.nl
@@ -66024,6 +66034,7 @@ msFilterList
 -d ol.cognitiononline.in
 -d olacabattachment.com
 -d oladi.sulinet.hu
+-d olafyoutrue.xyz
 -d olahnyomda.hu
 -d olairdryport.com
 -d olalekan419.000webhostapp.com
@@ -67154,6 +67165,7 @@ msFilterList
 -d ostappnp.myjino.ru
 -d ostaz.ml
 -d osteklenie-balkonov.tomsk.ru
+-d ostemeda.lt
 -d osteoliv.com
 -d osteopatasitgesblog.es
 -d osteopathin-husum.de
@@ -69553,6 +69565,7 @@ msFilterList
 -d physicianmedical-legalconsulting.com
 -d physicscafe.com.sg
 -d physio-bo.de
+-d physio-svdh.ch
 -d physio-veda.de
 -d physionize.com
 -d physiotherapeutinnen.at
@@ -73654,6 +73667,7 @@ msFilterList
 -d radiolajee.com
 -d radioland.eu
 -d radiolavariada.net
+-d radiolevi.ro
 -d radiomaismg.com.br
 -d radiomaxima.cl
 -d radiomega-hit.com
@@ -76916,6 +76930,7 @@ msFilterList
 -d s-vrach.com.ua
 -d s-zone.uz
 -d s.51shijuan.com
+-d s.lletlee.com
 -d s.oooooooooo.ga
 -d s.put.re
 -d s.thechinesemuslim.com
@@ -79059,6 +79074,7 @@ msFilterList
 -d seioodsoi.club
 -d seis.me
 -d seismophonic.com
+-d seitaiken.net
 -d seitenstreifen.ch
 -d seivenco.com
 -d seiz-ib.de
@@ -93516,7 +93532,6 @@ msFilterList
 -d url-validation-clients.com
 -d url.246546.com
 -d url.57569.fr.snd52.ch
--d url.sg
 -d url3.mailanyone.net
 -d url5459.41southbar.com
 -d url675.textilmallorca.com
diff --git a/urlhaus-filter.txt b/urlhaus-filter.txt
index 566db482..946151d3 100644
--- a/urlhaus-filter.txt
+++ b/urlhaus-filter.txt
@@ -1,5 +1,5 @@
 ! Title: Malicious URL Blocklist
-! Updated: Sat, 27 Mar 2021 12:12:22 UTC
+! Updated: Sun, 28 Mar 2021 00:12:34 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1867,6 +1867,7 @@
 101.108.142.60
 101.108.142.75
 101.108.142.82
+101.108.142.9
 101.108.143.105
 101.108.143.110
 101.108.143.137
@@ -2393,6 +2394,7 @@
 101.66.80.23
 101.66.80.72
 101.66.81.166
+101.66.81.70
 101.67.176.237
 101.67.180.154
 101.67.198.121
@@ -2972,6 +2974,7 @@
 103.126.100.31
 103.126.100.9
 103.126.217.58
+103.126.35.40
 103.127.104.16
 103.127.104.165
 103.127.104.184
@@ -4275,6 +4278,7 @@
 103.245.48.197
 103.245.49.135
 103.245.49.147
+103.245.49.180
 103.245.49.183
 103.245.49.204
 103.245.49.24
@@ -8722,6 +8726,7 @@
 107.173.160.139
 107.173.160.14
 107.173.171.123
+107.173.171.143
 107.173.171.168
 107.173.175.135
 107.173.176.100
@@ -12358,6 +12363,7 @@
 112.122.63.240
 112.122.63.54
 112.122.63.6
+112.122.63.70
 112.122.63.9
 112.122.90.208
 112.122.99.186
@@ -14453,6 +14459,7 @@
 112.235.188.86
 112.235.194.43
 112.235.210.15
+112.235.210.251
 112.235.217.106
 112.235.217.213
 112.235.219.224
@@ -16832,6 +16839,7 @@
 112.242.96.25
 112.242.96.4
 112.242.96.56
+112.242.97.131
 112.242.97.165
 112.242.97.195
 112.242.98.194
@@ -16886,6 +16894,7 @@
 112.245.177.136
 112.245.177.145
 112.245.177.215
+112.245.178.153
 112.245.179.96
 112.245.182.56
 112.245.182.9
@@ -17214,6 +17223,7 @@
 112.247.156.74
 112.247.158.19
 112.247.16.190
+112.247.16.222
 112.247.161.45
 112.247.161.83
 112.247.163.177
@@ -17281,6 +17291,7 @@
 112.247.248.76
 112.247.249.198
 112.247.249.82
+112.247.25.42
 112.247.250.193
 112.247.250.96
 112.247.251.11
@@ -18713,6 +18724,7 @@
 112.254.125.2
 112.254.127.63
 112.254.128.119
+112.254.128.160
 112.254.128.224
 112.254.129.79
 112.254.129.95
@@ -18816,6 +18828,7 @@
 112.254.188.12
 112.254.188.137
 112.254.188.19
+112.254.188.228
 112.254.188.35
 112.254.189.137
 112.254.189.16
@@ -21506,6 +21519,7 @@
 113.116.177.248
 113.116.177.29
 113.116.177.81
+113.116.177.90
 113.116.178.100
 113.116.178.133
 113.116.178.138
@@ -22345,6 +22359,7 @@
 113.116.89.25
 113.116.89.29
 113.116.89.40
+113.116.89.41
 113.116.89.45
 113.116.89.55
 113.116.89.82
@@ -22699,6 +22714,7 @@
 113.118.159.142
 113.118.159.144
 113.118.159.153
+113.118.159.178
 113.118.159.215
 113.118.159.22
 113.118.159.232
@@ -23152,6 +23168,7 @@
 113.118.87.84
 113.118.87.88
 113.119.36.91
+113.119.37.141
 113.119.85.16
 113.122.238.68
 113.122.32.245
@@ -26886,6 +26903,7 @@
 113.88.39.104
 113.88.39.194
 113.88.39.2
+113.88.39.21
 113.88.39.35
 113.88.39.37
 113.88.39.55
@@ -27594,6 +27612,7 @@
 113.90.26.54
 113.90.26.6
 113.90.27.178
+113.90.27.218
 113.90.92.191
 113.90.93.98
 113.90.94.120
@@ -27721,6 +27740,7 @@
 113.92.196.102
 113.92.196.116
 113.92.196.145
+113.92.196.173
 113.92.196.192
 113.92.196.227
 113.92.196.235
@@ -30187,6 +30207,7 @@
 115.205.14.76
 115.205.15.79
 115.205.171.34
+115.205.197.221
 115.205.235.30
 115.205.66.30
 115.205.70.49
@@ -32676,6 +32697,7 @@
 115.48.201.222
 115.48.201.244
 115.48.201.255
+115.48.201.26
 115.48.201.31
 115.48.201.37
 115.48.201.40
@@ -33513,6 +33535,7 @@
 115.48.40.227
 115.48.40.3
 115.48.40.63
+115.48.41.101
 115.48.41.141
 115.48.41.156
 115.48.41.184
@@ -34453,6 +34476,7 @@
 115.49.24.52
 115.49.24.58
 115.49.24.60
+115.49.24.63
 115.49.240.125
 115.49.240.14
 115.49.240.147
@@ -36543,6 +36567,7 @@
 115.50.168.145
 115.50.168.153
 115.50.168.159
+115.50.168.160
 115.50.168.168
 115.50.168.183
 115.50.168.19
@@ -36685,6 +36710,7 @@
 115.50.171.172
 115.50.171.184
 115.50.171.188
+115.50.171.192
 115.50.171.196
 115.50.171.248
 115.50.171.250
@@ -37470,6 +37496,7 @@
 115.50.211.56
 115.50.211.62
 115.50.211.65
+115.50.211.74
 115.50.211.8
 115.50.211.80
 115.50.212.1
@@ -38653,6 +38680,7 @@
 115.50.242.244
 115.50.242.246
 115.50.242.43
+115.50.242.7
 115.50.242.81
 115.50.242.89
 115.50.243.10
@@ -38770,6 +38798,7 @@
 115.50.247.245
 115.50.247.33
 115.50.247.40
+115.50.247.46
 115.50.247.47
 115.50.247.56
 115.50.247.80
@@ -40643,6 +40672,7 @@
 115.50.79.50
 115.50.79.7
 115.50.79.73
+115.50.79.78
 115.50.79.95
 115.50.8.131
 115.50.8.159
@@ -41823,6 +41853,7 @@
 115.51.58.162
 115.51.61.137
 115.51.7.177
+115.51.7.254
 115.51.78.11
 115.51.88.101
 115.51.88.11
@@ -42458,6 +42489,7 @@
 115.52.172.58
 115.52.172.63
 115.52.172.64
+115.52.172.72
 115.52.172.74
 115.52.172.91
 115.52.172.93
@@ -43809,6 +43841,7 @@
 115.53.56.72
 115.53.57.189
 115.53.58.162
+115.53.58.228
 115.53.58.24
 115.53.59.170
 115.53.59.68
@@ -43924,6 +43957,7 @@
 115.54.112.31
 115.54.113.101
 115.54.113.128
+115.54.113.49
 115.54.114.20
 115.54.114.211
 115.54.115.1
@@ -44112,6 +44146,7 @@
 115.54.158.17
 115.54.158.176
 115.54.158.210
+115.54.158.251
 115.54.158.255
 115.54.158.67
 115.54.159.101
@@ -45801,6 +45836,7 @@
 115.55.126.58
 115.55.126.59
 115.55.126.88
+115.55.127.0
 115.55.127.101
 115.55.127.126
 115.55.127.146
@@ -48041,6 +48077,7 @@
 115.55.197.78
 115.55.197.99
 115.55.198.103
+115.55.198.105
 115.55.198.117
 115.55.198.127
 115.55.198.143
@@ -48843,6 +48880,7 @@
 115.55.52.113
 115.55.52.125
 115.55.52.136
+115.55.52.17
 115.55.52.200
 115.55.52.206
 115.55.52.208
@@ -49748,6 +49786,7 @@
 115.56.131.136
 115.56.131.144
 115.56.131.148
+115.56.131.150
 115.56.131.166
 115.56.131.170
 115.56.131.186
@@ -49997,6 +50036,7 @@
 115.56.135.237
 115.56.135.247
 115.56.135.250
+115.56.135.255
 115.56.135.28
 115.56.135.33
 115.56.135.36
@@ -50417,6 +50457,7 @@
 115.56.142.39
 115.56.142.4
 115.56.142.44
+115.56.142.45
 115.56.142.49
 115.56.142.5
 115.56.142.66
@@ -50744,6 +50785,7 @@
 115.56.150.130
 115.56.150.139
 115.56.150.14
+115.56.150.149
 115.56.150.150
 115.56.150.152
 115.56.150.156
@@ -50993,6 +51035,7 @@
 115.56.155.38
 115.56.155.42
 115.56.155.43
+115.56.155.50
 115.56.155.51
 115.56.155.54
 115.56.155.64
@@ -52594,6 +52637,7 @@
 115.56.27.88
 115.56.3.209
 115.56.31.10
+115.56.31.11
 115.56.31.156
 115.56.31.170
 115.56.31.176
@@ -54742,6 +54786,7 @@
 115.58.91.225
 115.58.91.240
 115.58.91.52
+115.58.91.65
 115.58.91.74
 115.58.91.86
 115.58.91.9
@@ -57992,6 +58037,7 @@
 115.61.112.13
 115.61.112.14
 115.61.112.140
+115.61.112.159
 115.61.112.161
 115.61.112.168
 115.61.112.185
@@ -58629,6 +58675,7 @@
 115.61.158.55
 115.61.158.90
 115.61.158.93
+115.61.158.98
 115.61.159.102
 115.61.159.115
 115.61.159.118
@@ -60153,6 +60200,7 @@
 115.62.170.41
 115.62.170.82
 115.62.170.91
+115.62.171.143
 115.62.171.177
 115.62.171.71
 115.62.171.81
@@ -60547,6 +60595,7 @@
 115.63.131.168
 115.63.131.169
 115.63.131.170
+115.63.131.173
 115.63.131.176
 115.63.131.229
 115.63.131.230
@@ -60778,6 +60827,7 @@
 115.63.139.178
 115.63.139.183
 115.63.139.186
+115.63.139.187
 115.63.139.229
 115.63.139.246
 115.63.139.25
@@ -68428,6 +68478,7 @@
 115.97.139.254
 115.97.139.28
 115.97.139.3
+115.97.139.32
 115.97.139.35
 115.97.139.4
 115.97.139.43
@@ -92780,6 +92831,7 @@
 116.68.98.160
 116.68.98.163
 116.68.98.17
+116.68.98.173
 116.68.98.178
 116.68.98.182
 116.68.98.184
@@ -94890,6 +94942,7 @@
 116.72.28.187
 116.72.28.204
 116.72.28.226
+116.72.28.239
 116.72.28.48
 116.72.28.49
 116.72.28.76
@@ -96507,6 +96560,7 @@
 116.73.52.121
 116.73.52.122
 116.73.52.124
+116.73.52.125
 116.73.52.127
 116.73.52.13
 116.73.52.132
@@ -98338,6 +98392,7 @@
 116.73.99.95
 116.73.99.97
 116.74.101.118
+116.74.101.150
 116.74.101.161
 116.74.101.177
 116.74.101.210
@@ -100254,6 +100309,7 @@
 116.74.23.37
 116.74.23.44
 116.74.23.45
+116.74.23.46
 116.74.23.48
 116.74.23.51
 116.74.23.52
@@ -100345,6 +100401,7 @@
 116.74.24.75
 116.74.24.76
 116.74.24.79
+116.74.24.8
 116.74.24.82
 116.74.24.84
 116.74.24.85
@@ -111715,6 +111772,7 @@
 116.88.65.131
 116.9.145.199
 116.9.43.106
+116.9.43.220
 116.9.43.235
 116.90.238.142
 116.91.202.79
@@ -112816,6 +112874,7 @@
 117.194.148.188
 117.194.148.189
 117.194.148.190
+117.194.148.198
 117.194.148.202
 117.194.148.205
 117.194.148.207
@@ -113098,6 +113157,7 @@
 117.194.151.176
 117.194.151.178
 117.194.151.180
+117.194.151.184
 117.194.151.192
 117.194.151.196
 117.194.151.198
@@ -114049,6 +114109,7 @@
 117.194.164.97
 117.194.164.99
 117.194.165.0
+117.194.165.1
 117.194.165.100
 117.194.165.101
 117.194.165.102
@@ -114740,6 +114801,7 @@
 117.196.48.178
 117.196.48.179
 117.196.48.180
+117.196.48.181
 117.196.48.183
 117.196.48.184
 117.196.48.185
@@ -115030,6 +115092,7 @@
 117.196.50.147
 117.196.50.15
 117.196.50.150
+117.196.50.154
 117.196.50.158
 117.196.50.161
 117.196.50.164
@@ -115073,6 +115136,7 @@
 117.196.50.23
 117.196.50.230
 117.196.50.236
+117.196.50.239
 117.196.50.24
 117.196.50.240
 117.196.50.241
@@ -115117,6 +115181,7 @@
 117.196.50.7
 117.196.50.71
 117.196.50.72
+117.196.50.76
 117.196.50.77
 117.196.50.78
 117.196.50.79
@@ -115995,6 +116060,7 @@
 117.202.66.40
 117.202.66.41
 117.202.66.42
+117.202.66.44
 117.202.66.45
 117.202.66.46
 117.202.66.47
@@ -117611,6 +117677,7 @@
 117.207.47.96
 117.207.5.156
 117.207.50.5
+117.208.132.10
 117.208.132.101
 117.208.132.102
 117.208.132.103
@@ -117884,6 +117951,7 @@
 117.208.133.86
 117.208.133.87
 117.208.133.9
+117.208.133.91
 117.208.133.92
 117.208.133.97
 117.208.134.0
@@ -119325,6 +119393,7 @@
 117.213.41.74
 117.213.41.75
 117.213.41.78
+117.213.41.8
 117.213.41.80
 117.213.41.82
 117.213.41.83
@@ -120268,6 +120337,7 @@
 117.213.47.134
 117.213.47.136
 117.213.47.138
+117.213.47.139
 117.213.47.14
 117.213.47.140
 117.213.47.142
@@ -120527,6 +120597,7 @@
 117.215.210.230
 117.215.210.243
 117.215.210.245
+117.215.210.249
 117.215.210.25
 117.215.210.250
 117.215.210.251
@@ -120588,6 +120659,7 @@
 117.215.212.153
 117.215.212.166
 117.215.212.168
+117.215.212.174
 117.215.212.176
 117.215.212.180
 117.215.212.182
@@ -120729,6 +120801,7 @@
 117.215.248.158
 117.215.248.17
 117.215.248.181
+117.215.248.198
 117.215.248.20
 117.215.248.201
 117.215.248.205
@@ -121572,6 +121645,7 @@
 117.222.162.70
 117.222.162.71
 117.222.162.72
+117.222.162.73
 117.222.162.74
 117.222.162.75
 117.222.162.76
@@ -122345,6 +122419,7 @@
 117.222.166.28
 117.222.166.3
 117.222.166.30
+117.222.166.36
 117.222.166.38
 117.222.166.39
 117.222.166.4
@@ -122821,6 +122896,7 @@
 117.222.170.217
 117.222.170.223
 117.222.170.224
+117.222.170.234
 117.222.170.237
 117.222.170.238
 117.222.170.239
@@ -124469,6 +124545,7 @@
 117.242.210.238
 117.242.210.239
 117.242.210.24
+117.242.210.240
 117.242.210.241
 117.242.210.244
 117.242.210.246
@@ -124749,6 +124826,7 @@
 117.242.48.212
 117.242.48.232
 117.242.48.57
+117.242.49.157
 117.242.49.166
 117.242.49.185
 117.242.49.21
@@ -126494,6 +126572,7 @@
 117.248.63.61
 117.248.63.62
 117.248.63.67
+117.248.63.70
 117.248.63.73
 117.248.63.74
 117.248.63.75
@@ -127586,6 +127665,7 @@
 117.251.63.206
 117.251.63.207
 117.251.63.209
+117.251.63.21
 117.251.63.211
 117.251.63.212
 117.251.63.214
@@ -128461,6 +128541,7 @@
 118.113.244.200
 118.113.245.110
 118.114.216.131
+118.114.84.237
 118.116.192.103
 118.116.192.53
 118.117.167.48
@@ -128780,6 +128861,7 @@
 118.172.224.136
 118.172.224.179
 118.172.224.205
+118.172.224.37
 118.172.231.79
 118.172.232.164
 118.172.234.157
@@ -130316,6 +130398,7 @@
 118.79.91.203
 118.79.92.29
 118.79.93.194
+118.79.96.11
 118.79.96.249
 118.79.96.9
 118.79.97.100
@@ -130632,6 +130715,7 @@
 119.118.128.127
 119.118.139.228
 119.118.143.250
+119.118.150.84
 119.118.161.115
 119.118.167.179
 119.118.172.168
@@ -131012,6 +131096,7 @@
 119.123.173.46
 119.123.173.73
 119.123.173.91
+119.123.173.95
 119.123.173.96
 119.123.174.102
 119.123.174.11
@@ -131056,6 +131141,7 @@
 119.123.175.174
 119.123.175.175
 119.123.175.185
+119.123.175.210
 119.123.175.215
 119.123.175.222
 119.123.175.228
@@ -131274,6 +131360,7 @@
 119.123.219.194
 119.123.219.204
 119.123.219.230
+119.123.219.232
 119.123.219.234
 119.123.219.240
 119.123.219.247
@@ -131317,6 +131404,7 @@
 119.123.221.5
 119.123.221.6
 119.123.221.74
+119.123.221.94
 119.123.222.0
 119.123.222.112
 119.123.222.128
@@ -131457,6 +131545,7 @@
 119.123.239.109
 119.123.239.117
 119.123.239.122
+119.123.239.131
 119.123.239.142
 119.123.239.153
 119.123.239.180
@@ -137597,6 +137686,7 @@
 120.57.214.195
 120.57.214.200
 120.57.214.223
+120.57.214.228
 120.57.214.251
 120.57.214.38
 120.57.214.44
@@ -139449,6 +139539,7 @@
 120.6.233.250
 120.6.239.231
 120.6.240.130
+120.6.241.130
 120.6.242.41
 120.6.248.88
 120.6.4.156
@@ -140461,6 +140552,7 @@
 120.85.196.179
 120.85.196.196
 120.85.196.205
+120.85.196.211
 120.85.196.217
 120.85.196.220
 120.85.196.23
@@ -140560,6 +140652,7 @@
 120.85.199.91
 120.85.199.97
 120.85.208.103
+120.85.208.107
 120.85.208.111
 120.85.208.114
 120.85.208.121
@@ -140738,6 +140831,7 @@
 120.85.238.0
 120.85.238.10
 120.85.238.107
+120.85.238.129
 120.85.238.13
 120.85.238.137
 120.85.238.139
@@ -140754,6 +140848,7 @@
 120.85.238.218
 120.85.238.219
 120.85.238.233
+120.85.238.238
 120.85.238.240
 120.85.238.244
 120.85.238.25
@@ -145412,6 +145507,7 @@
 123.11.125.93
 123.11.126.117
 123.11.126.2
+123.11.126.225
 123.11.126.241
 123.11.126.62
 123.11.126.76
@@ -146829,6 +146925,7 @@
 123.11.62.73
 123.11.62.76
 123.11.63.112
+123.11.63.113
 123.11.63.133
 123.11.63.170
 123.11.63.180
@@ -147453,6 +147550,7 @@
 123.12.185.95
 123.12.186.64
 123.12.187.224
+123.12.189.247
 123.12.189.252
 123.12.189.93
 123.12.19.142
@@ -147564,6 +147662,7 @@
 123.12.225.250
 123.12.225.254
 123.12.225.62
+123.12.225.70
 123.12.225.90
 123.12.225.94
 123.12.226.11
@@ -147904,6 +148003,7 @@
 123.12.243.76
 123.12.243.82
 123.12.243.83
+123.12.243.85
 123.12.243.89
 123.12.243.95
 123.12.243.99
@@ -149462,6 +149562,7 @@
 123.130.254.2
 123.130.26.116
 123.130.27.172
+123.130.27.19
 123.130.28.103
 123.130.28.105
 123.130.28.213
@@ -150427,6 +150528,7 @@
 123.14.127.174
 123.14.127.209
 123.14.127.219
+123.14.127.238
 123.14.127.243
 123.14.127.250
 123.14.127.33
@@ -150769,6 +150871,7 @@
 123.14.173.130
 123.14.173.154
 123.14.173.159
+123.14.173.199
 123.14.173.202
 123.14.173.218
 123.14.174.128
@@ -151257,6 +151360,7 @@
 123.14.249.250
 123.14.249.253
 123.14.249.30
+123.14.249.33
 123.14.249.34
 123.14.249.38
 123.14.249.46
@@ -151509,6 +151613,7 @@
 123.14.34.184
 123.14.34.200
 123.14.34.222
+123.14.34.240
 123.14.34.246
 123.14.34.36
 123.14.34.42
@@ -151564,6 +151669,7 @@
 123.14.37.215
 123.14.37.228
 123.14.37.231
+123.14.37.32
 123.14.37.81
 123.14.38.0
 123.14.38.11
@@ -151711,6 +151817,7 @@
 123.14.50.184
 123.14.50.185
 123.14.50.207
+123.14.50.214
 123.14.50.221
 123.14.50.251
 123.14.50.3
@@ -152491,6 +152598,7 @@
 123.153.59.88
 123.153.80.178
 123.153.88.252
+123.154.116.116
 123.154.116.130
 123.154.116.155
 123.154.116.19
@@ -154351,6 +154459,7 @@
 123.4.194.144
 123.4.194.147
 123.4.194.15
+123.4.194.152
 123.4.194.167
 123.4.194.173
 123.4.194.18
@@ -154563,6 +154672,7 @@
 123.4.213.128
 123.4.213.152
 123.4.213.169
+123.4.213.239
 123.4.213.74
 123.4.213.83
 123.4.214.10
@@ -155115,6 +155225,7 @@
 123.4.45.112
 123.4.45.192
 123.4.45.221
+123.4.45.31
 123.4.45.4
 123.4.45.7
 123.4.46.136
@@ -159753,6 +159864,7 @@
 123.8.71.235
 123.8.71.243
 123.8.71.246
+123.8.71.27
 123.8.71.32
 123.8.71.7
 123.8.71.82
@@ -161025,6 +161137,7 @@
 123.9.239.80
 123.9.240.102
 123.9.240.103
+123.9.240.115
 123.9.240.138
 123.9.240.146
 123.9.240.16
@@ -162384,6 +162497,7 @@
 124.131.136.92
 124.131.137.113
 124.131.137.137
+124.131.137.147
 124.131.137.183
 124.131.137.190
 124.131.137.192
@@ -162744,6 +162858,7 @@
 124.131.23.131
 124.131.23.177
 124.131.239.254
+124.131.24.185
 124.131.24.187
 124.131.24.219
 124.131.24.229
@@ -164134,6 +164249,7 @@
 124.92.133.100
 124.92.135.150
 124.92.135.30
+124.92.135.37
 124.92.137.146
 124.92.137.71
 124.92.139.198
@@ -164377,6 +164493,7 @@
 125.106.44.171
 125.106.45.123
 125.106.45.200
+125.106.46.225
 125.106.47.217
 125.106.48.237
 125.106.48.250
@@ -167518,6 +167635,7 @@
 125.41.164.56
 125.41.164.59
 125.41.164.6
+125.41.164.60
 125.41.164.69
 125.41.164.92
 125.41.164.93
@@ -167713,6 +167831,7 @@
 125.41.184.230
 125.41.184.251
 125.41.185.110
+125.41.185.186
 125.41.185.237
 125.41.185.252
 125.41.185.65
@@ -167871,6 +167990,7 @@
 125.41.191.8
 125.41.191.88
 125.41.196.104
+125.41.196.114
 125.41.196.119
 125.41.196.128
 125.41.196.132
@@ -169759,6 +169879,7 @@
 125.41.97.224
 125.41.97.226
 125.41.97.228
+125.41.97.231
 125.41.97.234
 125.41.97.237
 125.41.97.238
@@ -173145,6 +173266,7 @@
 125.43.6.111
 125.43.6.114
 125.43.6.138
+125.43.6.186
 125.43.6.191
 125.43.6.204
 125.43.6.216
@@ -173239,6 +173361,7 @@
 125.43.63.252
 125.43.63.39
 125.43.63.46
+125.43.63.47
 125.43.63.49
 125.43.63.50
 125.43.63.55
@@ -174992,6 +175115,7 @@
 125.44.207.72
 125.44.207.91
 125.44.207.97
+125.44.208.152
 125.44.208.153
 125.44.208.164
 125.44.208.165
@@ -175470,6 +175594,7 @@
 125.44.227.242
 125.44.227.248
 125.44.227.4
+125.44.227.51
 125.44.227.65
 125.44.227.69
 125.44.228.124
@@ -176413,6 +176538,7 @@
 125.44.70.28
 125.44.70.31
 125.44.70.5
+125.44.70.64
 125.44.70.68
 125.44.70.87
 125.44.71.10
@@ -177125,6 +177251,7 @@
 125.45.43.19
 125.45.43.190
 125.45.43.209
+125.45.43.63
 125.45.43.78
 125.45.48.101
 125.45.48.154
@@ -178192,6 +178319,7 @@
 125.46.165.83
 125.46.166.10
 125.46.166.101
+125.46.166.112
 125.46.166.121
 125.46.166.123
 125.46.166.125
@@ -179424,6 +179552,7 @@
 125.47.124.60
 125.47.124.62
 125.47.125.129
+125.47.125.16
 125.47.126.230
 125.47.126.53
 125.47.126.63
@@ -180393,6 +180522,7 @@
 125.47.248.117
 125.47.248.119
 125.47.248.124
+125.47.248.131
 125.47.248.135
 125.47.248.141
 125.47.248.142
@@ -180899,9 +181029,11 @@
 125.47.37.56
 125.47.37.68
 125.47.38.10
+125.47.38.114
 125.47.38.119
 125.47.38.124
 125.47.38.132
+125.47.38.142
 125.47.38.152
 125.47.38.168
 125.47.38.17
@@ -181002,6 +181134,7 @@
 125.47.47.198
 125.47.47.209
 125.47.47.21
+125.47.47.212
 125.47.47.217
 125.47.47.220
 125.47.47.233
@@ -182998,6 +183131,7 @@
 125.99.220.202
 125.99.220.216
 125.99.222.152
+125.99.222.2
 125.99.222.245
 125.99.222.76
 125.99.223.227
@@ -185548,6 +185682,7 @@
 139.213.7.128
 139.213.7.230
 139.213.96.26
+139.213.97.191
 139.213.97.23
 139.214.62.66
 139.214.62.96
@@ -185776,6 +185911,7 @@
 14.109.109.129
 14.109.111.219
 14.109.112.100
+14.109.126.96
 14.113.12.153
 14.113.13.184
 14.113.14.145
@@ -186795,6 +186931,7 @@
 140.237.28.148
 140.237.29.28
 140.237.30.113
+140.237.30.172
 140.237.30.179
 140.237.30.188
 140.237.31.197
@@ -187598,6 +187735,7 @@
 149.255.15.112
 149.255.15.121
 149.255.15.134
+149.255.15.172
 149.255.15.180
 149.255.15.182
 149.255.15.184
@@ -190282,6 +190420,7 @@
 163.125.2.36
 163.125.2.67
 163.125.200.107
+163.125.200.118
 163.125.200.126
 163.125.200.129
 163.125.200.13
@@ -190303,6 +190442,7 @@
 163.125.200.230
 163.125.200.233
 163.125.200.238
+163.125.200.242
 163.125.200.247
 163.125.200.37
 163.125.200.40
@@ -190391,6 +190531,7 @@
 163.125.202.235
 163.125.202.245
 163.125.202.246
+163.125.202.255
 163.125.202.27
 163.125.202.4
 163.125.202.57
@@ -190398,6 +190539,7 @@
 163.125.202.74
 163.125.202.8
 163.125.202.83
+163.125.202.87
 163.125.202.9
 163.125.203.10
 163.125.203.118
@@ -190415,6 +190557,7 @@
 163.125.203.213
 163.125.203.214
 163.125.203.23
+163.125.203.236
 163.125.203.32
 163.125.203.33
 163.125.203.4
@@ -190473,6 +190616,7 @@
 163.125.206.133
 163.125.206.145
 163.125.206.151
+163.125.206.16
 163.125.206.162
 163.125.206.164
 163.125.206.187
@@ -190800,6 +190944,7 @@
 163.204.21.75
 163.204.210.243
 163.204.210.34
+163.204.211.136
 163.204.211.205
 163.204.211.228
 163.204.211.47
@@ -191887,6 +192032,7 @@
 168.187.202.184
 168.187.234.86
 168.194.110.39
+168.194.146.145
 168.194.176.180
 168.194.214.107
 168.194.214.113
@@ -192886,6 +193032,7 @@
 171.125.122.33
 171.125.122.54
 171.125.122.90
+171.125.122.91
 171.125.123.88
 171.125.124.133
 171.125.124.58
@@ -193149,6 +193296,7 @@
 171.125.65.193
 171.125.65.202
 171.125.65.22
+171.125.65.89
 171.125.66.6
 171.125.68.45
 171.125.7.181
@@ -198101,6 +198249,7 @@
 175.164.59.67
 175.164.6.45
 175.164.61.169
+175.164.61.215
 175.164.63.75
 175.164.63.94
 175.164.66.17
@@ -198243,6 +198392,7 @@
 175.169.118.51
 175.169.127.142
 175.169.127.205
+175.169.13.182
 175.169.15.220
 175.169.160.119
 175.169.163.231
@@ -201146,6 +201296,7 @@
 178.141.41.122
 178.141.41.125
 178.141.41.239
+178.141.44.152
 178.141.44.159
 178.141.44.184
 178.141.44.21
@@ -201409,6 +201560,7 @@
 178.175.1.155
 178.175.1.157
 178.175.1.159
+178.175.1.16
 178.175.1.161
 178.175.1.162
 178.175.1.164
@@ -201416,6 +201568,7 @@
 178.175.1.172
 178.175.1.174
 178.175.1.175
+178.175.1.176
 178.175.1.178
 178.175.1.179
 178.175.1.182
@@ -201451,6 +201604,7 @@
 178.175.1.33
 178.175.1.34
 178.175.1.43
+178.175.1.44
 178.175.1.46
 178.175.1.48
 178.175.1.5
@@ -201480,6 +201634,7 @@
 178.175.10.108
 178.175.10.113
 178.175.10.12
+178.175.10.121
 178.175.10.124
 178.175.10.125
 178.175.10.133
@@ -201499,6 +201654,7 @@
 178.175.10.173
 178.175.10.175
 178.175.10.177
+178.175.10.178
 178.175.10.182
 178.175.10.184
 178.175.10.186
@@ -201577,6 +201733,7 @@
 178.175.100.185
 178.175.100.187
 178.175.100.190
+178.175.100.191
 178.175.100.193
 178.175.100.2
 178.175.100.201
@@ -201615,6 +201772,7 @@
 178.175.100.48
 178.175.100.49
 178.175.100.5
+178.175.100.52
 178.175.100.54
 178.175.100.58
 178.175.100.61
@@ -201664,11 +201822,13 @@
 178.175.101.168
 178.175.101.170
 178.175.101.171
+178.175.101.173
 178.175.101.174
 178.175.101.177
 178.175.101.186
 178.175.101.187
 178.175.101.189
+178.175.101.191
 178.175.101.194
 178.175.101.196
 178.175.101.199
@@ -201880,8 +202040,10 @@
 178.175.103.233
 178.175.103.234
 178.175.103.239
+178.175.103.24
 178.175.103.242
 178.175.103.245
+178.175.103.246
 178.175.103.253
 178.175.103.26
 178.175.103.27
@@ -201947,6 +202109,7 @@
 178.175.104.145
 178.175.104.148
 178.175.104.15
+178.175.104.151
 178.175.104.152
 178.175.104.153
 178.175.104.154
@@ -201955,6 +202118,7 @@
 178.175.104.16
 178.175.104.161
 178.175.104.163
+178.175.104.166
 178.175.104.167
 178.175.104.169
 178.175.104.17
@@ -201974,6 +202138,7 @@
 178.175.104.195
 178.175.104.196
 178.175.104.198
+178.175.104.199
 178.175.104.200
 178.175.104.202
 178.175.104.206
@@ -201987,6 +202152,7 @@
 178.175.104.230
 178.175.104.234
 178.175.104.235
+178.175.104.239
 178.175.104.241
 178.175.104.243
 178.175.104.244
@@ -201995,6 +202161,7 @@
 178.175.104.252
 178.175.104.253
 178.175.104.255
+178.175.104.26
 178.175.104.27
 178.175.104.29
 178.175.104.34
@@ -202072,6 +202239,7 @@
 178.175.105.208
 178.175.105.21
 178.175.105.213
+178.175.105.214
 178.175.105.215
 178.175.105.217
 178.175.105.220
@@ -202080,6 +202248,7 @@
 178.175.105.235
 178.175.105.237
 178.175.105.238
+178.175.105.240
 178.175.105.245
 178.175.105.247
 178.175.105.248
@@ -202121,6 +202290,7 @@
 178.175.105.93
 178.175.105.94
 178.175.105.96
+178.175.105.99
 178.175.106.100
 178.175.106.102
 178.175.106.103
@@ -202140,6 +202310,7 @@
 178.175.106.136
 178.175.106.144
 178.175.106.146
+178.175.106.149
 178.175.106.15
 178.175.106.154
 178.175.106.156
@@ -202201,6 +202372,7 @@
 178.175.106.28
 178.175.106.31
 178.175.106.32
+178.175.106.36
 178.175.106.37
 178.175.106.42
 178.175.106.44
@@ -202220,6 +202392,7 @@
 178.175.106.78
 178.175.106.79
 178.175.106.8
+178.175.106.83
 178.175.106.84
 178.175.106.87
 178.175.106.9
@@ -202571,6 +202744,7 @@
 178.175.11.149
 178.175.11.150
 178.175.11.154
+178.175.11.155
 178.175.11.156
 178.175.11.157
 178.175.11.158
@@ -202604,6 +202778,7 @@
 178.175.11.23
 178.175.11.230
 178.175.11.235
+178.175.11.241
 178.175.11.243
 178.175.11.244
 178.175.11.246
@@ -202688,6 +202863,7 @@
 178.175.110.190
 178.175.110.191
 178.175.110.192
+178.175.110.194
 178.175.110.195
 178.175.110.197
 178.175.110.198
@@ -202838,6 +203014,7 @@
 178.175.112.103
 178.175.112.106
 178.175.112.109
+178.175.112.110
 178.175.112.113
 178.175.112.114
 178.175.112.117
@@ -203067,6 +203244,7 @@
 178.175.114.123
 178.175.114.124
 178.175.114.125
+178.175.114.127
 178.175.114.129
 178.175.114.13
 178.175.114.135
@@ -203277,6 +203455,7 @@
 178.175.116.1
 178.175.116.10
 178.175.116.100
+178.175.116.101
 178.175.116.103
 178.175.116.104
 178.175.116.106
@@ -203303,6 +203482,7 @@
 178.175.116.159
 178.175.116.165
 178.175.116.169
+178.175.116.170
 178.175.116.171
 178.175.116.174
 178.175.116.175
@@ -203783,6 +203963,7 @@
 178.175.12.78
 178.175.12.79
 178.175.12.91
+178.175.12.93
 178.175.12.97
 178.175.120.100
 178.175.120.101
@@ -203864,6 +204045,7 @@
 178.175.120.44
 178.175.120.47
 178.175.120.49
+178.175.120.5
 178.175.120.52
 178.175.120.57
 178.175.120.58
@@ -203916,6 +204098,8 @@
 178.175.121.180
 178.175.121.19
 178.175.121.190
+178.175.121.192
+178.175.121.193
 178.175.121.2
 178.175.121.202
 178.175.121.204
@@ -204157,6 +204341,7 @@
 178.175.123.247
 178.175.123.249
 178.175.123.255
+178.175.123.26
 178.175.123.27
 178.175.123.29
 178.175.123.3
@@ -204577,6 +204762,7 @@
 178.175.127.214
 178.175.127.216
 178.175.127.217
+178.175.127.219
 178.175.127.225
 178.175.127.228
 178.175.127.23
@@ -204599,6 +204785,7 @@
 178.175.127.35
 178.175.127.36
 178.175.127.38
+178.175.127.43
 178.175.127.45
 178.175.127.46
 178.175.127.53
@@ -204622,6 +204809,7 @@
 178.175.127.91
 178.175.127.92
 178.175.127.95
+178.175.127.97
 178.175.13.0
 178.175.13.1
 178.175.13.101
@@ -204716,6 +204904,7 @@
 178.175.14.126
 178.175.14.13
 178.175.14.130
+178.175.14.131
 178.175.14.141
 178.175.14.144
 178.175.14.152
@@ -205043,6 +205232,7 @@
 178.175.17.62
 178.175.17.63
 178.175.17.64
+178.175.17.66
 178.175.17.70
 178.175.17.74
 178.175.17.77
@@ -205255,6 +205445,7 @@
 178.175.2.18
 178.175.2.181
 178.175.2.184
+178.175.2.186
 178.175.2.187
 178.175.2.188
 178.175.2.189
@@ -205409,6 +205600,7 @@
 178.175.20.87
 178.175.20.93
 178.175.20.96
+178.175.20.97
 178.175.21.1
 178.175.21.110
 178.175.21.115
@@ -205606,6 +205798,7 @@
 178.175.23.184
 178.175.23.185
 178.175.23.187
+178.175.23.19
 178.175.23.198
 178.175.23.199
 178.175.23.201
@@ -205698,6 +205891,7 @@
 178.175.24.189
 178.175.24.190
 178.175.24.191
+178.175.24.198
 178.175.24.199
 178.175.24.200
 178.175.24.204
@@ -205971,6 +206165,7 @@
 178.175.27.122
 178.175.27.124
 178.175.27.125
+178.175.27.137
 178.175.27.138
 178.175.27.14
 178.175.27.143
@@ -206023,6 +206218,7 @@
 178.175.27.239
 178.175.27.24
 178.175.27.241
+178.175.27.244
 178.175.27.245
 178.175.27.246
 178.175.27.247
@@ -206111,6 +206307,7 @@
 178.175.28.198
 178.175.28.199
 178.175.28.20
+178.175.28.200
 178.175.28.202
 178.175.28.205
 178.175.28.206
@@ -206136,6 +206333,7 @@
 178.175.28.4
 178.175.28.5
 178.175.28.50
+178.175.28.51
 178.175.28.55
 178.175.28.59
 178.175.28.6
@@ -206143,6 +206341,7 @@
 178.175.28.64
 178.175.28.65
 178.175.28.66
+178.175.28.69
 178.175.28.7
 178.175.28.72
 178.175.28.74
@@ -206192,6 +206391,7 @@
 178.175.29.204
 178.175.29.205
 178.175.29.207
+178.175.29.208
 178.175.29.209
 178.175.29.219
 178.175.29.220
@@ -206228,6 +206428,7 @@
 178.175.29.55
 178.175.29.59
 178.175.29.6
+178.175.29.7
 178.175.29.72
 178.175.29.73
 178.175.29.77
@@ -206304,6 +206505,7 @@
 178.175.3.28
 178.175.3.3
 178.175.3.31
+178.175.3.32
 178.175.3.33
 178.175.3.34
 178.175.3.4
@@ -206316,6 +206518,7 @@
 178.175.3.58
 178.175.3.6
 178.175.3.62
+178.175.3.66
 178.175.3.68
 178.175.3.69
 178.175.3.72
@@ -206325,6 +206528,7 @@
 178.175.3.80
 178.175.3.81
 178.175.3.85
+178.175.3.87
 178.175.3.94
 178.175.3.98
 178.175.30.0
@@ -206483,6 +206687,7 @@
 178.175.31.247
 178.175.31.249
 178.175.31.251
+178.175.31.252
 178.175.31.253
 178.175.31.29
 178.175.31.3
@@ -206514,6 +206719,7 @@
 178.175.31.94
 178.175.31.97
 178.175.31.98
+178.175.31.99
 178.175.32.0
 178.175.32.1
 178.175.32.100
@@ -206533,6 +206739,7 @@
 178.175.32.133
 178.175.32.135
 178.175.32.138
+178.175.32.14
 178.175.32.140
 178.175.32.141
 178.175.32.142
@@ -206582,6 +206789,7 @@
 178.175.32.24
 178.175.32.241
 178.175.32.243
+178.175.32.244
 178.175.32.246
 178.175.32.248
 178.175.32.249
@@ -206653,6 +206861,7 @@
 178.175.33.186
 178.175.33.192
 178.175.33.193
+178.175.33.196
 178.175.33.198
 178.175.33.2
 178.175.33.202
@@ -206678,6 +206887,7 @@
 178.175.33.241
 178.175.33.242
 178.175.33.244
+178.175.33.245
 178.175.33.246
 178.175.33.255
 178.175.33.26
@@ -206896,6 +207106,7 @@
 178.175.35.85
 178.175.35.86
 178.175.35.89
+178.175.35.91
 178.175.35.92
 178.175.35.93
 178.175.35.96
@@ -206978,6 +207189,7 @@
 178.175.36.37
 178.175.36.46
 178.175.36.47
+178.175.36.5
 178.175.36.51
 178.175.36.52
 178.175.36.56
@@ -207096,6 +207308,7 @@
 178.175.37.67
 178.175.37.68
 178.175.37.70
+178.175.37.71
 178.175.37.74
 178.175.37.75
 178.175.37.76
@@ -207215,6 +207428,7 @@
 178.175.39.106
 178.175.39.107
 178.175.39.11
+178.175.39.110
 178.175.39.112
 178.175.39.113
 178.175.39.121
@@ -207285,6 +207499,7 @@
 178.175.39.57
 178.175.39.58
 178.175.39.61
+178.175.39.63
 178.175.39.71
 178.175.39.74
 178.175.39.76
@@ -207532,6 +207747,7 @@
 178.175.41.217
 178.175.41.221
 178.175.41.223
+178.175.41.224
 178.175.41.225
 178.175.41.229
 178.175.41.23
@@ -207620,9 +207836,11 @@
 178.175.42.228
 178.175.42.234
 178.175.42.235
+178.175.42.240
 178.175.42.243
 178.175.42.245
 178.175.42.247
+178.175.42.25
 178.175.42.253
 178.175.42.254
 178.175.42.255
@@ -207800,6 +208018,7 @@
 178.175.44.178
 178.175.44.179
 178.175.44.186
+178.175.44.188
 178.175.44.19
 178.175.44.191
 178.175.44.194
@@ -207928,6 +208147,7 @@
 178.175.45.241
 178.175.45.244
 178.175.45.246
+178.175.45.25
 178.175.45.250
 178.175.45.252
 178.175.45.253
@@ -208286,6 +208506,7 @@
 178.175.49.163
 178.175.49.166
 178.175.49.169
+178.175.49.177
 178.175.49.18
 178.175.49.180
 178.175.49.185
@@ -208299,6 +208520,7 @@
 178.175.49.208
 178.175.49.21
 178.175.49.213
+178.175.49.214
 178.175.49.215
 178.175.49.219
 178.175.49.221
@@ -208316,6 +208538,7 @@
 178.175.49.247
 178.175.49.248
 178.175.49.251
+178.175.49.252
 178.175.49.253
 178.175.49.3
 178.175.49.31
@@ -208425,6 +208648,7 @@
 178.175.5.68
 178.175.5.70
 178.175.5.71
+178.175.5.79
 178.175.5.84
 178.175.5.85
 178.175.5.88
@@ -208456,6 +208680,7 @@
 178.175.50.151
 178.175.50.152
 178.175.50.165
+178.175.50.168
 178.175.50.169
 178.175.50.173
 178.175.50.174
@@ -208493,6 +208718,7 @@
 178.175.50.27
 178.175.50.28
 178.175.50.3
+178.175.50.32
 178.175.50.33
 178.175.50.38
 178.175.50.40
@@ -208637,6 +208863,7 @@
 178.175.52.140
 178.175.52.141
 178.175.52.142
+178.175.52.146
 178.175.52.149
 178.175.52.15
 178.175.52.153
@@ -208658,6 +208885,7 @@
 178.175.52.200
 178.175.52.205
 178.175.52.206
+178.175.52.21
 178.175.52.211
 178.175.52.212
 178.175.52.216
@@ -208827,6 +209055,7 @@
 178.175.54.141
 178.175.54.142
 178.175.54.147
+178.175.54.15
 178.175.54.150
 178.175.54.151
 178.175.54.154
@@ -208834,6 +209063,7 @@
 178.175.54.162
 178.175.54.163
 178.175.54.165
+178.175.54.167
 178.175.54.172
 178.175.54.173
 178.175.54.178
@@ -209065,6 +209295,7 @@
 178.175.56.44
 178.175.56.48
 178.175.56.50
+178.175.56.52
 178.175.56.54
 178.175.56.55
 178.175.56.57
@@ -209100,6 +209331,7 @@
 178.175.57.119
 178.175.57.12
 178.175.57.121
+178.175.57.124
 178.175.57.126
 178.175.57.127
 178.175.57.129
@@ -209184,6 +209416,7 @@
 178.175.57.94
 178.175.57.95
 178.175.57.96
+178.175.57.99
 178.175.58.100
 178.175.58.101
 178.175.58.105
@@ -209325,6 +209558,7 @@
 178.175.59.237
 178.175.59.238
 178.175.59.239
+178.175.59.241
 178.175.59.243
 178.175.59.244
 178.175.59.245
@@ -209533,6 +209767,7 @@
 178.175.60.7
 178.175.60.70
 178.175.60.75
+178.175.60.76
 178.175.60.79
 178.175.60.8
 178.175.60.80
@@ -209623,6 +209858,7 @@
 178.175.61.9
 178.175.61.90
 178.175.61.91
+178.175.61.95
 178.175.61.96
 178.175.61.97
 178.175.62.1
@@ -209638,6 +209874,7 @@
 178.175.62.122
 178.175.62.123
 178.175.62.128
+178.175.62.141
 178.175.62.143
 178.175.62.150
 178.175.62.151
@@ -209776,6 +210013,7 @@
 178.175.63.227
 178.175.63.228
 178.175.63.229
+178.175.63.230
 178.175.63.231
 178.175.63.235
 178.175.63.239
@@ -209801,6 +210039,7 @@
 178.175.63.75
 178.175.63.76
 178.175.63.77
+178.175.63.78
 178.175.63.80
 178.175.63.87
 178.175.63.88
@@ -209834,6 +210073,7 @@
 178.175.64.149
 178.175.64.151
 178.175.64.154
+178.175.64.155
 178.175.64.156
 178.175.64.158
 178.175.64.163
@@ -209954,6 +210194,7 @@
 178.175.65.181
 178.175.65.184
 178.175.65.186
+178.175.65.19
 178.175.65.192
 178.175.65.193
 178.175.65.194
@@ -210198,6 +210439,7 @@
 178.175.67.48
 178.175.67.51
 178.175.67.54
+178.175.67.55
 178.175.67.59
 178.175.67.6
 178.175.67.60
@@ -210234,6 +210476,7 @@
 178.175.68.113
 178.175.68.114
 178.175.68.115
+178.175.68.116
 178.175.68.121
 178.175.68.124
 178.175.68.125
@@ -210908,6 +211151,7 @@
 178.175.73.72
 178.175.73.76
 178.175.73.77
+178.175.73.78
 178.175.73.86
 178.175.73.88
 178.175.73.89
@@ -210967,6 +211211,7 @@
 178.175.74.201
 178.175.74.203
 178.175.74.204
+178.175.74.205
 178.175.74.206
 178.175.74.207
 178.175.74.21
@@ -210984,6 +211229,7 @@
 178.175.74.237
 178.175.74.238
 178.175.74.241
+178.175.74.247
 178.175.74.251
 178.175.74.253
 178.175.74.30
@@ -211177,6 +211423,7 @@
 178.175.76.240
 178.175.76.241
 178.175.76.244
+178.175.76.246
 178.175.76.248
 178.175.76.27
 178.175.76.29
@@ -211256,6 +211503,7 @@
 178.175.77.242
 178.175.77.244
 178.175.77.246
+178.175.77.248
 178.175.77.250
 178.175.77.251
 178.175.77.252
@@ -211263,6 +211511,7 @@
 178.175.77.31
 178.175.77.32
 178.175.77.33
+178.175.77.34
 178.175.77.37
 178.175.77.38
 178.175.77.40
@@ -211363,6 +211612,7 @@
 178.175.78.48
 178.175.78.50
 178.175.78.51
+178.175.78.57
 178.175.78.58
 178.175.78.60
 178.175.78.64
@@ -211515,6 +211765,7 @@
 178.175.8.217
 178.175.8.223
 178.175.8.225
+178.175.8.227
 178.175.8.233
 178.175.8.238
 178.175.8.24
@@ -211531,6 +211782,7 @@
 178.175.8.60
 178.175.8.61
 178.175.8.63
+178.175.8.64
 178.175.8.67
 178.175.8.69
 178.175.8.72
@@ -211646,6 +211898,7 @@
 178.175.80.82
 178.175.80.86
 178.175.80.87
+178.175.80.89
 178.175.80.90
 178.175.80.91
 178.175.80.92
@@ -211697,6 +211950,7 @@
 178.175.81.185
 178.175.81.186
 178.175.81.189
+178.175.81.19
 178.175.81.192
 178.175.81.194
 178.175.81.197
@@ -211811,6 +212065,7 @@
 178.175.82.224
 178.175.82.226
 178.175.82.228
+178.175.82.23
 178.175.82.230
 178.175.82.233
 178.175.82.235
@@ -211872,11 +212127,13 @@
 178.175.83.125
 178.175.83.130
 178.175.83.133
+178.175.83.136
 178.175.83.137
 178.175.83.138
 178.175.83.139
 178.175.83.141
 178.175.83.143
+178.175.83.144
 178.175.83.145
 178.175.83.147
 178.175.83.15
@@ -211993,6 +212250,7 @@
 178.175.84.158
 178.175.84.159
 178.175.84.16
+178.175.84.17
 178.175.84.170
 178.175.84.178
 178.175.84.180
@@ -212446,10 +212704,12 @@
 178.175.88.230
 178.175.88.236
 178.175.88.237
+178.175.88.24
 178.175.88.241
 178.175.88.242
 178.175.88.243
 178.175.88.246
+178.175.88.248
 178.175.88.251
 178.175.88.253
 178.175.88.254
@@ -212550,6 +212810,7 @@
 178.175.89.25
 178.175.89.253
 178.175.89.28
+178.175.89.30
 178.175.89.31
 178.175.89.33
 178.175.89.37
@@ -212687,6 +212948,7 @@
 178.175.90.177
 178.175.90.178
 178.175.90.179
+178.175.90.185
 178.175.90.186
 178.175.90.187
 178.175.90.188
@@ -212741,6 +213003,7 @@
 178.175.90.79
 178.175.90.8
 178.175.90.80
+178.175.90.81
 178.175.90.85
 178.175.90.89
 178.175.90.90
@@ -212933,6 +213196,7 @@
 178.175.92.42
 178.175.92.43
 178.175.92.45
+178.175.92.48
 178.175.92.51
 178.175.92.54
 178.175.92.61
@@ -212993,6 +213257,7 @@
 178.175.93.196
 178.175.93.197
 178.175.93.198
+178.175.93.199
 178.175.93.200
 178.175.93.202
 178.175.93.203
@@ -213184,6 +213449,7 @@
 178.175.95.154
 178.175.95.156
 178.175.95.158
+178.175.95.163
 178.175.95.164
 178.175.95.165
 178.175.95.166
@@ -213285,6 +213551,7 @@
 178.175.96.169
 178.175.96.180
 178.175.96.181
+178.175.96.187
 178.175.96.189
 178.175.96.192
 178.175.96.195
@@ -213336,6 +213603,7 @@
 178.175.96.70
 178.175.96.75
 178.175.96.8
+178.175.96.81
 178.175.96.82
 178.175.96.88
 178.175.96.95
@@ -213404,6 +213672,7 @@
 178.175.97.219
 178.175.97.220
 178.175.97.224
+178.175.97.225
 178.175.97.23
 178.175.97.230
 178.175.97.231
@@ -213468,6 +213737,7 @@
 178.175.98.205
 178.175.98.206
 178.175.98.207
+178.175.98.216
 178.175.98.217
 178.175.98.221
 178.175.98.224
@@ -214138,6 +214408,7 @@
 178.95.195.240
 178.95.197.16
 178.95.197.55
+178.95.197.91
 178.95.198.146
 178.95.199.144
 178.95.199.175
@@ -214459,6 +214730,7 @@
 179.42.107.127
 179.42.107.128
 179.42.107.137
+179.42.107.139
 179.42.107.141
 179.42.107.144
 179.42.107.149
@@ -215824,6 +216096,7 @@
 180.188.224.104
 180.188.236.174
 180.188.236.247
+180.188.236.32
 180.188.236.9
 180.188.241.111
 180.188.241.115
@@ -216008,6 +216281,7 @@
 180.253.17.128
 180.253.191.125
 180.253.27.248
+180.253.99.109
 180.254.167.231
 180.254.241.245
 180.254.53.113
@@ -217186,6 +217460,7 @@
 182.112.28.104
 182.112.28.108
 182.112.28.116
+182.112.28.118
 182.112.28.122
 182.112.28.123
 182.112.28.13
@@ -217420,6 +217695,7 @@
 182.112.34.187
 182.112.34.20
 182.112.34.202
+182.112.34.220
 182.112.34.233
 182.112.34.25
 182.112.34.34
@@ -219673,6 +219949,7 @@
 182.113.238.135
 182.113.238.136
 182.113.238.165
+182.113.238.197
 182.113.238.199
 182.113.238.20
 182.113.238.28
@@ -219867,6 +220144,7 @@
 182.113.29.230
 182.113.29.241
 182.113.29.245
+182.113.29.28
 182.113.29.44
 182.113.29.46
 182.113.29.54
@@ -221878,6 +222156,7 @@
 182.114.76.254
 182.114.76.39
 182.114.76.41
+182.114.76.42
 182.114.76.50
 182.114.76.67
 182.114.76.81
@@ -223928,6 +224207,7 @@
 182.116.116.61
 182.116.116.64
 182.116.116.68
+182.116.116.70
 182.116.116.73
 182.116.116.75
 182.116.116.76
@@ -224104,6 +224384,7 @@
 182.116.119.53
 182.116.119.56
 182.116.119.59
+182.116.119.66
 182.116.119.68
 182.116.119.7
 182.116.119.74
@@ -224290,6 +224571,7 @@
 182.116.36.149
 182.116.36.15
 182.116.36.174
+182.116.36.175
 182.116.36.180
 182.116.36.195
 182.116.36.199
@@ -226600,6 +226882,7 @@
 182.117.13.21
 182.117.13.32
 182.117.13.4
+182.117.13.57
 182.117.13.71
 182.117.13.73
 182.117.13.75
@@ -229968,6 +230251,7 @@
 182.118.164.227
 182.118.164.248
 182.118.165.190
+182.118.166.128
 182.118.166.153
 182.118.166.36
 182.118.166.82
@@ -230711,6 +230995,7 @@
 182.119.15.63
 182.119.15.68
 182.119.15.70
+182.119.15.78
 182.119.15.81
 182.119.15.86
 182.119.15.91
@@ -230971,6 +231256,7 @@
 182.119.166.4
 182.119.166.64
 182.119.166.72
+182.119.166.76
 182.119.166.84
 182.119.166.9
 182.119.166.94
@@ -231136,6 +231422,7 @@
 182.119.179.130
 182.119.179.169
 182.119.179.17
+182.119.179.193
 182.119.179.199
 182.119.179.202
 182.119.179.230
@@ -231514,6 +231801,7 @@
 182.119.196.160
 182.119.196.182
 182.119.196.190
+182.119.197.123
 182.119.199.158
 182.119.199.85
 182.119.2.110
@@ -231614,6 +231902,7 @@
 182.119.202.159
 182.119.202.170
 182.119.202.179
+182.119.202.180
 182.119.202.189
 182.119.202.20
 182.119.202.201
@@ -231814,6 +232103,7 @@
 182.119.21.39
 182.119.21.46
 182.119.21.54
+182.119.21.68
 182.119.21.76
 182.119.21.79
 182.119.21.81
@@ -233457,6 +233747,7 @@
 182.119.88.4
 182.119.88.54
 182.119.88.88
+182.119.89.107
 182.119.89.11
 182.119.89.123
 182.119.89.126
@@ -236307,6 +236598,7 @@
 182.121.15.199
 182.121.15.203
 182.121.15.219
+182.121.15.223
 182.121.15.227
 182.121.15.237
 182.121.15.252
@@ -238187,6 +238479,7 @@
 182.121.254.117
 182.121.254.127
 182.121.254.132
+182.121.254.147
 182.121.254.15
 182.121.254.152
 182.121.254.198
@@ -239233,6 +239526,7 @@
 182.121.54.8
 182.121.54.81
 182.121.54.95
+182.121.55.106
 182.121.55.109
 182.121.55.112
 182.121.55.122
@@ -241953,6 +242247,7 @@
 182.123.241.130
 182.123.241.172
 182.123.241.173
+182.123.241.195
 182.123.241.200
 182.123.241.214
 182.123.241.23
@@ -242763,6 +243058,7 @@
 182.124.200.94
 182.124.201.176
 182.124.201.186
+182.124.201.207
 182.124.201.222
 182.124.202.211
 182.124.202.241
@@ -244284,6 +244580,7 @@
 182.126.123.185
 182.126.123.188
 182.126.123.189
+182.126.123.19
 182.126.123.191
 182.126.123.193
 182.126.123.199
@@ -246545,6 +246842,7 @@
 182.127.106.176
 182.127.106.216
 182.127.106.217
+182.127.106.43
 182.127.106.5
 182.127.106.53
 182.127.106.57
@@ -249991,6 +250289,7 @@
 182.127.93.229
 182.127.93.230
 182.127.93.35
+182.127.93.38
 182.127.93.39
 182.127.93.4
 182.127.93.42
@@ -250438,6 +250737,7 @@
 182.245.26.132
 182.245.26.171
 182.245.27.165
+182.245.28.162
 182.245.28.80
 182.245.34.249
 182.245.34.32
@@ -251103,6 +251403,7 @@
 182.56.192.77
 182.56.193.147
 182.56.193.161
+182.56.193.251
 182.56.193.26
 182.56.193.39
 182.56.193.46
@@ -255721,6 +256022,7 @@
 182.59.222.42
 182.59.222.60
 182.59.222.96
+182.59.223.113
 182.59.223.124
 182.59.223.127
 182.59.223.131
@@ -255912,6 +256214,7 @@
 182.59.235.100
 182.59.235.107
 182.59.235.121
+182.59.235.150
 182.59.235.151
 182.59.235.157
 182.59.235.164
@@ -258270,6 +258573,7 @@
 183.185.113.113
 183.185.115.92
 183.185.125.227
+183.185.162.225
 183.185.168.107
 183.185.168.165
 183.185.169.102
@@ -258664,6 +258968,7 @@
 183.188.90.55
 183.188.91.12
 183.188.92.208
+183.188.93.116
 183.188.93.21
 183.188.94.13
 183.188.94.195
@@ -262173,6 +262478,7 @@
 186.33.112.208
 186.33.112.209
 186.33.112.210
+186.33.112.211
 186.33.112.214
 186.33.112.216
 186.33.112.218
@@ -262260,6 +262566,7 @@
 186.33.112.95
 186.33.112.96
 186.33.112.97
+186.33.113.137
 186.33.113.2
 186.33.113.241
 186.33.113.5
@@ -263542,6 +263849,7 @@
 188.116.36.88
 188.119.112.125
 188.119.120.135
+188.119.45.194
 188.119.45.205
 188.119.49.1
 188.119.58.176
@@ -265886,6 +266194,7 @@
 190.72.32.132
 190.72.62.232
 190.73.101.231
+190.73.12.149
 190.73.71.174
 190.74.22.100
 190.75.113.109
@@ -267082,6 +267391,7 @@
 193.38.55.126
 193.38.55.59
 193.38.55.73
+193.38.55.9
 193.39.185.202
 193.39.185.207
 193.39.185.214
@@ -269227,6 +269537,7 @@
 2.68.190.234
 2.68.192.214
 2.68.234.169
+2.68.59.23
 2.68.78.147
 2.82.200.218
 2.82.28.27
@@ -270500,6 +270811,7 @@
 202.164.139.120
 202.164.139.121
 202.164.139.123
+202.164.139.124
 202.164.139.125
 202.164.139.127
 202.164.139.128
@@ -270594,6 +270906,7 @@
 202.164.139.243
 202.164.139.246
 202.164.139.247
+202.164.139.248
 202.164.139.249
 202.164.139.25
 202.164.139.252
@@ -274937,6 +275250,7 @@
 209.133.223.130
 209.14.30.109
 209.14.30.121
+209.14.30.132
 209.14.30.135
 209.14.30.136
 209.14.30.156
@@ -274948,6 +275262,7 @@
 209.14.30.205
 209.14.30.30
 209.14.30.54
+209.14.31.111
 209.14.31.125
 209.14.31.162
 209.14.31.163
@@ -277664,6 +277979,7 @@
 218.32.118.1
 218.32.118.185
 218.32.124.170
+218.32.96.158
 218.32.98.172
 218.35.198.109
 218.35.205.235
@@ -277762,6 +278078,7 @@
 218.57.107.48
 218.57.109.101
 218.57.109.155
+218.57.109.48
 218.57.109.58
 218.57.115.102
 218.57.115.124
@@ -279308,6 +279625,7 @@
 219.154.116.154
 219.154.116.156
 219.154.116.166
+219.154.116.168
 219.154.116.17
 219.154.116.171
 219.154.116.185
@@ -279961,6 +280279,7 @@
 219.154.142.196
 219.154.142.210
 219.154.142.239
+219.154.142.35
 219.154.142.4
 219.154.142.41
 219.154.142.43
@@ -280096,6 +280415,7 @@
 219.154.176.189
 219.154.176.24
 219.154.177.205
+219.154.178.138
 219.154.178.175
 219.154.178.69
 219.154.178.72
@@ -280304,6 +280624,7 @@
 219.154.41.137
 219.154.41.183
 219.154.41.31
+219.154.41.36
 219.154.41.51
 219.154.42.109
 219.154.42.121
@@ -280613,6 +280934,7 @@
 219.155.11.212
 219.155.11.220
 219.155.11.240
+219.155.11.252
 219.155.11.28
 219.155.11.36
 219.155.11.41
@@ -281251,6 +281573,7 @@
 219.155.209.230
 219.155.209.232
 219.155.209.25
+219.155.209.253
 219.155.209.35
 219.155.209.54
 219.155.209.74
@@ -282623,6 +282946,7 @@
 219.155.86.128
 219.155.86.136
 219.155.86.145
+219.155.86.156
 219.155.86.17
 219.155.86.182
 219.155.86.191
@@ -283453,6 +283777,7 @@
 219.156.175.190
 219.156.175.225
 219.156.176.129
+219.156.176.153
 219.156.176.184
 219.156.176.20
 219.156.176.64
@@ -283463,6 +283788,7 @@
 219.156.177.212
 219.156.177.232
 219.156.177.71
+219.156.178.130
 219.156.178.133
 219.156.178.137
 219.156.178.179
@@ -284113,6 +284439,7 @@
 219.156.65.250
 219.156.65.251
 219.156.65.27
+219.156.65.47
 219.156.65.48
 219.156.65.70
 219.156.65.71
@@ -285777,6 +286104,7 @@
 219.157.214.216
 219.157.214.22
 219.157.214.221
+219.157.214.235
 219.157.214.236
 219.157.214.24
 219.157.214.31
@@ -289584,6 +289912,7 @@
 221.13.191.75
 221.13.191.91
 221.13.208.118
+221.13.208.159
 221.13.208.8
 221.13.210.251
 221.13.211.121
@@ -290333,6 +290662,7 @@
 221.14.184.24
 221.14.184.32
 221.14.184.76
+221.14.185.105
 221.14.185.112
 221.14.185.157
 221.14.185.4
@@ -290454,6 +290784,7 @@
 221.14.46.48
 221.14.47.162
 221.14.47.182
+221.14.47.189
 221.14.47.46
 221.14.47.77
 221.14.47.82
@@ -290462,6 +290793,7 @@
 221.14.56.169
 221.14.56.252
 221.14.56.67
+221.14.57.175
 221.14.57.62
 221.14.58.27
 221.14.58.5
@@ -290613,6 +290945,7 @@
 221.15.111.49
 221.15.111.82
 221.15.111.96
+221.15.112.103
 221.15.112.186
 221.15.112.203
 221.15.112.220
@@ -291254,6 +291587,7 @@
 221.15.155.179
 221.15.155.180
 221.15.155.184
+221.15.155.186
 221.15.155.194
 221.15.155.197
 221.15.155.199
@@ -291989,6 +292323,7 @@
 221.15.190.179
 221.15.190.18
 221.15.190.188
+221.15.190.2
 221.15.190.232
 221.15.190.234
 221.15.190.247
@@ -294268,6 +294603,7 @@
 221.201.54.42
 221.201.54.97
 221.202.232.175
+221.202.232.230
 221.202.232.5
 221.202.234.170
 221.202.235.198
@@ -294562,6 +294898,7 @@
 221.214.249.112
 221.214.249.181
 221.214.249.199
+221.214.251.109
 221.214.251.162
 221.214.251.91
 221.214.254.15
@@ -296321,6 +296658,7 @@
 222.136.76.154
 222.136.76.84
 222.136.77.141
+222.136.77.190
 222.136.77.3
 222.136.77.91
 222.136.78.29
@@ -297708,6 +298046,7 @@
 222.137.161.73
 222.137.161.8
 222.137.161.85
+222.137.161.88
 222.137.161.91
 222.137.161.95
 222.137.161.96
@@ -298884,6 +299223,7 @@
 222.137.220.204
 222.137.220.207
 222.137.220.212
+222.137.220.215
 222.137.220.219
 222.137.220.226
 222.137.220.244
@@ -299093,6 +299433,7 @@
 222.137.237.181
 222.137.237.187
 222.137.237.190
+222.137.237.203
 222.137.237.208
 222.137.237.212
 222.137.237.217
@@ -299575,6 +299916,7 @@
 222.137.53.125
 222.137.53.191
 222.137.53.192
+222.137.53.193
 222.137.53.229
 222.137.53.242
 222.137.53.255
@@ -300487,6 +300829,7 @@
 222.138.118.186
 222.138.118.190
 222.138.118.191
+222.138.118.192
 222.138.118.195
 222.138.118.196
 222.138.118.2
@@ -301349,6 +301692,7 @@
 222.138.183.111
 222.138.183.116
 222.138.183.117
+222.138.183.120
 222.138.183.123
 222.138.183.126
 222.138.183.129
@@ -301741,6 +302085,7 @@
 222.138.213.192
 222.138.213.202
 222.138.213.219
+222.138.213.235
 222.138.213.239
 222.138.213.245
 222.138.213.31
@@ -302370,6 +302715,7 @@
 222.138.50.32
 222.138.50.50
 222.138.50.75
+222.138.51.203
 222.138.51.69
 222.138.52.108
 222.138.52.200
@@ -302620,6 +302966,7 @@
 222.139.106.121
 222.139.106.154
 222.139.106.230
+222.139.106.55
 222.139.107.10
 222.139.107.113
 222.139.107.137
@@ -304146,6 +304493,7 @@
 222.140.179.11
 222.140.179.120
 222.140.179.14
+222.140.179.142
 222.140.179.16
 222.140.179.168
 222.140.179.178
@@ -304385,6 +304733,7 @@
 222.140.207.76
 222.140.207.85
 222.140.208.132
+222.140.208.18
 222.140.208.205
 222.140.208.219
 222.140.208.45
@@ -304705,6 +305054,7 @@
 222.141.101.240
 222.141.101.251
 222.141.101.254
+222.141.101.39
 222.141.101.55
 222.141.101.87
 222.141.101.92
@@ -305728,6 +306078,7 @@
 222.141.40.47
 222.141.40.58
 222.141.40.65
+222.141.40.69
 222.141.40.7
 222.141.40.73
 222.141.40.75
@@ -308016,6 +308367,7 @@
 222.81.155.83
 222.81.155.88
 222.81.156.100
+222.81.156.229
 222.81.157.146
 222.81.157.148
 222.81.157.177
@@ -309507,6 +309859,7 @@
 27.153.140.109
 27.153.141.43
 27.153.141.80
+27.153.142.115
 27.153.142.228
 27.153.142.44
 27.153.143.113
@@ -313504,6 +313857,7 @@
 27.208.200.128
 27.208.200.67
 27.208.201.212
+27.208.202.165
 27.208.202.25
 27.208.203.172
 27.208.205.119
@@ -313554,6 +313908,7 @@
 27.208.55.230
 27.208.55.65
 27.208.63.93
+27.208.70.115
 27.208.70.207
 27.208.72.67
 27.208.76.142
@@ -314609,6 +314964,7 @@
 27.213.165.198
 27.213.166.136
 27.213.166.174
+27.213.166.50
 27.213.167.154
 27.213.167.175
 27.213.167.180
@@ -315333,6 +315689,7 @@
 27.215.253.149
 27.215.254.134
 27.215.255.209
+27.215.27.143
 27.215.28.105
 27.215.28.45
 27.215.3.1
@@ -319711,6 +320068,7 @@
 27.41.159.205
 27.41.159.216
 27.41.159.26
+27.41.159.28
 27.41.159.33
 27.41.159.58
 27.41.159.76
@@ -320460,6 +320818,7 @@
 27.41.37.128
 27.41.37.131
 27.41.37.133
+27.41.37.155
 27.41.37.171
 27.41.37.180
 27.41.37.187
@@ -320608,6 +320967,7 @@
 27.41.89.195
 27.41.89.50
 27.41.89.89
+27.41.9.105
 27.41.9.113
 27.41.9.130
 27.41.9.135
@@ -320660,6 +321020,7 @@
 27.41.97.172
 27.41.97.191
 27.41.97.2
+27.41.97.36
 27.41.97.40
 27.41.97.6
 27.41.97.94
@@ -320694,10 +321055,12 @@
 27.43.105.64
 27.43.106.242
 27.43.107.181
+27.43.108.78
 27.43.109.21
 27.43.110.101
 27.43.110.185
 27.43.110.198
+27.43.111.161
 27.43.111.217
 27.43.111.46
 27.43.115.108
@@ -320709,6 +321072,7 @@
 27.43.116.9
 27.43.116.96
 27.43.117.15
+27.43.117.66
 27.43.117.89
 27.43.118.111
 27.43.118.150
@@ -320840,6 +321204,7 @@
 27.46.22.67
 27.46.22.83
 27.46.22.9
+27.46.23.10
 27.46.23.123
 27.46.23.181
 27.46.23.188
@@ -320885,6 +321250,7 @@
 27.46.44.233
 27.46.44.235
 27.46.44.237
+27.46.44.239
 27.46.44.246
 27.46.44.254
 27.46.44.31
@@ -320944,6 +321310,7 @@
 27.46.45.7
 27.46.45.82
 27.46.45.85
+27.46.45.86
 27.46.45.88
 27.46.45.89
 27.46.45.90
@@ -322364,6 +322731,7 @@
 27.5.30.70
 27.5.30.71
 27.5.30.72
+27.5.30.79
 27.5.30.81
 27.5.30.82
 27.5.30.87
@@ -322823,6 +323191,7 @@
 27.5.36.221
 27.5.36.222
 27.5.36.230
+27.5.36.232
 27.5.36.233
 27.5.36.234
 27.5.36.238
@@ -323338,6 +323707,7 @@
 27.5.41.143
 27.5.41.144
 27.5.41.145
+27.5.41.146
 27.5.41.148
 27.5.41.149
 27.5.41.155
@@ -325853,6 +326223,7 @@
 27.6.122.19
 27.6.122.192
 27.6.122.193
+27.6.122.194
 27.6.122.197
 27.6.122.2
 27.6.122.202
@@ -331355,6 +331726,7 @@
 27.6.240.156
 27.6.240.161
 27.6.240.169
+27.6.240.171
 27.6.240.175
 27.6.240.181
 27.6.240.183
@@ -331576,6 +331948,7 @@
 27.6.243.113
 27.6.243.117
 27.6.243.12
+27.6.243.122
 27.6.243.126
 27.6.243.127
 27.6.243.128
@@ -332265,6 +332638,7 @@
 27.6.34.217
 27.6.34.60
 27.6.38.222
+27.6.38.96
 27.6.4.101
 27.6.4.102
 27.6.4.106
@@ -344723,6 +345097,7 @@
 36.251.18.2
 36.251.18.40
 36.251.18.44
+36.251.18.63
 36.251.19.213
 36.251.19.231
 36.251.19.249
@@ -345327,6 +345702,7 @@
 36.42.107.77
 36.42.107.99
 36.43.10.121
+36.43.11.16
 36.43.11.211
 36.43.12.163
 36.43.64.10
@@ -345464,6 +345840,7 @@
 36.81.158.24
 36.81.187.39
 36.81.209.186
+36.81.23.38
 36.81.230.140
 36.81.31.124
 36.82.179.161
@@ -348935,6 +349312,7 @@
 39.77.44.29
 39.77.44.32
 39.77.46.7
+39.77.48.213
 39.77.49.13
 39.77.5.113
 39.77.5.214
@@ -349364,6 +349742,7 @@
 39.79.162.176
 39.79.163.104
 39.79.163.173
+39.79.163.188
 39.79.163.252
 39.79.163.96
 39.79.164.165
@@ -349828,6 +350207,7 @@
 39.80.35.201
 39.80.36.151
 39.80.36.64
+39.80.37.182
 39.80.38.117
 39.80.38.27
 39.80.39.207
@@ -353512,6 +353892,7 @@
 42.224.122.174
 42.224.122.176
 42.224.122.182
+42.224.122.183
 42.224.122.186
 42.224.122.19
 42.224.122.191
@@ -355134,6 +355515,7 @@
 42.224.188.115
 42.224.188.137
 42.224.188.176
+42.224.188.223
 42.224.188.241
 42.224.188.250
 42.224.188.85
@@ -355141,6 +355523,7 @@
 42.224.189.121
 42.224.189.153
 42.224.189.208
+42.224.189.79
 42.224.189.88
 42.224.189.89
 42.224.189.90
@@ -356184,6 +356567,7 @@
 42.224.249.178
 42.224.249.18
 42.224.249.182
+42.224.249.188
 42.224.249.190
 42.224.249.195
 42.224.249.208
@@ -356630,6 +357014,7 @@
 42.224.3.171
 42.224.3.179
 42.224.3.180
+42.224.3.187
 42.224.3.192
 42.224.3.205
 42.224.3.206
@@ -357346,6 +357731,7 @@
 42.224.52.56
 42.224.52.58
 42.224.52.8
+42.224.52.81
 42.224.52.97
 42.224.53.120
 42.224.53.130
@@ -357487,6 +357873,7 @@
 42.224.59.245
 42.224.59.247
 42.224.59.249
+42.224.59.251
 42.224.59.68
 42.224.59.73
 42.224.59.74
@@ -357866,6 +358253,7 @@
 42.224.68.67
 42.224.68.69
 42.224.68.70
+42.224.68.72
 42.224.68.74
 42.224.68.78
 42.224.68.79
@@ -361728,6 +362116,7 @@
 42.228.196.177
 42.228.196.193
 42.228.196.218
+42.228.196.68
 42.228.196.89
 42.228.197.136
 42.228.197.142
@@ -366572,6 +366961,7 @@
 42.230.46.198
 42.230.46.231
 42.230.46.246
+42.230.46.55
 42.230.46.70
 42.230.46.9
 42.230.46.93
@@ -368997,6 +369387,7 @@
 42.231.95.195
 42.231.95.210
 42.231.95.230
+42.231.95.247
 42.231.95.99
 42.231.96.105
 42.231.96.176
@@ -369933,6 +370324,7 @@
 42.232.45.85
 42.232.46.1
 42.232.46.129
+42.232.46.169
 42.232.46.73
 42.232.46.86
 42.232.47.212
@@ -370629,6 +371021,7 @@
 42.233.159.141
 42.233.159.168
 42.233.159.19
+42.233.159.21
 42.233.159.223
 42.233.159.228
 42.233.159.230
@@ -372152,6 +372545,7 @@
 42.234.246.77
 42.234.247.171
 42.234.247.4
+42.234.247.41
 42.234.247.44
 42.234.247.55
 42.234.247.57
@@ -375440,6 +375834,7 @@
 42.235.81.88
 42.235.82.0
 42.235.82.108
+42.235.82.112
 42.235.82.118
 42.235.82.129
 42.235.82.141
@@ -375470,6 +375865,7 @@
 42.235.82.44
 42.235.82.45
 42.235.82.46
+42.235.82.52
 42.235.82.53
 42.235.82.54
 42.235.82.60
@@ -375660,6 +376056,7 @@
 42.235.86.87
 42.235.86.95
 42.235.87.1
+42.235.87.100
 42.235.87.102
 42.235.87.103
 42.235.87.121
@@ -376845,6 +377242,7 @@
 42.237.14.202
 42.237.14.74
 42.237.14.8
+42.237.142.157
 42.237.15.110
 42.237.15.142
 42.237.15.153
@@ -376954,6 +377352,7 @@
 42.237.24.108
 42.237.24.129
 42.237.24.14
+42.237.24.151
 42.237.24.166
 42.237.24.220
 42.237.24.23
@@ -377206,6 +377605,7 @@
 42.237.60.219
 42.237.60.254
 42.237.60.42
+42.237.60.73
 42.237.61.107
 42.237.61.152
 42.237.61.246
@@ -377835,6 +378235,7 @@
 42.238.227.72
 42.238.227.86
 42.238.227.95
+42.238.228.0
 42.238.228.122
 42.238.228.132
 42.238.228.220
@@ -378023,6 +378424,7 @@
 42.238.250.202
 42.238.250.246
 42.238.250.248
+42.238.250.56
 42.238.251.226
 42.238.251.47
 42.238.251.61
@@ -378539,6 +378941,7 @@
 42.239.154.85
 42.239.155.124
 42.239.155.143
+42.239.155.147
 42.239.155.158
 42.239.155.159
 42.239.155.165
@@ -378807,6 +379210,7 @@
 42.239.201.20
 42.239.201.86
 42.239.202.100
+42.239.202.121
 42.239.202.145
 42.239.202.227
 42.239.202.229
@@ -378901,6 +379305,7 @@
 42.239.217.21
 42.239.217.228
 42.239.217.56
+42.239.218.137
 42.239.218.141
 42.239.218.157
 42.239.218.63
@@ -381158,6 +381563,7 @@
 45.176.108.154
 45.176.108.157
 45.176.108.161
+45.176.108.164
 45.176.108.168
 45.176.108.170
 45.176.108.18
@@ -386294,6 +386700,7 @@
 5.39.218.162
 5.39.219.130
 5.39.223.68
+5.42.37.74
 5.42.48.223
 5.42.82.17
 5.42.92.195
@@ -387047,6 +387454,7 @@
 58.11.78.109
 58.114.245.23
 58.114.246.26
+58.115.108.164
 58.115.160.50
 58.115.162.92
 58.115.166.148
@@ -387716,6 +388124,7 @@
 58.248.116.190
 58.248.116.199
 58.248.116.2
+58.248.116.21
 58.248.116.210
 58.248.116.216
 58.248.116.222
@@ -387746,6 +388155,7 @@
 58.248.117.218
 58.248.117.226
 58.248.117.233
+58.248.117.238
 58.248.117.244
 58.248.117.253
 58.248.117.4
@@ -387902,6 +388312,7 @@
 58.248.142.11
 58.248.142.111
 58.248.142.116
+58.248.142.132
 58.248.142.137
 58.248.142.138
 58.248.142.148
@@ -387927,6 +388338,7 @@
 58.248.142.239
 58.248.142.24
 58.248.142.4
+58.248.142.5
 58.248.142.53
 58.248.142.64
 58.248.142.67
@@ -388059,6 +388471,7 @@
 58.248.147.159
 58.248.147.179
 58.248.147.182
+58.248.147.196
 58.248.147.208
 58.248.147.224
 58.248.147.226
@@ -388161,6 +388574,7 @@
 58.248.151.247
 58.248.151.248
 58.248.151.25
+58.248.151.33
 58.248.151.4
 58.248.151.48
 58.248.151.6
@@ -388254,6 +388668,7 @@
 58.248.74.230
 58.248.74.236
 58.248.74.24
+58.248.74.240
 58.248.74.241
 58.248.74.246
 58.248.74.41
@@ -388933,6 +389348,7 @@
 58.249.72.49
 58.249.72.67
 58.249.72.69
+58.249.72.88
 58.249.72.95
 58.249.72.98
 58.249.73.1
@@ -388989,6 +389405,7 @@
 58.249.74.222
 58.249.74.227
 58.249.74.235
+58.249.74.243
 58.249.74.245
 58.249.74.248
 58.249.74.35
@@ -389014,6 +389431,7 @@
 58.249.75.194
 58.249.75.20
 58.249.75.209
+58.249.75.213
 58.249.75.214
 58.249.75.218
 58.249.75.233
@@ -389186,6 +389604,7 @@
 58.249.80.242
 58.249.80.245
 58.249.80.246
+58.249.80.25
 58.249.80.37
 58.249.80.38
 58.249.80.46
@@ -389471,6 +389890,7 @@
 58.249.89.143
 58.249.89.15
 58.249.89.157
+58.249.89.158
 58.249.89.160
 58.249.89.162
 58.249.89.167
@@ -389879,6 +390299,7 @@
 58.255.140.125
 58.255.140.146
 58.255.140.149
+58.255.140.150
 58.255.140.156
 58.255.140.190
 58.255.140.21
@@ -390454,6 +390875,7 @@
 59.127.10.103
 59.127.108.38
 59.127.109.11
+59.127.11.50
 59.127.124.161
 59.127.125.164
 59.127.130.170
@@ -395290,6 +395712,7 @@
 59.92.176.201
 59.92.176.202
 59.92.176.209
+59.92.176.21
 59.92.176.218
 59.92.176.221
 59.92.176.222
@@ -395299,6 +395722,7 @@
 59.92.176.233
 59.92.176.235
 59.92.176.236
+59.92.176.24
 59.92.176.243
 59.92.176.244
 59.92.176.245
@@ -395313,6 +395737,7 @@
 59.92.176.40
 59.92.176.41
 59.92.176.44
+59.92.176.45
 59.92.176.47
 59.92.176.55
 59.92.176.56
@@ -395520,7 +395945,9 @@
 59.92.179.114
 59.92.179.115
 59.92.179.119
+59.92.179.12
 59.92.179.123
+59.92.179.124
 59.92.179.125
 59.92.179.13
 59.92.179.14
@@ -395593,6 +396020,7 @@
 59.92.18.145
 59.92.18.152
 59.92.18.155
+59.92.18.156
 59.92.18.159
 59.92.18.161
 59.92.18.170
@@ -395916,6 +396344,7 @@
 59.92.181.221
 59.92.181.222
 59.92.181.223
+59.92.181.224
 59.92.181.225
 59.92.181.226
 59.92.181.227
@@ -396039,6 +396468,7 @@
 59.92.182.138
 59.92.182.14
 59.92.182.140
+59.92.182.141
 59.92.182.144
 59.92.182.145
 59.92.182.147
@@ -396401,6 +396831,7 @@
 59.92.19.211
 59.92.19.212
 59.92.19.229
+59.92.19.230
 59.92.19.235
 59.92.19.24
 59.92.19.244
@@ -397730,6 +398161,7 @@
 59.93.19.99
 59.93.20.0
 59.93.20.1
+59.93.20.104
 59.93.20.106
 59.93.20.107
 59.93.20.110
@@ -397805,6 +398237,7 @@
 59.93.21.111
 59.93.21.115
 59.93.21.117
+59.93.21.119
 59.93.21.121
 59.93.21.126
 59.93.21.127
@@ -400772,6 +401205,7 @@
 59.96.37.177
 59.96.37.179
 59.96.37.180
+59.96.37.181
 59.96.37.182
 59.96.37.183
 59.96.37.185
@@ -400848,6 +401282,7 @@
 59.96.37.34
 59.96.37.35
 59.96.37.37
+59.96.37.38
 59.96.37.39
 59.96.37.4
 59.96.37.40
@@ -401234,6 +401669,7 @@
 59.96.39.241
 59.96.39.242
 59.96.39.243
+59.96.39.244
 59.96.39.246
 59.96.39.247
 59.96.39.248
@@ -403659,6 +404095,7 @@
 59.99.139.184
 59.99.139.186
 59.99.139.189
+59.99.139.19
 59.99.139.190
 59.99.139.191
 59.99.139.192
@@ -403713,6 +404150,7 @@
 59.99.139.64
 59.99.139.66
 59.99.139.68
+59.99.139.71
 59.99.139.73
 59.99.139.76
 59.99.139.78
@@ -404006,6 +404444,7 @@
 59.99.142.157
 59.99.142.158
 59.99.142.159
+59.99.142.163
 59.99.142.164
 59.99.142.165
 59.99.142.167
@@ -404108,6 +404547,7 @@
 59.99.143.112
 59.99.143.113
 59.99.143.114
+59.99.143.115
 59.99.143.117
 59.99.143.119
 59.99.143.120
@@ -404405,6 +404845,7 @@
 59.99.190.18
 59.99.190.182
 59.99.190.187
+59.99.190.189
 59.99.190.190
 59.99.190.191
 59.99.190.192
@@ -405237,6 +405678,7 @@
 59.99.44.123
 59.99.44.124
 59.99.44.125
+59.99.44.126
 59.99.44.129
 59.99.44.131
 59.99.44.132
@@ -405431,6 +405873,7 @@
 59.99.45.153
 59.99.45.154
 59.99.45.155
+59.99.45.156
 59.99.45.158
 59.99.45.16
 59.99.45.160
@@ -405607,6 +406050,7 @@
 59.99.46.166
 59.99.46.167
 59.99.46.168
+59.99.46.170
 59.99.46.171
 59.99.46.172
 59.99.46.174
@@ -405614,6 +406058,7 @@
 59.99.46.176
 59.99.46.177
 59.99.46.18
+59.99.46.180
 59.99.46.181
 59.99.46.182
 59.99.46.183
@@ -406566,6 +407011,7 @@
 59.99.95.161
 59.99.95.162
 59.99.95.164
+59.99.95.166
 59.99.95.167
 59.99.95.168
 59.99.95.169
@@ -407890,6 +408336,7 @@
 60.212.11.156
 60.212.110.19
 60.212.110.3
+60.212.111.39
 60.212.117.125
 60.212.117.206
 60.212.117.51
@@ -408256,6 +408703,7 @@
 60.214.217.79
 60.214.217.82
 60.214.217.85
+60.214.217.96
 60.214.218.136
 60.214.218.192
 60.214.218.196
@@ -408348,6 +408796,7 @@
 60.214.32.138
 60.214.32.150
 60.214.32.151
+60.214.32.17
 60.214.32.236
 60.214.32.243
 60.214.32.244
@@ -418531,6 +418980,7 @@
 61.128.83.148
 61.128.88.38
 61.129.101.57
+61.130.195.121
 61.130.195.172
 61.130.198.170
 61.130.224.119
@@ -421041,6 +421491,7 @@
 61.3.151.37
 61.3.151.38
 61.3.151.56
+61.3.151.60
 61.3.151.66
 61.3.151.70
 61.3.151.84
@@ -421318,6 +421769,7 @@
 61.52.103.2
 61.52.103.20
 61.52.103.21
+61.52.103.217
 61.52.103.220
 61.52.103.228
 61.52.103.229
@@ -421356,6 +421808,7 @@
 61.52.103.91
 61.52.103.93
 61.52.103.99
+61.52.109.9
 61.52.11.12
 61.52.11.15
 61.52.11.2
@@ -421707,6 +422160,7 @@
 61.52.166.218
 61.52.167.246
 61.52.167.249
+61.52.167.66
 61.52.167.89
 61.52.168.106
 61.52.168.121
@@ -422546,6 +423000,7 @@
 61.52.211.31
 61.52.211.38
 61.52.211.59
+61.52.211.61
 61.52.211.75
 61.52.211.76
 61.52.211.77
@@ -423196,6 +423651,7 @@
 61.52.30.159
 61.52.30.160
 61.52.30.161
+61.52.30.172
 61.52.30.174
 61.52.30.176
 61.52.30.178
@@ -423442,6 +423898,7 @@
 61.52.4.127
 61.52.4.138
 61.52.4.151
+61.52.4.214
 61.52.4.220
 61.52.4.59
 61.52.4.81
@@ -423495,6 +423952,7 @@
 61.52.42.112
 61.52.42.134
 61.52.42.138
+61.52.42.174
 61.52.42.192
 61.52.42.196
 61.52.42.20
@@ -424969,6 +425427,7 @@
 61.52.98.210
 61.52.98.214
 61.52.98.215
+61.52.98.22
 61.52.98.220
 61.52.98.231
 61.52.98.244
@@ -429536,6 +429995,7 @@
 62.76.5.154
 62.77.210.124
 62.78.131.240
+62.78.82.93
 62.80.167.71
 62.80.231.196
 62.80.235.224
@@ -430370,6 +430830,7 @@
 68.183.24.160
 68.183.24.34
 68.183.25.231
+68.183.25.71
 68.183.26.100
 68.183.26.166
 68.183.26.74
@@ -430501,6 +430962,7 @@
 68.99.179.195
 68.99.179.89
 68.99.180.30
+68468438438.xyz
 68h7.com
 69.10.193.239
 69.10.35.44
@@ -431556,6 +432018,7 @@
 77.43.248.83
 77.43.250.181
 77.43.250.205
+77.43.250.246
 77.43.251.170
 77.43.251.196
 77.43.251.77
@@ -431657,6 +432120,7 @@
 77.49.200.235
 77.51.189.86
 77.52.180.138
+77.53.144.46
 77.53.145.33
 77.53.2.182
 77.53.246.179
@@ -437960,6 +438424,7 @@
 999.buzz
 999.co.id
 999.rajaojek.com
+999080321newfolder1002002131-service1002.space
 999102com.cn
 99bkx.com
 99centsdigitals.com
@@ -439457,6 +439922,7 @@ adventuredsocks.com
 adventureexplorer.in
 adventurehr.com
 adventureitdate.com
+adventureits.com
 adventuremania.com
 adventurersafaris.com
 adventuresofarchibald.com
@@ -440485,6 +440951,7 @@ akasyahediyelik.com
 akatanomastos.net
 akatlot.com
 akatsolution.net
+akauk09.top
 akaunting.redocom.com
 akawork.io
 akbaara.com
@@ -440568,6 +441035,7 @@ akouzelis-patra.gr
 akowa.projet-test.com
 akowalska.ecrm.pl
 akpeugono.com
+akpgi08.top
 akpp-service.top
 akppservis30.ru
 akprokonaija.com
@@ -452520,6 +452988,7 @@ camelliia.com
 camelmorocco.com
 camelotbrasil.com
 camelotorganics.com
+cameltrektours.com
 camenisch-software.ch
 camera.risami.net
 camera88.vn
@@ -462541,6 +463010,7 @@ dl-45538429.onedrives-en-live.com
 dl-675423.store-downloads.com
 dl-80076342.md-downloads.com
 dl-97674424.md-downloads.com
+dl-link.link
 dl-link.live
 dl-link.network
 dl-rw.com
@@ -464212,6 +464682,7 @@ duck.org
 duckhouse.org
 duckiesplumbing.com.au
 duckpvp.xyz
+duckrambo.com
 ducks.org.tw
 ducontcl.esy.es
 ducro.nl
@@ -471406,6 +471877,7 @@ freedomlifestyleprogram.com
 freedomsec.com.br
 freedomsolutionsuk.co.uk
 freedomtoshine.co
+freedomwellnesstherapy.com
 freedownloadbravebrowser.com
 freeeeweb-com.umbler.net
 freeezguru.com
@@ -479361,6 +479833,7 @@ iapp-hml.adttemp.com.br
 iappco.ir
 iar.webprojemiz.com
 iarpp.ro
+iasdcentralbucaramanga.com
 iasgoogle.com
 iashelpdesk.in
 iasira.dm.files.1drv.com
@@ -481665,6 +482138,7 @@ investicon.in
 investigadoresforenses-abcjuris.com
 investigatorsnorthwest.co.uk
 investime.info
+investinae.com
 investingbazar.com
 investingpivot.co.uk
 investinscs.com
@@ -483888,6 +484362,7 @@ joespoolandspaservice.com
 joeundrosky.com
 joezer-online.com
 jofox.nl
+jofre.eu
 jogaae.jfoaigh.com
 joghataisalam.ir
 joghatay.ir
@@ -488332,7 +488807,6 @@ laparomc.com
 laparoscopysales.com
 lapartenza-khl.com
 lapc.com.pk
-lapcare.com
 lapcentervn.xyz
 lapchallenge.co.uk
 lapelimmortelle.com.au
@@ -489398,7 +489872,6 @@ lgjmcaz.cn
 lglab.co.uk
 lgmi.org.uk
 lgonlinecenter.com
-lgpass.com
 lgrp35.vatelstudents.fr
 lgs.ec
 lgservis.net
@@ -496756,7 +497229,6 @@ moitruongtunglam.com
 mojang.com.br
 mojehaftom.com
 mojewnetrza.pl
-mojno--vse.ru
 mojo-studios.co.uk
 mojorockstar.com
 mojstudent.net
@@ -497283,7 +497755,6 @@ motus.co.rs
 motzadministraties.nl
 mouas.xyz
 mouaysha.com
-moufed.com
 moulin-de-la-hunelle.be
 mouni11.xyz
 mounicmadiraju.com
@@ -498591,6 +499062,7 @@ mytelegramapi.ml
 mytemplate.ro
 mytempucheck.com
 mytest.alessioatzeni.com
+mytestingserver.ml
 mytestwp.cf
 mytex.pe
 mythelxis.gr
@@ -500783,6 +501255,7 @@ no18balloonroom.co.uk
 no1angelsescort.com
 no1spinningfields.90degrees.digital
 no1websitedesigner.com
+no2politics.com
 no70.fun
 noabuseshere.top
 noach.nl
@@ -502206,6 +502679,7 @@ okz.wloclawek.pl
 ol.cognitiononline.in
 olacabattachment.com
 oladi.sulinet.hu
+olafyoutrue.xyz
 olahnyomda.hu
 olairdryport.com
 olalekan419.000webhostapp.com
@@ -503336,6 +503810,7 @@ ostappapa.ru
 ostappnp.myjino.ru
 ostaz.ml
 osteklenie-balkonov.tomsk.ru
+ostemeda.lt
 osteoliv.com
 osteopatasitgesblog.es
 osteopathin-husum.de
@@ -505735,6 +506210,7 @@ physicaltrainernearme.com
 physicianmedical-legalconsulting.com
 physicscafe.com.sg
 physio-bo.de
+physio-svdh.ch
 physio-veda.de
 physionize.com
 physiotherapeutinnen.at
@@ -509836,6 +510312,7 @@ radioinspiraciontv.com
 radiolajee.com
 radioland.eu
 radiolavariada.net
+radiolevi.ro
 radiomaismg.com.br
 radiomaxima.cl
 radiomega-hit.com
@@ -513098,6 +513575,7 @@ s-tech.hu
 s-vrach.com.ua
 s-zone.uz
 s.51shijuan.com
+s.lletlee.com
 s.oooooooooo.ga
 s.put.re
 s.thechinesemuslim.com
@@ -515241,6 +515719,7 @@ seiomon.eu
 seioodsoi.club
 seis.me
 seismophonic.com
+seitaiken.net
 seitenstreifen.ch
 seivenco.com
 seiz-ib.de
@@ -529701,7 +530180,6 @@ url-update.com
 url-validation-clients.com
 url.246546.com
 url.57569.fr.snd52.ch
-url.sg
 url3.mailanyone.net
 url5459.41southbar.com
 url675.textilmallorca.com
@@ -538333,7 +538811,6 @@ zzznan.com
 ||advantechnologies.com/o1a4udwj$all
 ||advantechnologies.com/o1a4udwj/$all
 ||advantechnologies.com/sites/us_us/outstanding-invoices$all
-||adventureits.com/wp-content/6399952952/q54d7zyhe/$all
 ||adventureracen.nl/cgi-bin/parts_service/$all
 ||advokatryzhov.ru/images/zoelfr/$all
 ||aecotimes.com/wp-admin/44z/$all
@@ -538566,6 +539043,7 @@ zzznan.com
 ||aziznews.ru/z.exe$all
 ||azoresalive.com/wea92k.rar$all
 ||b.top4top.io/p_1487vww951.jpg$all
+||b4ad7b79-534a-4e83-953e-c36da8cf27d9.s3.amazonaws.com/ww/setup.exe$all
 ||babaikane.s3.amazonaws.com/elpaisadats.zip$all
 ||babalublog.com/anatasio/pzmdp-hdzcluvtvxsdcm_tkwgwiljc-qq/$all
 ||babalublog.com/image/h5jo1ao23800/$all
@@ -539278,7 +539756,6 @@ zzznan.com
 ||cafeponton.nl/bin/payment/vlk0jnl/oa006201284964852292audvywk0fd54p/$all
 ||calltorepair.com/assets/09erzff/$all
 ||camargobarcelos.com.br/wp-includes/djhvf4ald9xaalbaxcsr1gqqmwvjigyno1g0q9lzyflzadsz8fltetrxvdbt/$all
-||cameltrektours.com/wordpress_fille/overview/$all
 ||camiloyepesph.com/high-times-zkufb/kecprg1v0czd5oxlpgoo6moyw5hjhszq4guj0zxxeumuzae7wmp3m6y/$all
 ||camrash.com/wp-content/etrac/fhfosckzrimxy7h/$all
 ||camworks.com/wp-content/uploads/lynx_220a.zip$all
@@ -540087,9 +540564,14 @@ zzznan.com
 ||cdn.discordapp.com/attachments/821484577327022114/821484844893732874/2tgyjedsrgftyuikjsedrfgtgh.txt$all
 ||cdn.discordapp.com/attachments/821484577327022114/821484978260672592/ytguj3tgyhjedrgtgyfhjrft.txt$all
 ||cdn.discordapp.com/attachments/821511904769998921/821511945881911306/panam.exe$all
+||cdn.discordapp.com/attachments/821809080812437507/824392185902006272/mmp1_1.exe$all
 ||cdn.discordapp.com/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso$all
 ||cdn.discordapp.com/attachments/823624203529486349/823684377765871646/we.jpg$all
 ||cdn.discordapp.com/attachments/823801311480250391/824870560605274122/bilfx1x.exe$all
+||cdn.discordapp.com/attachments/823810712891555890/824413943526195210/runpetest.exe$all
+||cdn.discordapp.com/attachments/824689793140129857/824690055498170398/token_stealer.bat$all
+||cdn.discordapp.com/attachments/824689793140129857/824690065988386816/sendhookfile.exe$all
+||cdn.discordapp.com/attachments/824689793140129857/824691026852970496/photo.exe$all
 ||cdn.discordapp.com/attachments/824721527890641000/824721774205206618/2_5388614236127628287.exe$all
 ||cdn.discordapp.com/attachments/824721527890641000/824722602072997949/222.exe$all
 ||cdn.discordapp.com:443/attachments/790590543397781576/820879760904683561/system.exe$all
@@ -540510,6 +540992,8 @@ zzznan.com
 ||digigrad.in/wp-content/uploads/scan/$all
 ||digilander.libero.it/ricettesiciliane1/ecuoco.exe$all
 ||digitalassets.ams3.digitaloceanspaces.com/hahaza/visual19.exe$all
+||digitalassets.ams3.digitaloceanspaces.com/hold/schost.exe$all
+||digitalassets.ams3.digitaloceanspaces.com/modern/five.exe$all
 ||digitalassets.ams3.digitaloceanspaces.com/randf/multitimerrt.exe$all
 ||digitalbrit.com/raako/zxa72252/$all
 ||digitalprintxpress.co.za/rkgihzxzpq/039061/kteq_039061_03062020.zip$all
@@ -557134,7 +557618,6 @@ zzznan.com
 ||foxnib.com/c3uftcyx/bzvxfhbsybcqx/$all
 ||foxnib.com/c3uftcyx/mg8jp0zp0_0gtxu-17/$all
 ||francoisrobertphotography.com/wp-content/form/trv/$all
-||freedomwellnesstherapy.com/wp-includes/1a0fhsde7zdx9/$all
 ||freelancero.nl/wp-content/3r2/$all
 ||fresh-flowers-galore.com/wp-content/sschbp8p/$all
 ||freshersvista.com/images/companies/remittance_advice.jar$all
@@ -557295,6 +557778,7 @@ zzznan.com
 ||gindnetsoft.com/o/open-box/6q0e5gh11nhimjb-wc8imy42g-forum/8koki85tepjy-yuh1kgkgrx/$all
 ||gindnetsoft.com/o/open-resource/guarded-cloud/hh50dcc2eutevdf-5zy8vxy71yw3/$all
 ||gist.githubusercontent.com/jamme1020031/b0d4eadf162334049858b225bbac3017/raw/309944c554ba111c4b563fbf34ce416062516465/ilike.txt$all
+||gist.githubusercontent.com/jamme1020031/ef880bfeed7c6314b365c84b5999a27c/raw/4b3456ebe9e1a9717598dd416450e0eafe856311/fuuuuu.txt$all
 ||gist.githubusercontent.com/raigabrielmaia/4384962bcff6896cc89eb7b68924f62d/raw/1788cb8fc869dd68f507a462dee4dd6453e0ed24/avast.mp3$all
 ||gist.githubusercontent.com/raigabrielmaia/4384962bcff6896cc89eb7b68924f62d/raw/1788cb8fc869dd68f507a462dee4dd6453e0ed24/avastt.mp3$all
 ||gist.githubusercontent.com/raigabrielmaia/4384962bcff6896cc89eb7b68924f62d/raw/1788cb8fc869dd68f507a462dee4dd6453e0ed24/nod.mp3$all
@@ -557661,7 +558145,6 @@ zzznan.com
 ||iain-padangsidimpuan.ac.id/onnfzqq_un4xy2/$all
 ||iain-padangsidimpuan.ac.id/payment_details/2019-01$all
 ||iain-padangsidimpuan.ac.id/payment_details/2019-01/$all
-||iasdcentralbucaramanga.com/wp-includes/bt9vl1jt8gwkyrcfxcxtur1avcka98qreu1pvdx24wxdbzbfzsyfvs9g7ldu6h/$all
 ||ibernova.es/old/0785004373439085/g6mzhpx-766-596-vymf6wwrk-xo8ecm4u1/$all
 ||ibernova.es/old/lzncr/$all
 ||ibernova.es/old/open_box/corporate_cloud/klu6x6behlel_zqaidjj5g/$all
@@ -557830,7 +558313,6 @@ zzznan.com
 ||jhgfdsssdfgnhmj.s3-eu-west-1.amazonaws.com/htgvf.exe$all
 ||jkhgfdccsdvgfhj.s3.amazonaws.com/2rf3.exe$all
 ||joecampanaro.com/wp-admin/personal_resource/security_vgbe5kaznr_id9h5blvl/2574083826139_x00jq3u/$all
-||jofre.eu/wp-content/themes/basic/css/msg.jpg$all
 ||jogosdarua.com.br/x/6xsangrymaplutefmwctp5kc6lkqugotzxtsuqildzxi0elohggf6bzbd45lastiup/$all
 ||johnhaydenwrites.com/track_url/p/$all
 ||johnsonjoyonline.com/admin_links/7nkja4tqwamdp6pdsxxjfkg9wtvqhbjlgfeezjutwlennw1zf/$all
@@ -557968,6 +558450,8 @@ zzznan.com
 ||lambchop.net/audio/reso.zip$all
 ||lameda.cc/m/9jpkaawwwbwpurxerigf8ayghssbq/$all
 ||lameda.cc/m/scan/jmbau/$all
+||lapcare.com/wp-content/9fotgty/$all
+||lapcare.com/wp-content/o2bwo/$all
 ||lapetiteroulotte.cat/b/fasshqcmb8la740xvizxesg4yqya5wxpdcdiexikef/$all
 ||lapiramideopticas.com/tesla-powerwall-ok3h2/kmj/$all
 ||laptopya.com/m/cl4zpngcmc5d41auv9aoqfy442jtgzfgjawt3/$all
@@ -558072,6 +558556,10 @@ zzznan.com
 ||lexmausa.com/2013xmas/protected_box/605352_ovcidsyoqkvvj_bofa_856wt2dp/xt8nkjdqbh_eim4vxmc4835/$all
 ||lexmausa.com/2013xmas/protected_section/special_8ibnmrpd_wvjx9sgyrlf8ax/ixfk8ymgeai_u3gbvjo1le8gs/$all
 ||lexmausa.com/2013xmas/zcrqc7fbu9rq/zh471460655333005jrn3x8j348mdp6en6/$all
+||lgpass.com/images/closed_resource/security_portal/575383_fczjbnodcixu/$all
+||lgpass.com/images/common_resource/interior_cloud/637368803912_d35jil4kauy8qn/$all
+||lgpass.com/images/d1q66rszmw123555/$all
+||lgpass.com/images/wk128/$all
 ||libertuspharma.com/wp-admin/qy0mf1suhgkn2k5mghneshta5nvanmlbmvtaoo/$all
 ||library.mju.ac.th/2018/cfjdes/$all
 ||library.mju.ac.th/2018/mnnw0cr-ptv5a-370268/$all
@@ -558449,6 +558937,7 @@ zzznan.com
 ||mobilize.org.br/acompanhe-a-mobilidade/browse/$all
 ||mobilize.org.br/acompanhe-a-mobilidade/docs/unz0127392065-7906-8qtep00cgkpfl7wx0rh3/$all
 ||mobilize.org.br/acompanhe-a-mobilidade/qlvsgt/$all
+||mojno--vse.ru/content/6tqjfutopvigfknidf0sfae6guwnsxjjicomwynq0qmfksrit2be2/$all
 ||mommababy.vn/wp-includes/jutbya4dbu3/$all
 ||mommababy.vn/wp-includes/lgnwvunbc8/$all
 ||moneygain.work/payeerclient.exe$all
@@ -558459,6 +558948,14 @@ zzznan.com
 ||morrobaydrugandgift.com/wp-contentbak/t9m/$all
 ||morsel.co.in/wp-includes/kdq0fhpp8btxy001szwbzzhy6q3gsemnno7oov/$all
 ||mostazadesigns.com/cgi-bin/h8h2d482jxbk8w/syhg7c3xr7inno0fjapmvzs/$all
+||moufed.com/uu/bin_xcmcfzvl198.bin$all
+||moufed.com/wi/bin_ofekr30.bin$all
+||moufed.com/wi/bin_ygdafxi87.bin$all
+||moufed.com/wii/bin_ucpwetyk79.bin$all
+||moufed.com/wu/azor_gzufukw49.bin$all
+||moufed.com/wu/bin_ksbky53.bin$all
+||moufed.com/wu/bin_lzszqq48.bin$all
+||moufed.com/wu/bin_xiaudeklm176.bin$all
 ||movartemusic.com/wp-admin/kxpufj09v77nrvkj6s7vs/$all
 ||movartemusic.com/wp-content/etrac/51codgquzyt12n2i/$all
 ||movartemusic.com/wp-content/llc/$all
@@ -558523,7 +559020,6 @@ zzznan.com
 ||mypt3.com/en_us/payments/09_18$all
 ||myqbd.com/images/invoice_n857419354.jar$all
 ||mysharmaschool.live/wp-admin/iskgq5k0qoxfah54uur8g9rhsqma4qaqfp/$all
-||mytestingserver.ml/wp-admin/41m/$all
 ||mywonderfulpregnancy.com/blog/yt6usk8x0/$all
 ||na01.safelinks.protection.outlook.com/?url=http%3a%2f%2fjoannawedding.tw%2finfo%2fus%2fopen-past-due-orders&amp;data=02%7c01%7c%7c8a1f2e80eebf495af6c508d608cccb99%7c0beb0c359cbb4feb99e5589e415c7944%7c1%7c0%7c636706073006427786&amp;sdata=pv1mo82urolyp6vdg0%2bycpki8z65ugu8cly9weob974%3d&amp;reserved=0$all
 ||na01.safelinks.protection.outlook.com/?url=http%3a%2f%2floja.suportepjfp.com%2f8722897fju%2fwire%2fcommercial&data=02%7c01%7c%7c0ae4be3840c241580f0708d6075b2a22%7c0beb0c359cbb4feb99e5589e415c7944%7c1%7c0%7c636704485463038224&sdata=wwaii5ithspsebss%2fn0qtfqhdysacbuzu9feviip3qo%3d&reserved=0$all
@@ -558613,7 +559109,6 @@ zzznan.com
 ||nissanvinh.com.vn/wp-content/file/dzstsbdfmrxcrylycpikagmv/$all
 ||nltu.edu.ua/fakturierung/rechnung-0269807/$all
 ||nmsdevelopers.com/cgi-bin/isir0cvzfzzk3zjymvnmjykw/$all
-||no2politics.com/files/us_us/doc/invoice-069345/$all
 ||nobletrade.top/forced-to-ppjht/4ujxrcjziel7naqcz4okyfz9wamd4m/$all
 ||nobletrade.top/forced-to-ppjht/r8zjyoribymmst7nssspsdtkhe/$all
 ||nofile.io/f/ed4ptb5vkud/purchase+order.zip$all
@@ -561161,7 +561656,6 @@ zzznan.com
 ||oshiscafe.com/wp-admin/5dm/$all
 ||osliving.com/vyop-n8taxexfiqihcz_tqpsraxby-hk$all
 ||osliving.com/vyop-n8taxexfiqihcz_tqpsraxby-hk/$all
-||ostemeda.lt/wp-content/s/$all
 ||overwatchboostpro.com/e46a70d24f4162901a5dfbc139b40d49/gxgck/$all
 ||overwatchboostpro.com/e46a70d24f4162901a5dfbc139b40d49/lm/37-2371894-54-3l6f-2cmce/$all
 ||overwatchboostpro.com/ynibgkd65jf/sites/2bmfkc0j7qe8_58yyhd4-3344823406/$all
@@ -567268,9 +567762,6 @@ zzznan.com
 ||photowizard.com.ua/verif.accounts.resourses.com/$all
 ||phuhaihoang.vn/wp-content/uploads/2020/04/vary/111111.png$all
 ||phuongapple.com/messenger-sound-8kwkq/yfr7/$all
-||physio-svdh.ch/sitepage/wzfnncemhvoqidqzhnzkj82qdhk3jyqj39x1djl9pwrakgmuel0xtr/$all
-||physio-svdh.ch/wp-admin/kk/$all
-||physio-svdh.ch/wp-admin/reporting/kv8wbwskaa0txl3jxs/$all
 ||physiodelacomba.ch/userfiles/xing.txt$all
 ||pierreconsulting.info/wp-admin/llc/mwcacs65xienqdp/$all
 ||pineshop.in/child-protective-7rqhh/kkbgs6974yws0c1pfisge0nlbrerahukelsvh5egj/$all
@@ -567385,7 +567876,6 @@ zzznan.com
 ||rabiei.fun/eidl-reconsideration-bs3lu/feooiao/$all
 ||radioiluminacion.djsrecord.com/pm3ibp8on.rar$all
 ||radiokameleon.ba/wp-includes/cvsky29-prh8p1-157/$all
-||radiolevi.ro/wp-content/vdbb/$all
 ||raissamaison.com/wordpress/attachments/w6y5zxxnzj61/$all
 ||raissamaison.com/wp-includes/eenf/$all
 ||rajasthanstudy.com/wp-content/1m4fvr5r6ui4pppbzzr85vkvpepzxa6plywjnvdz/$all
@@ -567453,6 +567943,7 @@ zzznan.com
 ||raw.githubusercontent.com/i87924hgasdhg/hgytiryty/master/busybox$all
 ||raw.githubusercontent.com/idumkyf/za5u0i/gh-pages/h4qpxjhvr.jpeg$all
 ||raw.githubusercontent.com/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe$all
+||raw.githubusercontent.com/itroublve/token-browser-password-stealer-creator/master/avoid%20me/tokenstealer.vbs$all
 ||raw.githubusercontent.com/itroublve/token-browser-password-stealer-creator/master/avoid%20me/tokenstealer2.vbs$all
 ||raw.githubusercontent.com/jocofid282/tewsa/master/blow.exe$all
 ||raw.githubusercontent.com/jocofid282/tewsa/master/dera$all
@@ -567879,7 +568370,6 @@ zzznan.com
 ||secure-web.cisco.com/1vypgccgybkpf1prxej5fch8svg1xkv3nb66tqfrxc7b-vvmo2x8ynyl6ve6p1hwliztoeqwvhtiuwhztww5t2lr5vpbiq1dn3u1vjqp1tvxya02acmwwop-on54zcaz5navelmk7-v6zttoqfoxvtwlgki6y4fhgvtvhyxpbb4yl3cdoqq_ls0op2xlollina9lzbkmsf3qnomb7u7fet03ntqq9zachjl14--vqb16lmwxgany-cfcl8fdbak2uatzcnrcfkqjdw4xsdlqlvdf0lf747nwb76rt0f6h-mkxb3vfytjqjqqlhkgpyt0ekwkujzekgwjspvmakcm-pq/https%3a%2f%2fwww.dropbox.com%2fs%2fm02dp4122ei0p50%2fcertificate%25208205.doc%3fdl%3d1/$all
 ||secuser.com/telechargement/desinfection/fix_myparty.exe$all
 ||sedgefuneralplan.co.uk/wp-admin/ssm5z0oogilu2onjfuqb460gnoa7by8rhftysdsgqox/$all
-||seitaiken.net/wp-admin/qz9b/$all
 ||sendspace.com/file/7g7dli$all
 ||sendspace.com/file/7g7dli?e=11$all
 ||sendspace.com/file/dl9l2g$all
@@ -570739,6 +571229,7 @@ zzznan.com
 ||url.emailprotection.link/?bcp_lqdelwbkhxktoiznr8rouhtt9w4qlfovfoxc0z5zmn6k8ji5zi9v7qbcrvrgeprp065w1sneu27jfm6lqozrkxpwdzwxoqhcuebeujx-pj0fn_jidanzngihd_cy1/$all
 ||url.emailprotection.link/?bgmvicpuho15c9_q9hiofgnmkaco0q_lujjcaeowkfik_hdtt1uqmbkpovhxykckgjoqoytv_u0g2umkhd4mbi9ms8vo3vliq2clouuaa6no2a7ij5ljfsouoeememvmi/$all
 ||url.emailprotection.link/?bizyxbw1fdagsfcc1n6ep1awpdx9dr0brnjjqwgyaofpw98limviipvrszjnzzluclpeqqdywfxwnwudvwrljcufuhl2_nha0bs8wz9jmbahcciikbseljewayzbe_cnd/$all
+||url.sg/rwtho$all
 ||url2.mailanyone.net/v1/?m=1hibcm-0003zv-63&i=57e1b682&c=sb1blj46bk32u6f729r5t_slvkx-heewxh20_zdn9-3ktcc0-kn35fykilpydgeyvrbwqwb5h__fk383wtdakqftjlelxz06jbaglri5jmujnydjkasqxwdtg2hn-_be1dzrnthvvhigyhm_tvbew342habp8dtit9jjlieuc2x-ipgdgipe7y_c9jhe69532gmnxozb5wifjfbstzicagmtpg6yxmreaf0sq2dgo-ksy54hetfhn6gwm4kiw2vvcqx17a9bm6ykn8bwpwdjwg/$all
 ||urldefense.com/v3/__http:/download.tikishop.top/temp/oct/zxpz9h87ye/__;!!fbndfrmfwymjic8!esuixa6kh9x3c2evnf06q3vphe7ce6thjgjxuygtgkahdoypzovx_isni9xonn9idgfjjqtcun8$/$all
 ||urldefense.com/v3/__https://www.geoffoliver.org/simple-blog.off/vendor/payment/9yiv2xys/__;!!okyw9je!2zzbjlkqkjmstcwtza6cy_dauiy-njmys3cs6uteawgyow8yhyesg5jhjtttdwaxadrnh5k$/$all